Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

101.

Solve : West Yorkshire Police Virus?

Answer»

Hi!

We've got a laptop that's running Vista that has picked up a virus. There's a pop up stating it's from 'West Yorkshire Police' which covers the whole screen stating that the computer has been locked for illegal downloads and that we have to pay £100 to some moody pay site.

I can access safe mode, but there doesn't seem to be a system restore point? I've run spybot search and destroy, malware bytes and hosecall through it and it's still there when I reboot the machine. Any ideas please?

Thanks in advance Hi there!

Download Farbar Recovery Scan Tool and save it to a flash drive.


Depending on your type of system, you will have to select 32-bit or 64-bit accordingly. How do I tell?

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:
    Startup Repair
    System Restore
    Windows Complete PC Restore
    Windows Memory Diagnostic Tool
    Command Prompt

    [/list]
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to the disclaimer.
    • Place a check next to List Drivers MD5 as well as the default check marks that are already there
    • Press Scan button. It will do its scan and save a log on your flash drive.
    • Close out of the message after that, then type in the text services.exe in to the "Search:" text box. Then, press the Search file(s) button, just as below:

      When done searching, FRST makes a log, Search.txt, on the C:\ drive or on your flash drive.
    • Type exit in the Command Prompt window and reboot the computer normally
    • FRST will make a log (FRST.txt) on the flash drive and also the search.txt logfile, please copy and paste the logs in your reply.
    Hi, thanks for your help so far!

    Logs on my flash drive are as follows;

    Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 29-08-2012 03
    Ran by SYSTEM at 29-08-2012 20:27:12
    Running from E:\
    Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: English(US)
    The current controlset is ControlSet001

    ==================== Registry (Whitelisted) ===================

    HKLM\...\Run: [ISTray] "C:\Program FILES\Spyware Doctor\pctsTray.exe" [1243088 2009-11-18] (PC Tools)
    HKLM\...\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter

    HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
    HKLM\...\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe [2339168 2012-01-17] (AVG Technologies CZ, s.r.o.)
    HKLM\...\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
    HKLM\...\Run: [Anvi Smart Defender] C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe [1229104 2012-08-23] (Anvisoft)
    HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation)
    HKU\Default\...\RunOnce: [BurnImage] regsvr32 /s c:\windows\IMAPIShellExt.dll [720896 2008-08-28] (Dell Inc)
    HKU\Default User\...\RunOnce: [BurnImage] regsvr32 /s c:\windows\IMAPIShellExt.dll [720896 2008-08-28] (Dell Inc)
    HKU\Gemma\...\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
    HKU\Gemma\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
    HKU\Gemma\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [8704 2006-11-02] (Microsoft Corporation)
    HKU\Gemma\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
    HKU\Gemma\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
    HKU\Gemma\...\Run: [WindowsCodecsExt] C:\Users\Gemma\AppData\Local\Microsoft\Windows\228\WindowsCodecsExt.exe [75264 2012-08-27] ()
    Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll [X]
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
    Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
    ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
    Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
    ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)

    ========================== Services (Whitelisted) ========================

    2 asdsrv; C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe [686896 2012-08-23] (Anvisoft)
    2 AVGIDSAgent; "C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe" [7391072 2012-01-31] (AVG Technologies CZ, s.r.o.)
    2 avgwd; "C:\Program Files\AVG\AVG10\avgwdsvc.exe" [269520 2011-02-07] (AVG Technologies CZ, s.r.o.)
    2 Browser Defender Update Service; "C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe" [112592 2010-01-21] (Threat Expert Ltd.)
    2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [161048 2008-04-28] (Stardock Corporation)
    2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
    3 McComponentHostService; "C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
    2 sdAuxService; C:\Program Files\Spyware Doctor\pctsAuxs.exe [359624 2009-10-30] (PC Tools)
    2 sdCoreService; C:\Program Files\Spyware Doctor\pctsSvc.exe [1141712 2009-11-06] (PC Tools)
    2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter


    ==================== Drivers (Whitelisted) ===================

    3 alcan5wn; C:\Windows\System32\DRIVERS\alcan5wn.sys [53600 2003-12-08] (THOMSON)
    3 alcaudsl; C:\Windows\System32\DRIVERS\alcaudsl.sys [70688 2003-12-08] (THOMSON)
    1 asdrm; C:\Windows\System32\DRIVERS\asdrm.sys [16208 2012-08-20] (Anvisoft)
    2 asdrs; \??\C:\Windows\system32\DRIVERS\asdrs.sys [22864 2012-08-20] (Anvisoft)
    2 asdws; \??\C:\Windows\system32\DRIVERS\asdws.sys [14160 2012-08-20] ()
    3 AVGIDSDriver; C:\Windows\System32\DRIVERS\AVGIDSDriver.Sys [134480 2011-05-27] (AVG Technologies CZ, s.r.o. )
    0 AVGIDSEH; C:\Windows\System32\DRIVERS\AVGIDSEH.Sys [22992 2011-02-21] (AVG Technologies CZ, s.r.o. )
    3 AVGIDSFilter; C:\Windows\System32\DRIVERS\AVGIDSFilter.Sys [24144 2011-02-09] (AVG Technologies CZ, s.r.o. )
    3 AVGIDSShim; C:\Windows\System32\DRIVERS\AVGIDSShim.Sys [28624 2011-02-09] (AVG Technologies CZ, s.r.o. )
    1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [248656 2011-01-06] (AVG Technologies CZ, s.r.o.)
    1 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [34896 2011-03-01] (AVG Technologies CZ, s.r.o.)
    0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [32592 2011-03-16] (AVG Technologies CZ, s.r.o.)
    1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [297168 2011-04-04] (AVG Technologies CZ, s.r.o.)
    3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)
    0 PCTCore; C:\Windows\System32\drivers\PCTCore.sys [207792 2009-11-09] (PC Tools)
    3 s1018bus; C:\Windows\System32\DRIVERS\s1018bus.sys [86824 2009-03-25] (MCCI Corporation)
    3 s1018mdfl; C:\Windows\System32\DRIVERS\s1018mdfl.sys [15016 2009-03-25] (MCCI Corporation)
    3 s1018mdm; C:\Windows\System32\DRIVERS\s1018mdm.sys [114728 2009-03-25] (MCCI Corporation)
    3 s1018mgmt; C:\Windows\System32\DRIVERS\s1018mgmt.sys [106208 2009-03-25] (MCCI Corporation)
    3 s1018nd5; C:\Windows\System32\DRIVERS\s1018nd5.sys [26024 2009-03-25] (MCCI Corporation)
    3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [104744 2009-03-25] (MCCI Corporation)
    3 s1018unic; C:\Windows\System32\DRIVERS\s1018unic.sys [109864 2009-03-25] (MCCI Corporation)
    3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys

    3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys

    3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS

    3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS

    3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys

    3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys

    3 PCDSRVC{E9D79540-57D5953E-06020101}_0; \??\c:\program files\dell support center\pcdsrvc.pkms

    3 SymIMMP; C:\Windows\System32\DRIVERS\SymIM.sys


    ==================== NetSvcs (Whitelisted) =================


    ============ One Month Created Files and Folders ==============

    2012-08-29 20:26 - 2012-08-29 20:26 - 00000000 ____D C:\FRST
    2012-08-28 15:09 - 2012-08-28 15:10 - 00000000 ____D C:\Users\Gemma\AppData\Roaming\hellomoto
    2012-08-28 11:42 - 2012-08-28 11:42 - 06954184 ____A C:\Users\Gemma\Downloads\spybotsd_includes.exe
    2012-08-28 11:17 - 2012-08-28 11:17 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-28 11:15 - 2012-08-28 11:15 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Gemma\Downloads\mbam-setup-1.62.0.1300.exe
    2012-08-28 09:56 - 2012-08-28 10:25 - 00001458 ____A C:\Windows\System32\avgrep.txt
    2012-08-28 07:11 - 2012-08-28 07:11 - 00000979 ____A C:\Users\Public\Desktop\Anvi Smart Defender.lnk
    2012-08-28 07:11 - 2012-08-28 07:11 - 00000000 ____D C:\Users\Gemma\AppData\Roaming\Anvisoft
    2012-08-28 07:11 - 2012-08-28 07:11 - 00000000 ____D C:\Users\All Users\Anvisoft
    2012-08-28 07:11 - 2012-08-28 07:11 - 00000000 ____D C:\Program Files\Anvisoft
    2012-08-28 07:11 - 2012-08-20 01:23 - 00022864 ____A (Anvisoft) C:\Windows\System32\Drivers\asdrs.sys
    2012-08-28 07:11 - 2012-08-20 01:23 - 00016208 ____A (Anvisoft) C:\Windows\System32\Drivers\asdrm.sys
    2012-08-28 07:11 - 2012-08-20 01:23 - 00014160 ____A C:\Windows\System32\Drivers\asdws.sys
    2012-08-28 07:08 - 2012-08-28 07:08 - 16680192 ____A C:\Users\Gemma\Downloads\asdsetup_16.exe
    2012-08-28 07:01 - 2012-08-28 07:01 - 02002944 ____A (Trend Micro Inc.) C:\Users\Gemma\Downloads\HousecallLauncher(9).exe
    2012-08-28 01:18 - 2012-08-28 01:19 - 00000000 ____D C:\Users\Gemma\AppData\Local\{94447B95-2C31-450D-9891-0A31668D3720}
    2012-08-18 13:55 - 2012-08-18 13:56 - 00000000 ____D C:\Users\Gemma\AppData\Local\{D06149FA-5C31-4A05-99A9-E589DEF82FF1}
    2012-08-18 13:55 - 2012-08-18 13:55 - 00000000 ____D C:\Users\Gemma\AppData\Local\{A6A552F1-E76C-45AB-858C-F45E67BE5CC3}
    2012-08-17 14:20 - 2012-08-17 14:20 - 00000000 ____D C:\Users\Gemma\AppData\Local\{91E5961A-2EC3-4DD7-99C6-0481718275CC}
    2012-08-17 14:03 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-08-17 14:03 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-08-17 14:03 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-08-17 14:03 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-08-17 14:03 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-08-17 14:02 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-08-17 14:02 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-08-17 14:02 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-08-17 14:02 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-08-17 14:02 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-08-17 14:02 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-08-17 14:02 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-08-17 14:02 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-08-17 14:02 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-08-17 14:01 - 2012-07-04 06:02 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-08-15 11:49 - 2012-06-29 08:01 - 00467968 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
    2012-08-15 11:49 - 2012-05-11 07:57 - 00623616 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll

    ============ 3 Months Modified Files ========================

    2012-08-29 11:00 - 2006-11-02 02:33 - 00706628 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-08-29 10:59 - 2009-11-22 04:01 - 00001356 ____A C:\Users\Gemma\AppData\Local\d3d9caps.dat
    2012-08-28 22:16 - 2012-06-22 13:02 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-08-28 22:16 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    2012-08-28 22:16 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    2012-08-28 15:11 - 2008-08-26 11:04 - 01665058 ____A C:\Windows\WindowsUpdate.log
    2012-08-28 15:06 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-08-28 14:58 - 2006-11-02 05:01 - 00032536 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2012-08-28 11:42 - 2012-08-28 11:42 - 06954184 ____A C:\Users\Gemma\Downloads\spybotsd_includes.exe
    2012-08-28 11:17 - 2012-08-28 11:17 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-28 11:15 - 2012-08-28 11:15 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Gemma\Downloads\mbam-setup-1.62.0.1300.exe
    2012-08-28 10:25 - 2012-08-28 09:56 - 00001458 ____A C:\Windows\System32\avgrep.txt
    2012-08-28 07:11 - 2012-08-28 07:11 - 00000979 ____A C:\Users\Public\Desktop\Anvi Smart Defender.lnk
    2012-08-28 07:10 - 2012-02-17 12:27 - 00326277 ____A C:\Users\Gemma\AppData\Local\census.cache
    2012-08-28 07:10 - 2012-02-17 11:37 - 00185002 ____A C:\Users\Gemma\AppData\Local\ars.cache
    2012-08-28 07:08 - 2012-08-28 07:08 - 16680192 ____A C:\Users\Gemma\Downloads\asdsetup_16.exe
    2012-08-28 07:01 - 2012-08-28 07:01 - 02002944 ____A (Trend Micro Inc.) C:\Users\Gemma\Downloads\HousecallLauncher(9).exe
    2012-08-28 01:13 - 2008-01-20 18:47 - 00144932 ____A C:\Windows\PFRO.log
    2012-08-27 16:02 - 2010-06-14 13:12 - 00000402 ___AH C:\Windows\Tasks\Norton Security Scan for Gemma.job
    2012-08-24 15:34 - 2008-09-15 11:47 - 00091648 ____A C:\Users\Gemma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2012-08-20 01:23 - 2012-08-28 07:11 - 00022864 ____A (Anvisoft) C:\Windows\System32\Drivers\asdrs.sys
    2012-08-20 01:23 - 2012-08-28 07:11 - 00016208 ____A (Anvisoft) C:\Windows\System32\Drivers\asdrm.sys
    2012-08-20 01:23 - 2012-08-28 07:11 - 00014160 ____A C:\Windows\System32\Drivers\asdws.sys
    2012-08-17 14:15 - 2006-11-02 04:47 - 00381896 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-08-17 14:04 - 2006-11-02 02:24 - 59884088 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
    2012-08-14 10:52 - 2012-06-22 13:02 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
    2012-08-14 10:52 - 2011-05-15 08:32 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
    2012-07-12 12:26 - 2006-11-02 02:23 - 00000219 ____A C:\Windows\win.ini
    2012-07-07 09:48 - 2011-12-18 04:07 - 00013404 ____A C:\Users\Gemma\Desktop\Ebay.xlsx
    2012-07-07 09:32 - 2012-07-07 09:32 - 00812368 ____A (PortableApps.com) C:\Users\Gemma\Downloads\SkypePortable_5.10.0.115_online.paf.exe
    2012-07-07 09:22 - 2012-07-07 09:22 - 00946352 ____A (Skype Technologies S.A.) C:\Users\Gemma\Downloads\SkypeSetup(1).exe
    2012-07-04 06:02 - 2012-08-17 14:01 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-07-03 04:46 - 2011-05-14 10:41 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-06-29 08:01 - 2012-08-15 11:49 - 00467968 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
    2012-06-28 16:52 - 2012-08-17 14:02 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-28 16:27 - 2012-08-17 14:02 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-28 16:16 - 2012-08-17 14:02 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-28 16:09 - 2012-08-17 14:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-28 16:09 - 2012-08-17 14:02 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-28 16:08 - 2012-08-17 14:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-28 16:07 - 2012-08-17 14:02 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-28 16:06 - 2012-08-17 14:02 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-28 16:04 - 2012-08-17 14:03 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-28 16:04 - 2012-08-17 14:02 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-28 16:01 - 2012-08-17 14:03 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-28 16:01 - 2012-08-17 14:03 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-28 16:00 - 2012-08-17 14:03 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-28 15:57 - 2012-08-17 14:03 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-15 10:09 - 2012-06-15 10:09 - 02002320 ____A (Trend Micro Inc.) C:\Users\Gemma\Downloads\HousecallLauncher(.exe
    2012-06-08 09:47 - 2012-07-10 16:06 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-06-06 11:59 - 2012-06-06 11:59 - 01070152 ____A (Microsoft Corporation) C:\Windows\System32\MSCOMCTL.OCX
    2012-06-05 08:47 - 2012-07-10 16:06 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-06-05 08:47 - 2012-07-10 16:06 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-06-04 07:26 - 2012-07-10 16:06 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2012-06-02 14:19 - 2012-06-21 11:34 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-02 14:19 - 2012-06-21 11:34 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-02 14:19 - 2012-06-21 11:34 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-02 14:19 - 2012-06-21 11:34 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-02 14:19 - 2012-06-21 11:34 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-02 14:12 - 2012-06-21 11:34 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-02 14:12 - 2012-06-21 11:34 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-02 06:19 - 2012-06-21 11:33 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-02 06:12 - 2012-06-21 11:33 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-01 16:04 - 2012-07-10 16:06 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2012-06-01 16:03 - 2012-07-10 16:06 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2012-06-01 01:53 - 2006-11-02 04:52 - 00104975 ____A C:\Windows\setupact.log

    ==================== Known DLLs (Whitelisted) =================


    ==================== Bamital & volsnap Check =================

    C:\Windows\explorer.exe => MD5 is LEGIT
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================


    ==================== Memory info ===========================

    Percentage of memory in use: 17%
    Total physical RAM: 2037.31 MB
    Available physical RAM: 1683.78 MB
    Total Pagefile: 1970.94 MB
    Available Pagefile: 1846.59 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1975.56 MB

    ==================== Partitions ============================

    1 Drive c: (OS) (Fixed) (Total:99.19 GB) (Free:59.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
    3 Drive e: () (Removable) (Total:0.94 GB) (Free:0.94 GB) FAT32
    4 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:5.15 GB) NTFS

    Disk ### Status Size Free Dyn Gpt
    -------- ---------- ------- ------- --- ---
    Disk 0 Online 112 GB 0 B
    Disk 1 Online 965 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 OEM 102 MB 32 KB
    Partition 2 Primary 10 GB 102 MB
    Partition 3 Primary 99 GB 10 GB
    Partition 0 Extended 2560 MB 109 GB
    Partition 4 Logical 2559 MB 109 GB

    ==================================================================================

    Disk: 0
    Partition 1
    Type : DE
    Hidden: Yes
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 FAT Partition 102 MB Healthy Hidden

    ==================================================================================

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 X RECOVERY NTFS Partition 10 GB Healthy Boot

    ==================================================================================

    Disk: 0
    Partition 3
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 C OS NTFS Partition 99 GB Healthy

    ==================================================================================

    Disk: 0
    Partition 4
    Type : DD
    Hidden: Yes
    Active: No

    There is no volume associated with this partition.

    ==================================================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 965 MB 16 KB

    ==================================================================================

    Disk: 1
    Partition 1
    Type : 0B
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 E FAT32 Removable 965 MB Healthy

    ==================================================================================

    Last Boot: 2012-08-28 15:13

    ==================== End Of Log =============================

    Where would I find the other data log? I've SEARCHED on the laptop and can't find it?That's okay. Let's go to Safe Mode with Networking...

    ComboFix

    Please download ComboFix by sUBs
    From BleepingComputer.com

    Please save the file to your Desktop, but rename it first to svchost.exe

    [SIZE=14]Important information about ComboFix[/SIZE]

    Before the download:
    • Please copy and paste these instructions to Notepad and save to your Desktop, or print them - for easier access.
    • It is important to rename ComboFix before the download.
    • Please do not rename ComboFix to other names, but only the one indicated.
    After the download:
    • Close any open browsers.
    • Very Important: Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results". Please visit here if you don't know how.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until ComboFix has completely finished.
    • If there is no Internet connection after running ComboFix, then restart your computer to restore back your connection.
    Running ComboFix:
    • Double click on svchost.exe & follow the prompts.
    • It will attempt to install the Recovery Console:
    • When ComboFix finishes, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" in your next reply.
    [SIZE=14]Troubleshooting ComboFix[/SIZE]

    Safe Mode:

    If you still cannot get ComboFix to run, try booting into Safe Mode, and run it there.

    (To boot into Safe Mode, tap F8 after BIOS, and just before the Windows
    logo appears. A list of options will appear, select "Safe Mode.")

    Re-downloading:

    If this doesn't work either, try the same method (above method), but try to download it again, except name
    ComboFix.exe to iexplore.exe, explorer.exe, or winlogon.exe.

    Malware is known for blocking all "user" processes, except for its whitelist of system important processes such as iexplore.exe, explorer.exe, winlogon.exe.


    NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error. Hi and thanks again, I have the following

    ComboFix 12-08-30.05 - Gemma 31/08/2012 10:22:06.1.1 - x86 NETWORK
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2037.1433 [GMT 1:00]
    Running from: c:\users\Gemma\Desktop\svchost.exe.exe
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64}
    c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64}\chrome.manifest
    c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64}\chrome\content\_cfg.js
    c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64}\chrome\content\overlay.xul
    c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64}\install.rdf
    c:\users\Gemma\AppData\Local\qrly
    c:\users\Gemma\AppData\Roaming\6E3C.CA9
    c:\users\Gemma\AppData\Roaming\Adobe\plugs
    c:\users\Gemma\AppData\Roaming\Adobe\shed
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-31 )))))))))))))))))))))))))))))))
    .
    .
    2012-08-31 09:28 . 2012-08-31 09:28--------d-----w-c:\users\Default\AppData\Local\temp
    2012-08-31 09:28 . 2012-08-31 09:28--------d-----w-c:\users\Gemma\AppData\Local\temp
    2012-08-30 04:26 . 2012-08-30 04:26--------d-----w-C:\FRST
    2012-08-28 23:09 . 2012-08-28 23:10--------d-----w-c:\users\Gemma\AppData\Roaming\hellomoto
    2012-08-28 16:41 . 2012-08-28 16:41--------d-----w-C:\Temp
    2012-08-28 15:11 . 2012-08-31 08:36--------d-----w-c:\users\Gemma\AppData\Roaming\Anvisoft
    2012-08-28 15:11 . 2012-08-28 15:11--------d-----w-c:\programdata\Anvisoft
    2012-08-28 15:11 . 2012-08-28 15:11--------d-----w-c:\program files\Anvisoft
    2012-08-17 22:03 . 2012-06-29 01:00140920----a-w-c:\program files\Internet Explorer\sqmapi.dll
    2012-08-17 22:03 . 2012-06-29 00:002382848----a-w-c:\windows\system32\mshtml.tlb
    2012-08-17 22:03 . 2012-06-29 00:06194560----a-w-c:\program files\Internet Explorer\ieproxy.dll
    2012-08-17 22:03 . 2012-06-29 00:06194048----a-w-c:\program files\Internet Explorer\IEShims.dll
    2012-08-17 22:03 . 2012-06-29 00:04142848----a-w-c:\windows\system32\ieUnatt.exe
    2012-08-17 22:02 . 2012-06-29 00:161800704----a-w-c:\windows\system32\jscript9.dll
    2012-08-17 22:02 . 2012-06-29 00:091129472----a-w-c:\windows\system32\wininet.dll
    2012-08-17 22:02 . 2012-06-29 01:00748664----a-w-c:\program files\Internet Explorer\iexplore.exe
    2012-08-17 22:02 . 2012-06-29 00:10678912----a-w-c:\program files\Internet Explorer\iedvtool.dll
    2012-08-17 22:02 . 2012-06-29 00:10387584----a-w-c:\program files\Internet Explorer\jsdbgui.dll
    2012-08-17 22:02 . 2012-06-29 00:081427968----a-w-c:\windows\system32\inetcpl.cpl
    2012-08-17 22:01 . 2012-07-04 14:022047488----a-w-c:\windows\system32\win32k.sys
    2012-08-15 19:49 . 2012-05-11 15:57623616----a-w-c:\windows\system32\localspl.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-08-14 18:52 . 2012-06-22 21:02426184----a-w-c:\windows\system32\FlashPlayerApp.exe
    2012-08-14 18:52 . 2011-05-15 16:3270344----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-07-03 12:46 . 2011-05-14 18:4122344----a-w-c:\windows\system32\drivers\mbam.sys
    2012-06-06 19:59 . 2012-06-06 19:591070152----a-w-c:\windows\system32\MSCOMCTL.OCX
    2012-06-05 16:47 . 2012-07-11 00:061401856----a-w-c:\windows\system32\msxml6.dll
    2012-06-05 16:47 . 2012-07-11 00:061248768----a-w-c:\windows\system32\msxml3.dll
    2012-06-04 15:26 . 2012-07-11 00:06440704----a-w-c:\windows\system32\drivers\ksecdd.sys
    2012-06-02 22:19 . 2012-06-21 19:3453784----a-w-c:\windows\system32\wuauclt.exe
    2012-06-02 22:19 . 2012-06-21 19:3445080----a-w-c:\windows\system32\wups2.dll
    2012-06-02 22:19 . 2012-06-21 19:3435864----a-w-c:\windows\system32\wups.dll
    2012-06-02 22:19 . 2012-06-21 19:34577048----a-w-c:\windows\system32\wuapi.dll
    2012-06-02 22:19 . 2012-06-21 19:341933848----a-w-c:\windows\system32\wuaueng.dll
    2012-06-02 22:12 . 2012-06-21 19:342422272----a-w-c:\windows\system32\wucltux.dll
    2012-06-02 22:12 . 2012-06-21 19:3488576----a-w-c:\windows\system32\wudriver.dll
    2012-06-02 14:19 . 2012-06-21 19:33171904----a-w-c:\windows\system32\wuwebv.dll
    2012-06-02 14:12 . 2012-06-21 19:3333792----a-w-c:\windows\system32\wuapp.exe
    2012-07-18 20:15 . 2011-05-28 22:48136672----a-w-c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
    "Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
    "WindowsCodecsExt"="c:\users\Gemma\AppData\Local\Microsoft\Windows\228\WindowsCodecsExt.exe" [2012-08-28 75264]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
    "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVZOVgtTlNWVkwtTzRCWlEtUUlNQ0wtU
    VREQ0gtNElKTUg&inst=NzctNjI0MDU1MjQ0LVRUKzEtVDUtVUNBTEwrMS1TVDErMi1
    GUDkyKzYtQkFSOU8rMS1GTCs5LVhPMzYrMS1GOU 0xMEErMi1GOU0yKzEtRkwxMCsxLVhPMTArMTEtT ElDKzItRERUKzU4ODg5LUREMTBGKzEtU1
    QxMEZBUFArMS1GMTBNMTJUQSsxLVUxMCsxLVZJU DEyKzEtRjEwTTEyUisxLUYxME0xMlIyKzEtQ0lE MTArMS1DSUQrMTA∏=90&ver=10.0.1424" [?]
    .
    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-5-13 1058088]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
    2010-10-13 18:0916680----a-w-c:\program files\Citrix\GoToAssist\570\g2awinlogon.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "mixer1"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
    backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
    backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^Users^Gemma^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
    path=c:\users\Gemma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
    backup=c:\windows\pss\Dell Dock.lnk.Startup
    backupExtension=.Startup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2008-10-15 01:0439792----a-w-c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
    2008-05-04 09:25167936----a-w-c:\program files\DellTPad\Apoint.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
    2008-05-16 12:173444736----a-w-c:\windows\System32\WLTRAY.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_McciTrayApp]
    2009-12-07 11:501584640----a-w-c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DACSMiniApp]
    2007-07-24 11:20197888----a-w-c:\program files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
    2011-07-28 23:081259376----a-w-c:\program files\DivX\DivX Update\DivXUpdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
    2008-02-29 04:1817920----a-w-c:\dell\E-Center\EULALauncher.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
    2008-01-21 02:25125952----a-w-c:\windows\ehome\ehtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    2009-02-26 18:3630040----a-w-c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2008-03-06 07:58166424----a-w-c:\windows\System32\hkcmd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
    2007-03-21 12:00174872----a-w-c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2008-03-06 07:58141848----a-w-c:\windows\System32\igfxtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
    2012-07-03 12:46973488----a-w-c:\program files\Malwarebytes' Anti-Malware\mbam.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
    2012-03-08 17:504280184----a-w-c:\program files\Windows Live\Messenger\msnmsgr.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
    2007-12-21 09:58184320----a-w-c:\program files\Dell\MediaDirect\PCMService.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
    2008-03-06 07:58133656----a-w-c:\windows\System32\igfxpers.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
    2007-11-12 11:07405504----a-w-c:\program files\Sigmatel\C-Major Audio\WDM\sttray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    2012-07-13 12:3317418928----a-r-c:\program files\Skype\Phone\Skype.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
    2009-06-18 09:04772096----a-w-c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
    2004-01-26 10:38866816----a-w-c:\program files\Thomson\SpeedTouch USB\dragdiag.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
    2009-03-05 15:072260480--sha-r-c:\program files\Spybot - Search & Destroy\TeaTimer.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2010-05-14 10:44248552----a-w-c:\program files\Common Files\Java\Java Update\jusched.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2010-05-20 22:40202256----a-w-c:\program files\Common Files\Real\Update_OB\realsched.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
    2009-11-13 11:31247144----a-w-c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    2008-01-21 02:231008184----a-w-c:\program files\Windows Defender\MSASCui.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    .
    R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe

    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - ECACHE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-08-29 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-22 18:52]
    .
    2012-08-28 c:\windows\Tasks\Norton Security Scan for Gemma.job
    - c:\progra~1\NORTON~2\Engine\301~1.8\Nss.exe [2011-01-26 01:45]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uSearchMigratedDefaultURL = hxxp://search.orange.co.uk/all?brand=ouk&tab=web&p=_adr&q={searchTerms}
    mWindow Title = Microsoft Internet Explorer Provided by Wanadoo
    uInternet Settings,ProxyOverride =
    uInternet Settings,ProxyServer = http=127.0.0.1:58343
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 192.168.1.254
    FF - ProfilePath - c:\users\Gemma\AppData\Roaming\Mozilla\Firefox\Profiles\75cd0c58.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=1eic6yu9oa4y3&scc=1&ltmpl=default&ltmplcache=2
    FF - prefs.js: keyword.URL - hxxp://flvtubesearch.co/?prt=02ff&clid=&subid=&Keywords=
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 58343
    FF - prefs.js: network.proxy.type - 4
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-BigBitmap - (no file)
    Toolbar-SmallBitmap - (no file)
    HKLM-Run-dellsupportcenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
    MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
    MSConfigStartUp-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
    MSConfigStartUp-dscactivate - c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
    MSConfigStartUp-ISTray - c:\program files\Spyware Doctor\pctsTray.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-08-31 10:28
    Windows 6.0.6002 Service Pack 2 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020101}_0]
    "ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2012-08-31 10:32:28
    ComboFix-quarantined-files.txt 2012-08-31 09:32
    .
    Pre-Run: 65,570,836,480 bytes free
    Post-Run: 66,023,469,056 bytes free
    .
    - - End Of File - - 3B5C74C0FDE1CAB09C16CC280DEE2D21
    Please download aswMBR from here

    • Save aswMBR.exe to your Desktop
    • Double click aswMBR.exe to run it
    • Click the Scan button to start the scan as illustrated below


    Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives

    • Once the scan finishes click Save log to save the log to your Desktop


    • Copy and paste the contents of aswMBR.txt back here for review
    I've got the following

    aswMBR version 0.9.9.1665 COPYRIGHT(c) 2011 AVAST Software
    Run date: 2012-08-31 13:17:32
    -----------------------------
    13:17:32.961 OS Version: Windows 6.0.6002 Service Pack 2
    13:17:32.961 Number of processors: 1 586 0x1601
    13:17:32.961 ComputerName: GEMMA-PC UserName: Gemma
    13:17:50.433 Initialize success
    13:18:08.717 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
    13:18:08.717 Disk 0 Vendor: ST912081 3.AD Size: 114473MB BusType: 3
    13:18:08.748 Disk 0 MBR read successfully
    13:18:08.748 Disk 0 MBR scan
    13:18:08.763 Disk 0 Windows VISTA default MBR code
    13:18:08.779 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 101 MB offset 63
    13:18:08.795 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 208896
    13:18:08.810 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 101569 MB offset 21180416
    13:18:08.810 Disk 0 Partition - 00 0F Extended LBA 2560 MB offset 229195776
    13:18:08.888 Disk 0 Partition 4 00 DD MSDOS5.0 2559 MB offset 229197824
    13:18:08.919 Disk 0 scanning sectors +234438656
    13:18:09.044 Disk 0 scanning C:\Windows\system32\drivers
    13:18:16.220 Service scanning
    13:18:38.591 Modules scanning
    13:18:44.300 Disk 0 trace - called modules:
    13:18:44.347 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
    13:18:44.347 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b02f878]
    13:18:44.363 3 CLASSPNP.SYS[8d9a78b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8a5c0030]
    13:18:44.363 Scan finished successfully
    13:41:27.849 Disk 0 MBR has been saved successfully to "C:\Users\Gemma\Desktop\MBR.dat"
    13:41:27.865 The log file has been saved successfully to "C:\Users\Gemma\Desktop\aswMBR.txt"


    Thanks again, I appreciate your help!Excellent work!

    ESET Online Scan

    Please run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install, or it will ask to download an installer. Please do so an install it.
    • Click Start or wait for the scanner to load.
    • Make sure that the options Remove found threats and the option Scan unwanted applications are checked.
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, there are a couple of things to keep in mind:
    • 1. If NO threats were found, allow the scanner to Uninstall on close and then close the Window.
    • 2. If threats WERE detected, click on List of Threats Found, Export to Text File...save it as ESET-Scan-Log.txt. Click the back button/link, put a checkmark to Uninstall Application on Close and then close the window.
    • Open the logfile from wherever you saved it
    • Copy and paste the contents in your next reply.
    7 threats found

    C:\Users\Gemma\AppData\Local\Microsoft\Windows\228\WindowsCodecsExt.exea variant of Win32/Kryptik.ALBD trojancleaned by deleting - quarantined
    C:\Users\Gemma\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\120217225646367.rsc_tmpmultiple threatsdeleted - quarantined
    C:\Users\Gemma\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\120217231620925.rscmultiple threatsdeleted - quarantined
    C:\Users\Gemma\AppData\Roaming\B4414EE8A7520B62EDE608ED711EDA7A\enemies-names.txtWin32/Adware.AntimalwareDoctor.AE.Gen applicationcleaned by deleting - quarantined
    C:\Users\Gemma\AppData\Roaming\B4414EE8A7520B62EDE608ED711EDA7A\local.iniWin32/Adware.AntimalwareDoctor.AE.Gen applicationcleaned by deleting - quarantined
    C:\Users\Gemma\Downloads\BitZipper50TrialSetupEn.exea variant of Win32/InstallIQ applicationcleaned by deleting - quarantined
    C:\Users\Gemma\Downloads\BitZipperH2010.v8326484.TrialSetupEn.exea variant of Win32/InstallIQ applicationcleaned by deleting - quarantined

    ThanksAny more issues?

    We need to know any other issues that are plaguing your computer. Kindly give a summary so we know how to continue from here.

    Many of the things to note for us would be:

    • Slow computer
    • Error messages
    • Fake antivirus alerts or the icon in the system tray
    • svchost.exe running at 100%
    • System crashes or blue screen of death
    Sorry I was away for the weekend. All seems well thank you very much

    Is there a good free anti virus you can recommend?

    Thanks again!Let's clean up, then you will be able to see them. This is preventative measures to make sure you don't get infected again...

    Clean up System Restore

    Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."

    To manually create a new Restore Point
    • Go to Control Panel and select System and Maintenance
    • Select System
    • On the left select Advance System Settings and accept the warning if you get one
    • Select System Protection Tab
    • Select Create at the bottom
    • Type in a name i.e. Clean
    • Select Create
    Now we can purge the infected ones
    • Go back to the System and Maintenance page
    • Select Performance Information and Tools
    • On the left select Open Disk Cleanup
    • Select Files from all users and accept the warning if you get one
    • In the drop down box select your main drive i.e. C
    • For a few moments the system will make some calculations:

    • Select the More Options tab

    • In the System Restore and Shadow Backups select Clean up

    • Select Delete on the pop up
    • Select OK
    • Select Delete
    Run OTC to remove our tools

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    Purge old temporary files

    Download CCleaner Slim and save it to your Desktop - Alternate download link

    When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
    Follow the prompts to install the program.

    * Double-click the CCleaner shortcut on the desktop to start the program.
    * Click on the Options block on the left, then choose Cookies.
    * Under Cookies to Delete, highlight any cookies you would like to retain permanently
    * Click the right arrow > to move them to the Cookies to Keep window.
    * Go into Options > Advanced & uncheck Only delete files in Windows Temp folders older than 48 hours
    * Click Cleaner on the left then Run Cleaner on the right to run the program.
    * Important: Make sure that ALL browser windows are closed before selecting Run Cleaner

    Caution: Only use the Registry feature if you are very familiar with the registry.
    Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

    Security Check

    Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    102.

    Solve : FireFox hanging +?

    Answer»

    Firefox 15 is hanging and unresponsive. Tried re-installing etc. MB says it is clean and dds and adwcleaner say ok. IExplorer seems to be ok. Below is combo fix.
    ComboFix 12-08-31.08 - Cesare 01/09/2012 12:52:46.1.4 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.2815.1325 [GMT 1:00]
    Running from: c:\users\Cesare\Downloads\ComboFix.exe
    AV: Lavasoft Ad-Aware *Enabled/Updated* {445B48C3-0FA4-6B16-8F07-6506F305D800}
    AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    FW: Lavasoft Ad-Aware *Disabled* {7C60C9E6-45CB-6A4E-A458-CC330DD69F7B}
    SP: Lavasoft Ad-Aware *Enabled/Updated* {FF3AA927-299E-6498-B5B7-5E74888292BD}
    SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files (x86)\Common Files\packardbell.ico
    c:\programdata\FullRemove.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-08-01 to 2012-09-01 )))))))))))))))))))))))))))))))
    .
    .
    2012-09-01 12:03 . 2012-09-01 12:03--------d-----w-c:\users\LogMeInRemoteUser\AppData\Local\temp
    2012-09-01 12:03 . 2012-09-01 12:03--------d-----w-c:\users\Default\AppData\Local\temp
    2012-09-01 08:11 . 2012-09-01 08:11--------d-----w-c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-09-01 08:11 . 2012-07-03 12:4624904----a-w-c:\windows\system32\drivers\mbam.sys
    2012-09-01 07:15 . 2012-07-13 13:08504136----a-w-c:\windows\system32\EasyRedirect64.dll
    2012-09-01 07:15 . 2012-07-13 13:08364360----a-w-c:\windows\SysWow64\EasyRedirect.dll
    2012-09-01 07:14 . 2012-09-01 07:14--------d-----w-c:\program files\Easy-Hide-IP
    2012-08-31 17:52 . 2012-08-23 08:269310152----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FBA07272-DF88-43EC-9087-B27B39FA6B1B}\mpengine.dll
    2012-08-31 16:40 . 2012-08-31 16:40--------d-----w-c:\users\Cesare\AppData\Local\adaware
    2012-08-31 16:40 . 2012-09-01 08:03--------d-----w-c:\programdata\Ad-Aware Browsing Protection
    2012-08-31 16:40 . 2011-12-19 11:4460536----a-w-c:\windows\system32\drivers\sbhips.sys
    2012-08-31 16:40 . 2011-12-19 12:2145936----a-w-c:\windows\system32\sbbd.exe
    2012-08-31 16:40 . 2011-10-26 13:2357976----a-w-c:\windows\system32\drivers\sbredrv.sys
    2012-08-31 16:40 . 2012-08-31 16:40--------d-----w-c:\programdata\Lavasoft
    2012-08-31 16:40 . 2012-08-31 17:17--------d-----w-c:\program files (x86)\Ad-Aware Antivirus
    2012-08-31 16:39 . 2012-08-31 16:39--------d-----w-c:\users\Cesare\AppData\Local\Downloaded Installations
    2012-08-31 16:38 . 2012-08-31 18:25--------d-----w-c:\users\Cesare\AppData\Roaming\Ad-Aware Antivirus
    2012-08-31 09:06 . 2012-06-26 10:25773968----a-w-c:\windows\system32\msvcr100.dll
    2012-08-31 03:59 . 2009-05-18 12:1734152----a-w-c:\windows\system32\drivers\GEARAspiWDM.sys
    2012-08-31 03:59 . 2008-04-17 11:12126312----a-w-c:\windows\system32\GEARAspi64.dll
    2012-08-31 03:59 . 2008-04-17 11:12107368----a-w-c:\windows\SysWow64\GEARAspi.dll
    2012-08-31 03:58 . 2012-08-31 03:58--------d-----w-c:\program files\iPod
    2012-08-31 03:58 . 2012-08-31 03:59--------d-----w-c:\program files\iTunes
    2012-08-31 03:58 . 2012-08-31 03:59--------d-----w-c:\program files (x86)\iTunes
    2012-08-31 03:18 . 2012-08-31 03:18--------d-----w-c:\program files\Bonjour
    2012-08-30 17:56 . 2012-08-30 17:56--------d-----w-c:\programdata\Okidata
    2012-08-30 17:53 . 2012-08-23 08:269310152----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2012-08-30 17:48 . 2010-09-10 04:4967584----a-w-c:\windows\system32\okis2lna64.dll
    2012-08-30 17:48 . 2010-01-27 05:05105984----a-w-c:\windows\system32\okscllna64.dll
    2012-08-29 07:24 . 2012-08-29 07:24--------d-----w-c:\users\Cesare\AppData\Roaming\iFunbox_UserCache
    2012-08-29 07:24 . 2012-08-29 07:24--------d-----w-c:\program files (x86)\i-Funbox DevTeam
    2012-08-28 18:19 . 2012-08-28 18:19--------d-----w-c:\users\Cesare\AppData\Local\Macromedia
    2012-08-28 18:04 . 2012-08-28 18:04--------d-----w-c:\program files (x86)\Common Files\IVA
    2012-08-28 18:04 . 2012-08-28 18:04--------d-----w-c:\program files (x86)\Common Files\Nuance
    2012-08-28 18:02 . 2012-08-28 18:02--------d-----w-c:\programdata\Macrovision
    2012-08-28 17:35 . 2012-08-28 17:35--------d-----w-c:\program files (x86)\Creative
    2012-08-28 12:29 . 2012-08-28 12:29--------d-----w-c:\users\Default\AppData\Local\Microsoft Help
    2012-08-28 12:26 . 2012-08-28 12:26--------d-----w-c:\program files (x86)\Microsoft Security Client
    2012-08-28 12:00 . 2003-11-10 17:14729088----a-w-c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
    2012-08-28 12:00 . 2003-11-10 17:1369715----a-w-c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
    2012-08-28 12:00 . 2003-11-10 17:12266240----a-w-c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
    2012-08-28 12:00 . 2003-11-10 17:12192512----a-w-c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
    2012-08-28 12:00 . 2003-11-10 17:115632----a-w-c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
    2012-08-28 12:00 . 2012-08-28 12:00311428----a-w-c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
    2012-08-28 12:00 . 2012-08-28 12:00188548----a-w-c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
    2012-08-28 11:59 . 2012-08-28 11:59--------d-----w-C:\Live! Cam
    2012-08-28 11:59 . 2007-06-14 08:5499328----a-w-c:\windows\CtDrvIns.exe
    2012-08-28 11:59 . 2007-02-15 12:26811008----a-w-c:\windows\SysWow64\cximage.dll
    2012-08-28 11:59 . 2005-07-07 00:0725088----a-w-c:\windows\system32\CtCamMgr.dll
    2012-08-28 10:33 . 2012-08-28 10:33--------d-----w-c:\program files (x86)\Enigma Software Group
    2012-08-28 10:31 . 2012-08-31 15:50--------d-----w-c:\windows\CC1F6DA021D2425AB1B65B164A598450.TMP
    2012-08-28 10:31 . 2012-08-28 10:31--------d-----w-c:\program files (x86)\Common Files\Wise Installation Wizard
    2012-08-28 10:26 . 2012-08-28 12:17426184----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
    2012-08-28 10:24 . 2012-08-28 10:24--------d-----w-c:\users\Cesare\AppData\Local\Scansoft
    2012-08-28 10:17 . 2012-02-09 13:17927800------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
    2012-08-28 10:17 . 2012-02-09 13:17927800------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E6383379-76B9-4ABD-AAAB-7777CCF30B6D}\gapaengine.dll
    2012-08-28 10:05 . 2012-08-28 10:05--------d-----w-c:\windows\Temp250F8E53-DD37-B6DA-3FAD-F7846A9417EE-Signatures
    2012-08-28 10:00 . 2012-03-01 06:4623408----a-w-c:\windows\system32\drivers\fs_rec.sys
    2012-08-28 10:00 . 2012-03-01 06:3381408----a-w-c:\windows\system32\imagehlp.dll
    2012-08-28 10:00 . 2012-03-01 05:33159232----a-w-c:\windows\SysWow64\imagehlp.dll
    2012-08-28 10:00 . 2012-03-01 06:38220672----a-w-c:\windows\system32\wintrust.dll
    2012-08-28 10:00 . 2012-03-01 06:285120----a-w-c:\windows\system32\wmi.dll
    2012-08-28 10:00 . 2012-03-01 05:37172544----a-w-c:\windows\SysWow64\wintrust.dll
    2012-08-28 10:00 . 2012-03-01 05:295120----a-w-c:\windows\SysWow64\wmi.dll
    2012-08-28 09:30 . 2012-05-04 09:59514560----a-w-c:\windows\SysWow64\qdvd.dll
    2012-08-28 09:30 . 2012-05-04 11:00366592----a-w-c:\windows\system32\qdvd.dll
    2012-08-28 09:09 . 2012-08-28 09:09--------d-----w-c:\program files (x86)\Common Files\Skype
    2012-08-28 09:04 . 2012-03-03 06:351544704----a-w-c:\windows\system32\DWrite.dll
    2012-08-28 09:04 . 2012-03-03 05:311077248----a-w-c:\windows\SysWow64\DWrite.dll
    2012-08-28 09:04 . 2012-05-05 08:36503808----a-w-c:\windows\system32\srcore.dll
    2012-08-28 09:04 . 2012-05-05 07:4643008----a-w-c:\windows\SysWow64\srclient.dll
    2012-08-28 09:03 . 2011-10-01 05:45886784----a-w-c:\program files\Common Files\System\wab32.dll
    2012-08-28 09:03 . 2011-10-01 04:37708608----a-w-c:\program files (x86)\Common Files\System\wab32.dll
    2012-08-28 09:03 . 2011-10-26 05:251572864----a-w-c:\windows\system32\quartz.dll
    2012-08-28 09:03 . 2011-10-26 04:321328128----a-w-c:\windows\SysWow64\quartz.dll
    2012-08-28 09:02 . 2012-01-04 10:44509952----a-w-c:\windows\system32\ntshrui.dll
    2012-08-28 09:02 . 2012-01-04 08:58442880----a-w-c:\windows\SysWow64\ntshrui.dll
    2012-08-28 09:01 . 2011-11-17 06:35395776----a-w-c:\windows\system32\webio.dll
    2012-08-28 09:01 . 2011-11-17 05:35314880----a-w-c:\windows\SysWow64\webio.dll
    2012-08-28 09:01 . 2012-06-06 06:062004480----a-w-c:\windows\system32\msxml6.dll
    2012-08-28 09:01 . 2012-06-06 06:061881600----a-w-c:\windows\system32\msxml3.dll
    2012-08-28 09:01 . 2012-06-06 05:051390080----a-w-c:\windows\SysWow64\msxml6.dll
    2012-08-28 09:01 . 2012-06-06 05:051236992----a-w-c:\windows\SysWow64\msxml3.dll
    2012-08-28 09:01 . 2010-06-26 03:552048----a-w-c:\windows\system32\msxml3r.dll
    2012-08-28 09:01 . 2010-06-26 03:242048----a-w-c:\windows\SysWow64\msxml3r.dll
    2012-08-28 09:00 . 2011-10-26 05:2143520----a-w-c:\windows\system32\csrsrv.dll
    2012-08-28 09:00 . 2011-12-30 06:26515584----a-w-c:\windows\system32\timedate.cpl
    2012-08-28 09:00 . 2011-12-30 05:27478720----a-w-c:\windows\SysWow64\timedate.cpl
    2012-08-28 09:00 . 2012-02-11 06:43751104----a-w-c:\windows\system32\win32spl.dll
    2012-08-28 08:59 . 2012-02-11 06:36559104----a-w-c:\windows\system32\spoolsv.exe
    2012-08-28 08:59 . 2012-02-11 06:3667072----a-w-c:\windows\splwow64.exe
    2012-08-28 08:59 . 2012-02-11 05:43492032----a-w-c:\windows\SysWow64\win32spl.dll
    2012-08-28 08:58 . 2012-08-28 08:58--------d-----w-c:\programdata\InstallShield
    2012-08-28 08:58 . 2012-08-28 08:58--------d-----w-c:\users\Cesare\AppData\Roaming\ScanSoft
    2012-08-28 08:58 . 2012-06-09 05:4314172672----a-w-c:\windows\system32\shell32.dll
    2012-08-28 08:58 . 2012-08-28 08:58--------d-----w-c:\program files (x86)\ScanSoft
    2012-08-28 08:56 . 2012-05-01 05:40209920----a-w-c:\windows\system32\profsvc.dll
    2012-08-28 08:55 . 2012-05-04 11:065559664----a-w-c:\windows\system32\ntoskrnl.exe
    2012-08-28 08:55 . 2012-05-04 10:033968368----a-w-c:\windows\SysWow64\ntkrnlpa.exe
    2012-08-28 08:55 . 2012-05-04 10:033913072----a-w-c:\windows\SysWow64\ntoskrnl.exe
    2012-08-28 08:54 . 2011-08-17 05:26613888----a-w-c:\windows\system32\psisdecd.dll
    2012-08-28 08:54 . 2011-08-17 04:24465408----a-w-c:\windows\SysWow64\psisdecd.dll
    2012-08-28 08:54 . 2011-08-17 04:1975776----a-w-c:\windows\SysWow64\psisrndr.ax
    2012-08-28 08:54 . 2011-08-17 05:25108032----a-w-c:\windows\system32\psisrndr.ax
    2012-08-28 08:53 . 2012-04-28 03:55210944----a-w-c:\windows\system32\drivers\rdpwd.sys
    2012-08-28 08:53 . 2011-12-28 03:59498688----a-w-c:\windows\system32\drivers\afd.sys
    2012-08-28 08:52 . 2012-03-17 07:5875120----a-w-c:\windows\system32\drivers\partmgr.sys
    2012-08-28 08:52 . 2012-04-07 12:313216384----a-w-c:\windows\system32\msi.dll
    2012-08-28 08:52 . 2012-04-07 11:262342400----a-w-c:\windows\SysWow64\msi.dll
    2012-08-28 08:52 . 2012-04-24 05:371462272----a-w-c:\windows\system32\crypt32.dll
    2012-08-28 08:52 . 2012-04-24 05:37184320----a-w-c:\windows\system32\cryptsvc.dll
    2012-08-28 08:52 . 2012-04-24 05:37140288----a-w-c:\windows\system32\cryptnet.dll
    2012-08-28 08:52 . 2012-04-24 04:36140288----a-w-c:\windows\SysWow64\cryptsvc.dll
    2012-08-28 08:52 . 2012-04-24 04:361158656----a-w-c:\windows\SysWow64\crypt32.dll
    2012-08-28 08:52 . 2012-04-24 04:36103936----a-w-c:\windows\SysWow64\cryptnet.dll
    2012-08-28 08:51 . 2012-07-04 22:1359392----a-w-c:\windows\system32\browcli.dll
    2012-08-28 08:51 . 2012-07-04 22:13136704----a-w-c:\windows\system32\browser.dll
    2012-08-28 08:51 . 2012-07-04 22:1673216----a-w-c:\windows\system32\netapi32.dll
    2012-08-28 08:51 . 2012-07-04 21:1441984----a-w-c:\windows\SysWow64\browcli.dll
    2012-08-28 08:50 . 2011-12-16 08:46634880----a-w-c:\windows\system32\msvcrt.dll
    2012-08-28 08:50 . 2011-12-16 07:52690688----a-w-c:\windows\SysWow64\msvcrt.dll
    2012-08-28 08:49 . 2012-07-18 18:153148800----a-w-c:\windows\system32\win32k.sys
    2012-08-28 08:48 . 2012-05-14 05:26956928----a-w-c:\windows\system32\localspl.dll
    2012-08-28 08:48 . 2011-08-27 05:37861696----a-w-c:\windows\system32\oleaut32.dll
    2012-08-28 08:48 . 2011-08-27 05:37331776----a-w-c:\windows\system32\oleacc.dll
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-08-28 12:17 . 2011-06-15 13:2570344----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-08-03 03:27 . 2011-06-15 08:0262134624----a-w-c:\windows\system32\MRT.exe
    2012-06-25 15:04 . 2012-06-25 15:041394248----a-w-c:\windows\SysWow64\msxml4.dll
    2012-06-06 07:49 . 2012-06-06 07:491070152----a-w-c:\windows\SysWow64\MSCOMCTL.OCX
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty ENTRIES & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{73A89C60-CF59-4EC7-9215-9B7EF05ECEA4}]
    2012-07-18 18:26195448----a-w-c:\program files (x86)\Nuance\NaturallySpeaking12\Program\ieshim.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:3694208----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:3694208----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:3694208----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:3694208----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
    "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-28 39408]
    "Easy-Hide-IP"="c:\program files\Easy-Hide-IP\easy-hide-ip.exe" [2012-07-13 4612424]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]
    "Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2011-10-21 198032]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
    "Malwarebytes Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
    .
    c:\users\Cesare\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dropbox.lnk - c:\users\Cesare\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
    OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Stickies.lnk - c:\program files (x86)\Stickies\stickies.exe [2008-1-16 1122304]
    Wi-Fire Connection Manager.lnk - c:\program files (x86)\hField Technologies, Inc\Wi-Fire Connection Manager\Wi-Fire Connection Manager.exe [2011-8-25 417792]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security PackagesREG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
    @="Ad-Aware Service"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
    @="Service"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
    @="Service"
    .
    R2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-07-12 1239952]
    R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-28 135664]
    R2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2011-12-19 3289032]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-28 250056]
    R3 esgiguard;esgiguard;c:\program files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys


    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-28 135664]
    R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2010-04-19 22528]
    R3 netr28ux;Belkin N+ Wireless USB Adapter Driver;c:\windows\system32\DRIVERS\netr28ux.sys [2011-06-14 1061888]
    R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
    R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe

    R3 sbhips;sbhips;c:\windows\system32\drivers\sbhips.sys [2011-12-19 60536]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-04-25 52736]
    R3 VF0350Afx;VF0350 Audio FX;c:\windows\system32\Drivers\V0350Afx.sys [2007-06-11 214240]
    R3 VF0350Vfx;VF0350 Video FX;c:\windows\system32\DRIVERS\V0350VFx.sys [2007-03-05 12288]
    R3 VF0350Vid;Live! Cam Video IM (VF0350);c:\windows\system32\DRIVERS\V0350Vid.sys [2007-08-29 214976]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-14 1255736]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-06-16 55024]
    S1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [2011-10-26 57976]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-08 169312]
    S2 DragonSvc;Dragon Service;c:\program files (x86)\Common Files\Nuance\dgnsvc.exe [2012-07-18 310232]
    S2 EasyRedirect;EasyRedirect;c:\program files\Easy-Hide-IP\rdr\EasyRedirect.exe [2012-07-13 3542856]
    S2 OberonGameConsoleService;Oberon Media Game Console service;c:\program files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe [2009-08-29 44312]
    S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-02-10 144672]
    S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [2011-11-29 74872]
    S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2009-07-04 240160]
    S3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\system32\DRIVERS\athrxusb.sys [2008-07-28 1075712]
    S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2009-08-21 84512]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-08-31 c:\windows\Tasks\0.job
    - c:\program files (x86)\internet explorer\iexplore.exe [2012-08-28 01:00]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:3697792----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:3697792----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:3697792----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:3697792----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.bbc.co.uk/
    uLocal Page = c:\windows\system32\blank.htm
    mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0809&m=imedia_s3720&r=173606119306p03f5v1k5y4721031q
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: Free YouTube Download - c:\users\Cesare\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
    IE: Free YouTube to MP3 Converter - c:\users\Cesare\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    IE: OPEN with PDF Viewer Plus - c:\program files (x86)\Nuance\PDFViewerPlus\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
    IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
    LSP: c:\windows\system32\EasyRedirect.dll
    TCP: DhcpNameServer = 192.168.1.1
    FF - ProfilePath - c:\users\Cesare\AppData\Roaming\Mozilla\Firefox\Profiles\sdbtzu4f.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.bbc.co.uk/
    FF - prefs.js: network.proxy.type - 0
    .
    .
    ------- File Associations -------
    .
    JSEFile=NOTEPAD.EXE %1
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    Toolbar-Locked - (no file)
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    @Denied: (A) (Everyone)
    "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    @Denied: (A) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    "Key"="ActionsPane3"
    "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2012-09-01 13:20:52
    ComboFix-quarantined-files.txt 2012-09-01 12:20
    .
    Pre-Run: 36,748,992,512 bytes free
    Post-Run: 36,613,259,264 bytes free
    .
    - - End Of File - - 5FBC790BC3BB303F89368B4FD269C0CB


    [year+ old attachment deleted by admin]Hi there.

    Please download aswMBR from here

    • Save aswMBR.exe to your Desktop
    • Double click aswMBR.exe to run it
    • Click the Scan button to start the scan as illustrated below


    Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives

    • Once the scan finishes click Save log to save the log to your Desktop


    • Copy and paste the contents of aswMBR.txt back here for review
    Thanks DMJ
    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-09-01 19:46:42
    -----------------------------
    19:46:42.604 OS Version: Windows x64 6.1.7601 Service Pack 1
    19:46:42.604 Number of processors: 4 586 0x170A
    19:46:42.605 ComputerName: CESARE-PC UserName: Cesare
    19:46:43.393 Initialize success
    19:48:40.504 AVAST engine defs: 12090100
    19:48:54.964 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005c
    19:48:54.968 Disk 0 Vendor: Hitachi_ ST2O Size: 305245MB BusType: 3
    19:48:55.021 Disk 0 MBR read successfully
    19:48:55.027 Disk 0 MBR scan
    19:48:55.037 Disk 0 Windows 7 default MBR code
    19:48:55.045 Disk 0 Partition 1 00 42 SFS 0 MB offset 63
    19:48:55.072 Disk 0 Partition 2 00 27 Hidden NTFS WinRE NTFS 15360 MB offset 2048
    19:48:55.087 Disk 0 Partition 3 80 (A) 42 SFS NTFS 100 MB offset 31459328
    19:48:55.103 Disk 0 Partition 4 00 42 SFS NTFS 144846 MB offset 31664128
    19:48:55.111 Disk 0 scanning C:\Windows\system32\drivers
    19:48:55.119 Service scanning
    19:49:23.738 Modules scanning
    19:49:23.750 Disk 0 trace - called modules:
    19:49:23.770 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor64.sys
    19:49:24.011 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800334b060]
    19:49:24.019 3 CLASSPNP.SYS[fffff88001bbd43f] -> nt!IofCallDriver -> [0xfffffa8002fc2e40]
    19:49:24.031 5 ACPI.sys[fffff88000f877a1] -> nt!IofCallDriver -> \Device\0000005c[0xfffffa8002fb66f0]
    19:49:25.130 AVAST engine scan C:\Windows
    19:49:25.139 AVAST engine scan C:\Windows\system32
    19:49:25.152 AVAST engine scan C:\Windows\system32\drivers
    19:49:25.162 AVAST engine scan C:\Users\Cesare
    19:49:25.173 AVAST engine scan C:\ProgramData
    19:49:25.183 Scan finished successfully
    19:49:58.375 Disk 0 MBR has been saved successfully to "C:\Users\Cesare\Desktop\MBR.dat"
    19:49:58.389 The log file has been saved successfully to "C:\Users\Cesare\Desktop\aswMBR001.txt"


    Please download AdwCleaner by Xplode onto your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Search.
    • A logfile will automatically open after the scan has finished.
    • Please post the content of that logfile in your reply.
    • You can find the logfile at C:\AdwCleaner[Rn].txt as well - n is the order number.
    # AdwCleaner v2.000 - Logfile created 09/02/2012 at 23:16:08
    # Updated 30/08/2012 by Xplode
    # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
    # User : Cesare - CESARE-PC
    # Boot Mode : Normal
    # Running from : C:\Users\Cesare\Downloads\adwcleaner.exe
    # Option [Search]


    ***** [Services] *****


    ***** [Files / Folders] *****


    ***** [Registry] *****


    ***** [Internet Browsers] *****

    -\\ Internet Explorer v9.0.8112.16421

    [OK] Registry is clean.

    -\\ Mozilla Firefox v15.0 (en-US)

    Profile name : default
    File : C:\Users\Cesare\AppData\Roaming\Mozilla\Firefox\Profiles\sdbtzu4f.default\prefs.js

    [OK] File is clean.

    -\\ Google Chrome v [Unable to get version]

    File : C:\Users\Cesare\AppData\Local\Google\Chrome\User Data\Default\Preferences

    [OK] File is clean.

    -\\ Opera v11.11.2109.0

    File : C:\Users\Cesare\AppData\Roaming\Opera\Opera\operaprefs.ini

    [OK] File is clean.

    *************************

    AdwCleaner[S1].txt - [5842 octets] - [01/09/2012 09:01:21]
    AdwCleaner[R1].txt - [1179 octets] - [02/09/2012 12:22:01]
    AdwCleaner[S2].txt - [1390 octets] - [02/09/2012 12:22:21]
    AdwCleaner[R2].txt - [1151 octets] - [02/09/2012 23:16:08]

    ########## EOF - C:\AdwCleaner[R2].txt - [1211 octets] ##########

    Cheers
    altvicRogueKiller log:
    RogueKiller V8.0.2 [08/31/2012] by Tigzy
    mail: tigzyRKgmailcom
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : Cesare [Admin rights]
    Mode : Scan -- Date : 09/02/2012 23:20:52

    ¤¤¤ Bad processes : 3 ¤¤¤
    [RESIDUE] iexplore.exe -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -> KILLED [TermProc]
    [RESIDUE] iexplore.exe -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -> KILLED [TermProc]
    [RESIDUE] iexplore.exe -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -> KILLED [TermThr]

    ¤¤¤ Registry Entries : 11 ¤¤¤
    [TASK][ROGUE ST] 0.job : c:\program files (x86)\internet explorer\iexplore.exe -> FOUND
    [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
    [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
    [HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
    [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
    [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
    [HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    [FILEASSO] HKLM\[...]\command : ("C:\Program Files (x86)\Internet Explorer\iexplore.exe") -> FOUND

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED] ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\Windows\system32\drivers\etc\hosts

    127.0.0.1 localhost


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: Hitachi HDT721032SLA SCSI Disk Device +++++
    --- User ---
    [MBR] b6fca15b00ab5cfcd59958d591ebc78d
    [BSP] 018e58c0f60582cf2d35679dcc2f8b1b : Windows 7 MBR Code
    Partition table:
    0 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 63 | Size: 0 Mo
    1 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 Mo
    2 - [ACTIVE] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 31459328 | Size: 100 Mo
    3 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 31664128 | Size: 144846 Mo
    User = LL1 ... OK!
    Error reading LL2 MBR!

    Finished : << RKreport[1].txt >>
    RKreport[1].txt



    Please download and run TDSSKiller to your desktop as outlined below:

    Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

    For Windows XP, double-click to start.
    For Vista or Windows 7, do a right-click on the program, select Run as ADMINISTRATOR to start, & when PROMPTED Allow to run.




    -------------------------

    Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.



    ------------------------

    Click the Start Scan button.



    -----------------------

    If a suspicious object is detected, the default action will be Skip, click on Continue
    If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
    Skip and click on Continue




    ----------------------

    If malicious objects are found, they will show in the Scan results and offer three (3) options.

    Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.





    --------------------

    A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
    Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.

    -------------------

    Here's a summary of what to do if you would like to print it out:

    If a suspicious object is detected, the default action will be Skip, click on Continue
    If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
    Skip and click on Continue

    If malicious objects are found, they will show in the Scan results and offer three (3) options.

    Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
    103.

    Solve : Logs from malware removal guide?

    Answer»

    i reported a malware problem earlier, as a guest, but have since become a registered user. i'm being prompted to allow the installation of an ask toolbar. i removed everything "ask" related using revo uninstaller, but continued to RECEIVE the prompt. i followed the steps in the "malware removal guide" and am submitting the requested logs for review. also, i'm confused regarding step 6. i ran HJT, but took no action when i received the results of the scan. how do i proceed in regards to the scan results? thanks for all your help, you guys are doing a great job!

    [recovering disk space - old attachment deleted by admin]Hello jpb759.

    You have way too MUCH real-time antispyware running. This actually giving you less protection rather than more.

    Winpatrol
    SpySweeper
    Malwarebytes


    Disable either SpySweeper or Malwarebytes and just use it as an on-demand scanner. Winpatrol should be fine as it does not interfere with anything like the others do.

    ----------

    Disable SpySweeper so it does not block any fixes.

    You can re-enable it after we're done.

    To disable SpySweeper:

    • Open Spysweeper and click Options over to the left thenProgram Options and uncheck Load at windows startup
    • Over to the left click Shields and uncheckeverything.
    • UncheckHome page shield
    • UncheckAutomatically restore default without notification
    .
    ----------

    Disable Winpatrol so it does not block any fixes.

    You can re-enable it after we're done.

    Right-click the running icon of Winpatrol in the sytem tray and choose exit.

    ----------

    Malwarebytes is a version behind so you need to update and run it again.

    Open Malwarebytes' Anti-Malware.

    * Click the Update tab.
    * Click Check for Updates
    * If an update is found, it will download and install.
    * Click the Scanner tab.
    * Select Perform Quick Scan, then click Scan.
    * The scan may take some time to finish,so PLEASE be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
    * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    * Copy & Paste the entire report in your next reply.

    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    ----------

    Right click HijackThis and choose Run as Administrator

    Next select Do a system scan only

    Place a check mark next to the following entries: (if there)

    - O2 - BHO: (no NAME) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    I am not seeing where the Ask installer is running from so we need to go in and find it. The 64 bit OS also limits us as to the tools we can use. But we will get it.

    First let's try the easy way and hope it finds and removes the leftovers.

    Ask Toolbar Remover 1.3:

    A program that is able to remove the Ask toolbar (plus all the debris) and set the homepage back to the one the user wants to.
    More info here. http://fred-de-vries.blogspot.com/2009/12/autoclean-ask-toolbar-remover.html
    Download here. http://autoclean.computersitter.com/downloads/ASKRemover.zip?attredirects=0&d=1

    Just download and open the zip file then run the tool. A window swill open with more information and that is normal. The tool runs/completes very fast.

    Restart the computer and let me know if it worked.
    104.

    Solve : My computer won't even come on now?

    Answer»

    My friend gave me a lap top computer. It is an HP PAVILION dv6000. I can't tell you much else about it because it doesn't even TURN on. He said that it was locking up on him, and he gave it to someone that supposedly makes a living fixing computers, but after 6 weeks he gave it back and now it doesn't do anything. Is there something that I can do to try and get it working again.

    Thank You,
    SeanGo to Google and search for:
    HP Pavilion dv6000 service

    There are many sites that offer advice on HP products. Be aware that many of these are NOT free. And be very CAREFUL about downloading anything, EXPECT the service manual.
    http://www.ebooksquad.com/2009/03/25/hp-pavilion-dv1600-service-manual-and-maintenance.html

    My best guess is the battery is shot. But why didn't they catch that?

    105.

    Solve : Getting my A** kicked by nodqq.exe virus on 3 machines....wow?

    Answer»

    Took most of last night and today to sift through posts, google searches and to get my THOUGHTS together...so here goes.

    2 weeks ago bought a verbatim 500G usb drive to use between my 3 machines, a desktop, a laptop and a netbook.
    Yesterday I first noticed that I couldn't get to any hidden files with the laptop. Each time I tried to reset the folder options to show hidden files, it WOULD go right back to not show them. Tried with my desktop and same problem.
    Checked my netbook and all was ok with hidden files, so I plugged in my USB drive and bang! Immediately lost the ability to see them. It then occured to me that it had to be spread thru the USB drive.

    Since then I have identified 2 what I think are trojans on my machines, one named ca.exe and one named nodqq.exe. I'll cover one machine at a time and post the logs for each. The post is going to get waaay long, but I want to include as much info as might be necessary.

    First thing I did was update all virus protection to Norton internet security 2010 and run scans. (All 3 machines)

    First the logs:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:47:45 AM, on 5/1/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
    C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe
    C:\Program Files\InstaVerse\InstaVerse.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hphmon05.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Microsoft Money\System\mnyexpr.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Common Files\MySoftware\Newsflsh.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=laptop
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\IPSBHO.DLL
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
    O3 - Toolbar: FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - C:\Documents and Settings\HomePro\Application Data\Mozilla\Firefox\Profiles\z4mprbi8.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fsaddin-0.80.dll
    O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\coIEPlg.dll
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [tracker] C:\Program Files\MySoftware\MyInvoices\tracker.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [MSN Toolbar] "C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe"
    O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
    O4 - HKLM\..\Run: [InstaVerse] C:\Program Files\InstaVerse\InstaVerse.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: MySoftware NewsFlash.lnk = C:\Program Files\Common Files\MySoftware\Newsflsh.exe
    O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1269371081812
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe

    --
    End of file - 8464 bytes





    Norton Internet Security 2010 Logs

    Category: Resolved Security Risks
    Date & Time,Risk,Activity,Status,Recommended Action
    5/1/2010 7:33 AM,High,ca.exe (ca.exe) DETECTED by SONAR,Quarantined,Resolved - No Action
    5/1/2010 7:25 AM,High,nodqq.exe (nodqq.exe) detected by SONAR,Quarantined,Resolved - No Action
    5/1/2010 1:34 AM,High,nodqq0.dll (Trojan.Packed.NsAnti) detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:27 AM,High,p.exe (Trojan Horse) detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:25 AM,High,plugin-newplayer.pdf (Bloodhound.PDF!gen) detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:20 AM,High,nmdfgds0.dll (Trojan Horse) detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:13 AM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action
    5/1/2010 12:11 AM,High,5c244c96-38b87354 (Downloader) detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:11 AM,High,Downloader detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:11 AM,High,Downloader detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:11 AM,High,Trojan Horse detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:11 AM,High,Trojan Horse detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:11 AM,High,Trojan Horse detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:11 AM,High,Downloader detected by Virus scanner,Quarantined,Resolved - No Action
    5/1/2010 12:06 AM,High,cdaudio.sys (Infostealer.Gampass) detected by Virus scanner,Quarantined,Resolved - No Action


    Category: SONAR Activity
    Date & Time,Risk,Activity,Status,Recommended Action
    5/1/2010 7:33 AM,High,ca.exe (ca.exe) detected by SONAR,Quarantined,Resolved - No Action
    5/1/2010 7:25 AM,High,nodqq.exe (nodqq.exe) detected by SONAR,Quarantined,Resolved - No Action



    After scanning 3 TIMES and restarting each time, the SONAR from Norton picked up on nodqq.exe first and then ca.exe and quarantined them.

    These items never showed up in the task manager, but nodqq.exe showed up in the start up list of msconfig. I deleted it from there and dumped the recycle bin. I then ran a search for them by Start>Search>filename and found nodqq.dll. I deleted and dumped that too.
    I restarted and was able to reset folder options, so now I can see hidden files. I still have some issues though. In msconfig I have 1 blank line thats checked with no name and no command. Not sure if that's an issue. Also if I try to make any changes, I get an "access denied error" and says I should sign in as an administrator. Theres only 1 user on this machine which is an admin.
    Not sure if I still have issues with this machine, But I'll also need to kill and remove these fro m the drive.
    I appreciate any thoughts, It is a huge help that so many people take the time to share their expertise.



    Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.

    106.

    Solve : Hijacked by "File Recovery" malware sales program?

    Answer»

    Update Your Java (JRE)

    Old versions of Java have vulnerabilities that malware can use to infect your system.

    First Verify your Java Version

    If there are any other version(s) installed then update now.

    Get the new version (if needed)

    If your version is out of date install the newest version of the Sun Java Runtime Environment.

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close ALL open web browsers before starting the installation.

    Remove any old versions

    1. Download JavaRa and unzip the file to your DESKTOP.
    2. Open JavaRA.exe and choose Remove Older Versions
    3. Once complete exit JavaRA.

    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
    **************************************************
    Re-running ComboFix to remove infections:

    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Open notepad and copy/paste the text in the quotebox below into it:
      Quote
      KillAll::

      DirLook::

      C:\.Trash-999

    • SAVE this as CFScript.txt, in the same location as ComboFix.exe



    • Referring to the picture above, drag CFScript into ComboFix.exe
    • When finished, it shall produce a log for you at C:\ComboFix.txt
    • Please post the contents of the log in your next reply.
    I didn't realize that you had to remove old java versions... I did clean up some of them previously, but hadn't realized they weren't disabled once an update had been installed. Thanks for the utility to do that.

    It appears that the trash-999 folder was genuinely connected to the trash, because the files in it were empty folders that I recently deleted on purpose.

    Here's what ComboFix spit out this time:

    ComboFix 12-07-21.01 - Franis 07/22/2012 15:35:39.2.1 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2812.1809 [GMT -10:00]
    Running from: c:\users\Franis\Desktop\ComboFixAlso.exe
    Command switches used :: c:\users\Franis\Desktop\CFScript.txt
    AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
    SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 )))))))))))))))))))))))))))))))
    .
    .
    2012-07-23 01:45 . 2012-07-23 01:45--------d-----w-c:\users\Guest\AppData\Local\temp
    2012-07-23 01:45 . 2012-07-23 01:45--------d-----w-c:\users\Default\AppData\Local\temp
    2012-07-23 01:45 . 2012-07-23 01:45--------d-----w-c:\users\Certainly\AppData\Local\temp
    2012-07-23 00:25 . 2012-07-23 00:25476976----a-w-c:\windows\SysWow64\npdeployJava1.dll
    2012-07-18 09:57 . 2012-07-18 09:57--------d-----w-c:\users\Franis\AppData\Roaming\SUPERAntiSpyware.com
    2012-07-18 09:57 . 2012-07-18 09:57--------d-----w-c:\program files\SUPERAntiSpyware
    2012-07-18 09:57 . 2012-07-18 09:57--------d-----w-c:\programdata\SUPERAntiSpyware.com
    2012-07-15 20:29 . 2012-07-15 20:29--------d---a-w-C:\.Trash-999
    2012-07-11 22:32 . 2012-07-11 22:32--------d-----w-c:\program files (x86)\Malwarebitey
    2012-07-11 22:32 . 2012-04-05 01:5624904----a-w-c:\windows\system32\drivers\mbam.sys
    2012-07-11 16:38 . 2012-07-11 16:38--------d-----w-c:\program files (x86)\Mozilla Maintenance Service
    2012-07-11 16:38 . 2012-07-11 16:38421200----a-w-c:\program files (x86)\Mozilla Firefox\msvcp100.dll
    2012-07-11 16:38 . 2012-07-11 16:38770384----a-w-c:\program files (x86)\Mozilla Firefox\msvcr100.dll
    2012-07-11 16:04 . 2012-06-12 03:083148800----a-w-c:\windows\system32\win32k.sys
    2012-07-11 15:48 . 2012-06-02 12:01173056----a-w-c:\windows\system32\ieUnatt.exe
    2012-07-11 14:50 . 2012-06-06 06:062004480----a-w-c:\windows\system32\msxml6.dll
    2012-07-11 14:50 . 2012-06-06 06:061881600----a-w-c:\windows\system32\msxml3.dll
    2012-07-11 14:50 . 2012-06-06 05:051390080----a-w-c:\windows\SysWow64\msxml6.dll
    2012-07-11 14:50 . 2012-06-06 05:051236992----a-w-c:\windows\SysWow64\msxml3.dll
    2012-07-11 14:50 . 2010-06-26 03:552048----a-w-c:\windows\system32\msxml3r.dll
    2012-07-11 14:50 . 2010-06-26 03:242048----a-w-c:\windows\SysWow64\msxml3r.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-07-23 00:25 . 2010-06-07 12:18472880----a-w-c:\windows\SysWow64\deployJava1.dll
    2012-07-13 10:14 . 2012-04-04 20:32426184----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
    2012-07-13 10:14 . 2011-05-31 10:1270344----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-07-11 15:52 . 2009-11-21 06:4359701280----a-w-c:\windows\system32\MRT.exe
    2012-06-03 01:19 . 2012-06-22 06:48186752----a-w-c:\windows\system32\wuwebv.dll
    2012-06-03 01:15 . 2012-06-22 06:4836864----a-w-c:\windows\system32\wuapp.exe
    2012-06-02 22:19 . 2012-06-22 06:4938424----a-w-c:\windows\system32\wups.dll
    2012-06-02 22:19 . 2012-06-22 06:502428952----a-w-c:\windows\system32\wuaueng.dll
    2012-06-02 22:19 . 2012-06-22 06:5057880----a-w-c:\windows\system32\wuauclt.exe
    2012-06-02 22:19 . 2012-06-22 06:5044056----a-w-c:\windows\system32\wups2.dll
    2012-06-02 22:19 . 2012-06-22 06:49701976----a-w-c:\windows\system32\wuapi.dll
    2012-06-02 22:15 . 2012-06-22 06:502622464----a-w-c:\windows\system32\wucltux.dll
    2012-06-02 22:15 . 2012-06-22 06:4999840----a-w-c:\windows\system32\wudriver.dll
    2012-05-20 06:36 . 2012-05-16 21:1498848----a-w-c:\windows\system32\drivers\avgntflt.sys
    2012-05-20 06:36 . 2012-05-16 21:14132832----a-w-c:\windows\system32\drivers\avipbb.sys
    2012-05-04 11:06 . 2012-06-14 09:505559664----a-w-c:\windows\system32\ntoskrnl.exe
    2012-05-04 10:03 . 2012-06-14 09:503968368----a-w-c:\windows\SysWow64\ntkrnlpa.exe
    2012-05-04 10:03 . 2012-06-14 09:503913072----a-w-c:\windows\SysWow64\ntoskrnl.exe
    2012-05-01 05:40 . 2012-06-14 09:50209920----a-w-c:\windows\system32\profsvc.dll
    2012-04-28 03:55 . 2012-06-14 09:50210944----a-w-c:\windows\system32\drivers\rdpwd.sys
    2012-04-26 05:41 . 2012-06-14 09:5077312----a-w-c:\windows\system32\rdpwsx.dll
    2012-04-26 05:41 . 2012-06-14 09:50149504----a-w-c:\windows\system32\rdpcorekmts.dll
    2012-04-26 05:34 . 2012-06-14 09:509216----a-w-c:\windows\system32\rdrmemptylst.exe
    2012-04-24 05:37 . 2012-06-14 09:49184320----a-w-c:\windows\system32\cryptsvc.dll
    2012-04-24 05:37 . 2012-06-14 09:49140288----a-w-c:\windows\system32\cryptnet.dll
    2012-04-24 05:37 . 2012-06-14 09:491462272----a-w-c:\windows\system32\crypt32.dll
    2012-04-24 04:36 . 2012-06-14 09:491158656----a-w-c:\windows\SysWow64\crypt32.dll
    2012-04-24 04:36 . 2012-06-14 09:49140288----a-w-c:\windows\SysWow64\cryptsvc.dll
    2012-04-24 04:36 . 2012-06-14 09:49103936----a-w-c:\windows\SysWow64\cryptnet.dll
    .
    .
    (((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    ---- Directory of C:\.Trash-999 ----
    .
    2012-07-15 22:14 . 2012-07-15 22:14111----a-w-c:\.trash-999\info\Out4improv.trashinfo
    2012-07-15 22:13 . 2012-07-15 22:13105----a-w-c:\.trash-999\info\Text.trashinfo
    2012-07-15 20:52 . 2012-07-15 20:52102----a-w-c:\.trash-999\info\video clips.trashinfo
    2012-07-15 20:34 . 2012-07-15 20:34108----a-w-c:\.trash-999\info\Hula-at-Volcano on SAT-July14th.txt.trashinfo
    2012-07-15 20:29 . 2012-07-15 20:2998----a-w-c:\.trash-999\info\malware_File_Recovery.lnk.trashinfo
    2012-07-14 08:10 . 2012-07-14 08:10659----a-w-c:\.trash-999\files\malware_File_Recovery.lnk
    2012-07-08 17:04 . 2012-07-08 17:041494----a-w-c:\.trash-999\files\Hula-at-Volcano on SAT-July14th.txt
    .
    .Please download Rooter and Save it to your desktop.
    • Double click it to start the tool.Vista and Windows7 run as administrator.
    • Click Scan.
    • Eventually, a Notepad file containing the report will open, also found at C:\Rooter.txt. Post that log in your next reply.
    The ones I don't recognize as programs I use are:
    Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (2924) -
    Deluxe\PlayMovie\PMVService.exe (3216)
    C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe (3216)
    C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe (1612)

    (these may have been part of the bloatware that came originally with the computer, even though I don't use them)

    Programs that I do use and recognize are:
    C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (1584)
    C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (1440)
    C:\Users\Franis\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (2388)
    C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (2260)
    C:\Windows\Tasks\GlaryInitialize.job


    I'm curious about what the rest of this scan means, if you care to educate me a bit.

    Here is the Rooter scan results:


    Rooter.exe (v1.0.2) by Eric_71
    .
    SeDebugPrivilege granted successfully ...
    .
    Windows 7 Home Edition (6.1.7601) Service Pack 1
    [32_bits] - AMD64 Family 15 Model 124 Stepping 2, AuthenticAMD
    .
    [wscsvc] (Security Center) RUNNING (state:4)
    [MpsSvc] RUNNING (state:4)
    Windows Firewall -> Enabled
    Windows Defender -> Enabled
    .
    Internet Explorer 9.0.8112.16421
    Mozilla Firefox 13.0.1 (en-US)
    .
    C:\ [Fixed-NTFS] .. ( Total:136 Go - Free:76 Go )
    D:\ [CD_Rom]
    .
    Scan : 02:39.14
    Path : C:\Users\Franis\Desktop\Rooter.exe
    User : Franis ( Administrator -> YES )
    .
    ----------------------\\ Processes
    .
    Locked [System Process] (0)
    Locked System (4)
    ______ ? (260)
    ______ ? (400)
    ______ ? (472)
    ______ ? (484)
    ______ ? (532)
    ______ ? (540)
    ______ ? (548)
    ______ ? (604)
    ______ ? (700)
    ______ ? (772)
    ______ ? (820)
    ______ ? (940)
    ______ ? (984)
    ______ ? (100)
    ______ C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (308)
    ______ ? (716)
    ______ ? (1080)
    ______ ? (1108)
    ______ ? (1252)
    ______ C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (1292)
    ______ ? (1312)
    ______ ? (1420)
    ______ C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (1440)
    ______ ? (1492)
    ______ C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (1536)
    ______ C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (1584)
    ______ C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe (1612)
    ______ C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (1660)
    ______ ? (1760)
    ______ C:\Program Files\Acer\Acer Updater\UpdaterService.exe (1824)
    ______ ? (1864)
    ______ ? (1988)
    ______ ? (2144)
    ______ ? (2152)
    ______ ? (2516)
    ______ ? (2608)
    ______ ? (2648)
    ______ ? (2856)
    ______ ? (2868)
    ______ ? (2896)
    ______ C:\Users\Franis\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (2388)
    ______ ? (140)
    ______ C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe (960)
    ______ ? (1324)
    ______ ? (1956)
    ______ C:\Program Files (x86)\Launch Manager\LManager.exe (2940)
    ______ C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (2924)
    ______ C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (2260)
    ______ ? (904)
    ______ C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (2384)
    ______ C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe (3216)
    ______ ? (3232)
    ______ C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe (3268)
    ______ C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (3308)
    ______ C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (3444)
    ______ ? (3484)
    ______ ? (2404)
    ______ ? (2364)
    ______ ? (3968)
    ______ ? (4104)
    ______ ? (4992)
    Locked audiodg.exe (4524)
    ______ C:\Users\Franis\Desktop\Rooter.exe (4600)
    .
    ----------------------\\ Device\Harddisk0\
    .
    \Device\Harddisk0 [Sectors : 63 x 512 Bytes]
    .
    \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:12888981504)
    \Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:12889013760 | Length:106928640)
    \Device\Harddisk0\Partition3 (Start_Offset:12995942400 | Length:147044894720)
    .
    ----------------------\\ Scheduled Tasks
    .
    C:\Windows\Tasks\Adobe Flash Player Updater.job
    C:\Windows\Tasks\GlaryInitialize.job
    C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1109757479-377625319-1456128612-1000Core.job
    C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1109757479-377625319-1456128612-1000UA.job
    C:\Windows\Tasks\SA.DAT
    C:\Windows\Tasks\SCHEDLGU.TXT
    .
    ----------------------\\ Registry
    .
    .
    ----------------------\\ Files & Folders
    .
    ----------------------\\ Scan completed at 02:39.26
    .
    C:\Rooter$\Rooter_3.txt - (24/07/2012 | 02:39.26)
    Quote
    The ones I don't recognize as programs I use are:
    Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (2924) -
    Deluxe\PlayMovie\PMVService.exe (3216)
    C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe (3216)
    C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe (1612)
    They probably were install when your computer was loaded or by another program. If you don't use them, uninstall them.

    Quote
    I'm curious about what the rest of this scan means, if you care to educate me a bit.
    I don't wish to go into too much detail in an open forum but it is a scanner looking for Rootkits.
    How is your computer working now?

    I'd like to scan your machine with ESET OnlineScan

    •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
    •Click the button.
    •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
    •Check
    •Click the button.
    •Accept any security warnings from your browser.
    •Check
    •Push the Start button.
    •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    •When the scan completes, push
    •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    •Push the button.
    •Push
    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
    OK, that scan (which took twelve hours!) found a couple of objections... The computer seems to be running normally, even before these two little problems were found.

    Is there any cleanup that I should do to uninstall some of these programs we've used to scour these bugs away? These programs you recommended to use in this process seem pretty tiny - is there any danger of leaving them installed?


    Here's the log file from the online scan:

    C:\Users\Franis\Documents\THINKGS\src\browsers\newerChrome\chromupdater_exe.exea variant of Win32/InstallCore.D applicationcleaned by deleting - quarantined
    C:\Users\Franis\Documents\THINKGS\src\skype\recording messenger svs\Setup-SkypePlus-1.2.exea variant of Win32/MessengerPlus.A applicationdeleted - quarantined

    Quote
    Is there any cleanup that I should do to uninstall some of these programs we've used to scour these bugs away? These programs you recommended to use in this process seem pretty tiny - is there any danger of leaving them installed?

    Yes, we can do some cleanup. You can keep SAS and MBAM on your computer, if you wish. Update them and run them on a regular basis as they are not full-time scanners.

    Download this program and run it Uninstall ComboFix .It will remove ComboFix for you.

    ***************************************************
    To set a new Restore Point.

    Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
    Click the Start button , click Control Panel, click System and Maintenance, and then click System.
    In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
    To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
    This will give you a new, clean Restore Point.
    ***************************************************
    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
    **************************************************
    Use the Secunia Software Inspector to check for out of date software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, VIRUSES and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    Yes, I appreciate the reminder to do a new restore point again and the other things to do you suggested to beef up my protection levels. I'm considering also using Comodor for my firewall too, because I heard that the default one I have been using wasn't really adequate.

    I have a few more clueless questions.
    When I ran the uninstall to Combofix, it didn't disappear the .exe file that was on my desktop where I'd downloaded it. So does that mean the uninstall program uninstalled ComboFix, but left the original file that installed ComboFix alone... and if I clicked on the .exe file of ComboFix I would reinstall it again?

    Another one of the things that changed because of the attack was how the list of currently running programs is displayed on my task bar. These currently running programs used to be in a MENU that took up a half an inch of space on my lower right corner. Since the attack, these programs are in a line, taking up three inches instead of a half inch. Also, I imagine I can replace the icons that used to be next to my "start" button by dragging them onto the task bar on the other side, but there used to be an icon there signifying "show desktop" that I'd like to have back too. I think that I'm remembering this change happened when I ran the "unhide" program.
    Quote
    When I ran the uninstall to Combofix, it didn't disappear the .exe file that was on my desktop where I'd downloaded it. So does that mean the uninstall program uninstalled ComboFix, but left the original file that installed ComboFix alone... and if I clicked on the .exe file of ComboFix I would reinstall it again?
    It's probably just something left over. You can check for ComboFix on C: Combofix. If it's still there please run the uninstall program. I've never tried that uninstall program so I'm unsure how it works.

    Quote
    Another one of the things that changed because of the attack was how the list of currently running programs is displayed on my task bar. These currently running programs used to be in a menu that took up a half an inch of space on my lower right corner. Since the attack, these programs are in a line, taking up three inches instead of a half inch. Also, I imagine I can replace the icons that used to be next to my "start" button by dragging them onto the task bar on the other side, but there used to be an icon there signifying "show desktop" that I'd like to have back too. I think that I'm remembering this change happened when I ran the "unhide" program.
    I'm not sure what you mean. Could you provide a screenprint?
    How to post screenshots or images
    OK, here's a screen shot of what I mean... I was about wrote a little note on the picture itself.
    (Hope the typeface isn't too small to see... but if it is, it says: Here's a screenprint. these icons you see below used to not be located in a line as they are now. They used to be in a menu, (which did not take up more than an EIGHTH of the space here) After clicking on the menu, each icon was displayed and could be interacted with in the same way, but they were displayed in a menu box rather than in a line as they appear here. )

    That looks normal but here's more information about the icons.
    107.

    Solve : Some advice??

    Answer»

    I have some pretty strong suspicions of others messing around with my machine. Im not going to get into detail of who is doing it or for whatever reasons because in truth I dont know and because it will take a long long time.
    Below is a picture of a supposedly freshly formatted Solid state drive. Whenever I format the drive it tells me that it has space used as you can see. The amount of space varies by filesystem it is the same drive under different filesystems. This does not only happen with this hard drive but with all of the drives I own.
    So what I did today was to install windows XP and look for rootkits via a utility called TDSSKiller. To my surprise It found over 174 rootkits but I knew something was up from the start.. I really don't want to touch any Microsoft operating system anymore. The hole gets deeper tough when I attempt to run the program DBAN I cant use it. It tells me that the Hard DISKS might contain bad sectors yet in on other computer I can use the software. One possibility that I am getting that error might be hardware related issues but by any chance can a motherboard become infected?

    What I will attempt is to run DBAN once again but am expecting the same result since Ive done it before I installed windows XP and found the rootkits.



    [year+ old attachment deleted by admin]Quote from: Forward on July 01, 2012, 06:32:15 PM

    Whenever I format the drive it tells me that it has space used as you can see. The amount of space varies by filesystem it is the same drive under different filesystems. This does not only happen with this hard drive but with all of the drives I own.
    Data used and reserved for file structures with various File Systems use disk space.

    Quote
    So what I did today was to install windows XP and look for rootkits via a utility called TDSSKiller. To my surprise It found over 174 rootkits but I knew something was up from the start..
    Only way I can see that happening is with a pirated install of XP. (Or, if the install was actually a repair install or upgrade install of an existing infected XP installation)

    Quote
    The hole gets deeper tough when I attempt to run the program DBAN I cant use it. It tells me that the Hard disks might contain bad sectors yet in on other computer I can use the software. One possibility that I am getting that error might be hardware related issues but by any chance can a motherboard become infected?
    bad sectors can be responsible for false flaggings of rootkits, based on how a lot of them work (which is typically to inspect the disk at a lower level than the API functions that a rootkit would circumvent). Errors are sometimes flagged as rootkits. This is a sensible approach because the assumption on the software side is that hardware is working properly, so if something goes wrong, it assumes there is some other piece of software getting in the way. DBAN isn't designed to wipe disks with bad sectors. You could try an alternative tool like MHDD or HDDErase. Another common tool is [emailprotected] disk, which comes in a free VERSION that can be used.

    Quote
    What I will attempt is to run DBAN once again but am expecting the same result since Ive done it before I installed windows XP and found the rootkits.
    Rootkits are low level drivers installed into the operating System, usually used to facilitate the infection of the machine by hiding those new files from your standard OS tools. It quite literally cannot exist separate from the OS. A fresh install of Windows- or any OS, for that matter, quite literally cannot be infected in this way- UNLESS the install is done using a pirated Disc, which can often come with loads of "goodies" in the form of malware and rootkits.


    Some could argue that as part of a MBR or other low level code it could, but the XP install rewrites the MBR (as does GRUB install, to my recollection) so that isn't a place it would survive.

    Theoretically it is POSSIBLE for a virus to infect a BIOS, however, the problem here is that a Jumper would almost always have to be moved on the motherboard, and it would have to be BUILT to specifically target that exact Motherboard model. Since malware authors aim to infect as many machines as possible, this simply isn't economical from that perspective.
    Tried anything I can think of including deleting the master boot records and activekilldisk. Some pretty sticky malware i now dont think this drive is of any use to me now.
    Thank you.Please excuse the double post but I really need some guidance.
    I was able to run Dariks boot and nuke (switched AHCI to IDE) but now have a bigger issue. The issue now is the read/write rate. I suspect that the hard drives are somehow "frozen" the reasons for this are that as soon as I run the program the read/write rates are pretty fast (in KB/s) Expecting a successful wipe in about 8-10 hours after 20 minutes or so the read/write rates drop to bytes per second and the expected wipe should complete in 350+ hours.. Will try to use parted magic as my next resort.Are you needing malware removal or hard drive assistance?I apologize for not posting earlier. The reason is that I have been using other operating systems. I dont even know what is happening to my machine. I think I found some rootkits Im not sure though. Ran a scan with Kapersky TDSSKiller and found a lot of nasty stuff I would post logs but I didnt save them. The system would act up like nothing that Ive seen before. For example when I would try to install a piece of software like an antivirus the installer would hang unless I went to the task manager and ended a process called svchost that would take up %25 cpu usage the installer would then continue. Many things that are unexplained have caused me to believe that there is someone messing with my computer I dont want to get into detail since there is always that possibility that I am wrong.
    108.

    Solve : Application cannot be executed. The file **** is infected - Please help?

    Answer»

    I was stupidly downloading music and I must have come to some site that GAVE me a virus. I'm not TOO familiar with computers REALLY. Any help would be very APPRECIATED. This (possible) virus is really making me angry.

    Is there something maybe I could do easily, because I'm at a point where I PROBABLY GOT the virus about five minutes before I got on this board. Is there a way to "quickly destroy" this virus?

    Thanks in advance. Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.

    109.

    Solve : Searchfilterhost.exe is infected -- My world has turned on me......?

    Answer»

    Hello:
    I am new to this community, am GLAD it exist. from reading the posts it seem that there are some serious help is available here. Well i need help, I really do.
    I am running win 7 profetional on my Laptop(Dell Vostro 1700). I do run Adaware live, but iguess it is not good enough to catch what I have. My symtoms are that i keep getting notices from os saying I have been infected(See clip1 and 2 Attached) and the adaware is crippled, can't run task manager, it popsup for a sec and disappears and I keep getting this window(see clip3)wanting me to purchase anti malware from this site (*LINK REMOVED*). I also have in my icon and notification window(Clip4) a file labeled as Vfuxnrxtssd.exe that I have no idea what it is. I also have lost the use of dos window(cmd). So As you can see I need so serious help.
    In most posts I have seen Super Dave(SD) who seem to be having very detailed help instructions and succcesses with people, So SD if you are out there I really need your help

    Ardy



    [recovering disk space - old attachment deleted by admin]Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.Hello DragonMaster Jay:
    Thanks for the reply and help.... . it took me while. The infection is crippling...... it changes IE settings to proxy and keeps giving me all kinds of problems....any how ran combofix. it finished all stages and was deleting some files and backing up others when the OS gave me the blue screen of deth. I booted in safe mode and ran CF again this time it finished. here is the log file....

    ComboFix 10-04-21.01 - Ardy 04/23/2010 21:23:23.2.2 - x86 MINIMAL
    Running from: c:\users\Ardy\Desktop\ComboFix.exe
    AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
    SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run -------
    .
    c:\$recycle.bin\S-1-5-21-1361614194-4143690539-4151942459-1002
    c:\$recycle.bin\S-1-5-21-1361614194-4143690539-4151942459-500
    c:\$recycle.bin\S-1-5-21-2826133206-2312993737-4083541239-500
    c:\$recycle.bin\S-1-5-21-918056312-2952985149-2686913973-500
    C:\Images
    c:\users\Ardy\AppData\Roaming\xolehlpy.dll
    c:\windows\system32\win.ini
    c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

    .
    ((((((((((((((((((((((((( Files Created from 2010-03-24 to 2010-04-24 )))))))))))))))))))))))))))))))
    .

    2010-04-24 04:30 . 2010-04-24 04:30--------d-----w-c:\users\Default\AppData\Local\temp
    2010-04-24 04:22 . 2010-04-24 04:22--------d-----w-C:\32788R22FWJFW
    2010-04-24 02:53 . 2010-04-24 02:53--------d-----w-c:\users\Ardy\AppData\Local\ktrfptpku
    2010-04-23 17:01 . 2010-04-23 17:33--------d-----w-c:\temp\virus-tools
    2010-04-23 14:55 . 2010-04-23 14:5561184----a-w-c:\users\Ardy\AppData\Local\syssvc.exe
    2010-04-23 14:53 . 2010-04-23 14:53--------d-----w-c:\users\Ardy\AppData\Local\inngnjoss
    2010-04-22 14:41 . 2010-04-23 02:07--------d-----w-c:\users\Ardy\AppData\Local\ewkjldovf
    2010-04-22 14:25 . 2010-04-22 14:28--------d-----w-c:\temp\AllwaysSync
    2010-04-22 02:31 . 2010-04-22 02:31--------d-----w-c:\temp\TFTP-Program
    2010-04-16 01:17 . 2009-12-29 06:55172032----a-w-c:\windows\system32\wintrust.dll
    2010-04-16 01:17 . 2010-02-27 07:32221696----a-w-c:\windows\system32\drivers\mrxsmb10.sys
    2010-04-16 01:17 . 2010-02-27 07:3295744----a-w-c:\windows\system32\drivers\mrxsmb20.sys
    2010-04-16 01:17 . 2010-02-27 07:32123392----a-w-c:\windows\system32\drivers\mrxsmb.sys
    2010-04-16 01:17 . 2010-02-27 12:073954568----a-w-c:\windows\system32\ntkrnlpa.exe
    2010-04-16 01:17 . 2010-02-27 12:073899280----a-w-c:\windows\system32\ntoskrnl.exe
    2010-04-16 01:17 . 2010-03-08 21:33427520----a-w-c:\windows\system32\vbscript.dll
    2010-04-16 01:17 . 2010-01-09 06:52132608----a-w-c:\windows\system32\cabview.dll
    2010-04-13 21:26 . 2010-04-21 18:01193872----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\lib7zip.dll
    2010-04-13 21:26 . 2010-04-21 18:011000784----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\lgpl.dll
    2010-04-11 05:37 . 2010-04-11 05:38--------d-----w-c:\programdata\SSScanAppDataDir
    2010-04-11 05:37 . 2010-04-11 05:37--------d-----w-c:\programdata\MSScanAppDataDir
    2010-04-10 16:36 . 2010-04-10 16:36--------d-----w-c:\program files\Common Files\AnswerWorks 5.0
    2010-04-10 16:32 . 2010-04-10 16:32--------d-----w-c:\users\Ardy\AppData\Local\IsolatedStorage
    2010-04-10 16:26 . 2010-04-10 16:26--------d-----w-c:\program files\TurboTax
    2010-04-10 16:10 . 2010-02-23 07:56977920----a-w-c:\windows\system32\wininet.dll
    2010-04-07 23:30 . 2010-04-07 23:30--------d-----w-c:\users\Ardy\.jagex_cache_32
    2010-04-03 15:33 . 2010-04-03 15:33--------d-----w-c:\program files\FileZilla FTP Client
    2010-04-03 15:22 . 2010-04-06 17:18--------d-----w-c:\temp\TomCat_6.0.26
    2010-04-03 14:54 . 2010-04-03 15:33--------d-----w-c:\temp\Filzilla-Ftp
    2010-04-02 16:37 . 2010-04-02 16:370----a-w-c:\users\Ardy\jagex__preferences3.dat
    2010-03-30 15:49 . 2010-03-30 15:4917632----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
    2010-03-29 01:52 . 2010-04-22 03:211366----a-w-c:\users\Ardy\SDM-2.5-877W-c870-advipservicesk9-mz.124-15.T12.bin

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-04-24 03:10 . 2008-11-19 05:08--------d-----w-c:\programdata\Google Updater
    2010-04-23 19:53 . 2008-04-15 06:01--------d-----w-c:\users\Ardy\AppData\Roaming\ESRI
    2010-04-22 15:33 . 2009-11-11 19:34--------d-----w-c:\program files\Allway Sync
    2010-04-21 05:42 . 2010-03-17 00:50--------d-----w-c:\users\Ardy\AppData\Roaming\Skype
    2010-04-21 00:51 . 2009-01-22 02:39--------d-----w-c:\users\Ardy\AppData\Roaming\skypePM
    2010-04-16 02:24 . 2010-01-16 19:08--------d-----w-c:\programdata\WebEx
    2010-04-16 02:07 . 2010-01-21 02:55--------d-----w-c:\users\Ardy\AppData\Roaming\webex
    2010-04-16 02:07 . 2010-01-21 02:552211840----a-w-c:\programdata\WebEx\WebEx\924\atpdmod.dll
    2010-04-16 02:07 . 2010-01-21 02:5598304----a-w-c:\programdata\WebEx\WebEx\924\atplayim.dll
    2010-04-16 02:07 . 2010-01-21 02:55364544----a-w-c:\programdata\WebEx\WebEx\924\atarm.dll
    2010-04-16 02:07 . 2010-01-21 02:5553248----a-w-c:\programdata\WebEx\WebEx\924\atcarmcl.dll
    2010-04-16 02:07 . 2010-01-21 02:5524576----a-w-c:\programdata\WebEx\WebEx\924\atmemmgr.dll
    2010-04-16 01:23 . 2007-11-12 02:34--------d-----w-c:\programdata\Microsoft Help
    2010-04-12 14:34 . 2010-03-24 16:173757392----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\vcore.dll
    2010-04-12 14:34 . 2010-03-24 16:17259408----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\remediation.dll
    2010-04-12 14:33 . 2010-03-24 16:17226640----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\libZip.dll
    2010-04-12 14:33 . 2010-03-24 16:17390480----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\libVvs.dll
    2010-04-12 14:33 . 2010-03-24 16:17173392----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\libtd.dll
    2010-04-12 14:33 . 2010-03-24 16:17296272----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\libRar.dll
    2010-04-12 14:33 . 2010-03-24 16:17345424----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\libOleA.dll
    2010-04-12 14:33 . 2010-03-24 16:17206160----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\libNSIS.dll
    2010-04-12 14:33 . 2010-03-24 16:17177488----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\libMsi.dll
    2010-04-12 14:33 . 2010-03-24 16:17283984----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\libEmail.dll
    2010-04-12 14:33 . 2010-03-24 16:17206160----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\libCHM.dll
    2010-04-10 16:37 . 2010-02-16 02:44147784----a-w-c:\users\Ardy\AppData\Local\GDIPFONTCACHEV1.DAT
    2010-04-10 16:36 . 2008-08-08 06:12--------d-----w-c:\users\Ardy\AppData\Roaming\Intuit
    2010-04-10 16:33 . 2008-08-08 05:51--------d-----w-c:\programdata\Intuit
    2010-04-10 16:32 . 2008-08-08 03:21--------d-----w-c:\program files\Common Files\Intuit
    2010-04-09 17:50 . 2009-10-07 21:15--------d-----w-c:\users\Ardy\AppData\Roaming\FileZilla
    2010-04-08 01:16 . 2009-08-07 21:1241----a-w-c:\users\Ardy\jagex_runescape_preferences.dat
    2010-04-08 01:00 . 2009-09-07 14:2569----a-w-c:\users\Ardy\jagex_runescape_preferences2.dat
    2010-04-06 14:11 . 2009-12-20 16:42966104----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
    2010-04-06 14:11 . 2009-12-20 16:381265264----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
    2010-04-01 03:54 . 2008-09-27 22:43--------d-----w-c:\program files\AirPort
    2010-03-22 22:37 . 2010-03-22 22:370---ha-w-c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
    2010-03-18 03:22 . 2010-01-20 05:371662----a-w-c:\users\Ardy\SDM-2.5-877W-c870-advipservicesk9-mz.124-2.T5.bin
    2010-03-17 00:50 . 2010-03-17 00:49--------d-----r-c:\program files\Skype
    2010-03-17 00:49 . 2010-03-17 00:49--------d-----w-c:\program files\Common Files\Skype
    2010-03-17 00:49 . 2009-01-22 02:37--------d-----w-c:\programdata\Skype
    2010-03-13 01:24 . 2010-03-24 16:1783280----a-w-c:\programdata\Lavasoft\Ad-Aware\Defs\Extended\kbu.dll
    2010-03-09 00:15 . 2008-11-21 05:51--------d-----w-c:\program files\RegCure
    2010-03-08 04:12 . 2010-03-08 04:1295024----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
    2010-03-08 04:12 . 2009-10-27 17:2795024----a-w-c:\windows\system32\drivers\SBREDrv.sys
    2010-03-08 04:12 . 2010-03-08 04:12566608----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\sbap.dll
    2010-03-08 04:12 . 2009-12-21 01:2115880----a-w-c:\windows\system32\lsdelete.exe
    2010-03-08 04:12 . 2009-12-20 16:4715880----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
    2010-03-08 04:12 . 2010-01-27 22:471230160----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\SBTE.dll
    2010-03-08 04:12 . 2010-01-27 22:47247120----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\SBRE.dll
    2010-03-08 04:11 . 2009-12-20 16:426330848----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
    2010-03-08 04:11 . 2010-03-08 04:1117480----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
    2010-03-08 04:10 . 2010-03-08 04:10735008----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AAWWSC.exe
    2010-03-08 04:10 . 2009-12-21 16:502270720----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\ToolBox\LT\HostFileEditor.exe
    2010-03-08 04:10 . 2010-03-08 04:1269936----a-w-c:\windows\system32\drivers\sbapifs.sys
    2010-03-08 04:10 . 2010-03-08 04:1077616----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\i386\sbapifsl.sys
    2010-03-08 04:10 . 2010-03-08 04:1069936----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\i386\sbapifs.sys
    2010-03-08 04:10 . 2010-03-08 04:1013360----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\i386\sbaphd.sys
    2010-03-08 04:10 . 2009-12-21 16:492038272----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\ToolBox\LT\ProcessWatch.exe
    2010-03-08 04:10 . 2009-12-21 16:49104960----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\ToolBox\AutoStart Manager\SO.dll
    2010-03-03 22:54 . 2009-12-20 16:413803208----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
    2010-02-27 20:11 . 2010-02-27 20:11--------d-----w-c:\programdata\PC Drivers HeadQuarters
    2010-02-25 22:16 . 2010-01-16 19:08743224----a-w-c:\programdata\WebEx\WebEx\932\atsccust.dll
    2010-02-25 22:16 . 2010-01-16 19:08356352----a-w-c:\programdata\WebEx\WebEx\932\sccustres.dll
    2010-02-25 22:16 . 2010-01-16 19:0853248----a-w-c:\programdata\WebEx\WebEx\932\atcarmcl.dll
    2010-02-25 22:16 . 2010-01-16 19:08364544----a-w-c:\programdata\WebEx\WebEx\932\atarm.dll
    2010-02-25 22:16 . 2010-01-16 19:0824576----a-w-c:\programdata\WebEx\WebEx\932\atmemmgr.dll
    2010-02-22 03:40 . 2010-02-22 03:41720896----a-w-c:\windows\iun6002.exe
    2010-02-15 23:09 . 2010-02-15 23:0921316----a-w-c:\windows\system32\emptyregdb.dat
    2010-02-15 19:54 . 2007-07-27 09:064268----a-w-c:\windows\bthservsdp.dat
    2010-02-02 17:02 . 2010-01-27 22:48348160----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\msvcr71.dll
    2010-02-02 17:02 . 2010-01-27 22:48503808----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\msvcp71.dll
    2010-02-02 07:45 . 2010-02-27 15:232048----a-w-c:\windows\system32\tzres.dll
    2010-01-27 22:49 . 2009-12-20 16:468----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
    2007-07-27 09:18 . 2007-07-27 09:1876--sha-r-c:\windows\CT4CET.bin
    2009-06-10 21:26 . 2009-07-14 02:049633792--sha-r-c:\windows\Fonts\StaticCache.dat
    2007-11-11 05:03 . 2007-11-11 05:038--sha-r-c:\windows\System32\84463728C9.sys
    2007-11-12 02:30 . 2007-11-11 05:032672--sha-w-c:\windows\System32\KGyGaAvL.sys
    2009-07-14 01:14 . 2009-07-13 23:42396800--sha-w-c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-19 39408]
    "TomTomHOME.exe"="c:\program files\TomTom HOME\TomTomHOMERunner.exe" [2009-11-13 247144]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2009-07-14 65024]
    "Allway Sync"="c:\program files\Allway Sync\Bin\syncappw.exe" [2010-03-23 102168]
    "qrwaffgj"="c:\users\Ardy\AppData\Local\inngnjoss\vfuxnrxtssd.exe" [2010-04-23 272640]
    "ygwsslvv"="c:\users\Ardy\AppData\Local\ktrfptpku\dcowjmatssd.exe" [2010-04-24 272640]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
    "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-06-27 405504]
    "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-10 36864]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-12 101136]
    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-08 3444736]
    "EC Software TNT"="c:\program files\TNT\tnt.exe" [2004-04-05 4051456]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-19 13793824]
    "NVHotkey"="c:\windows\system32\nvHotkey.dll" [2009-08-19 92704]
    "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-09-21 184320]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
    "SMART Board Service"="c:\program files\SMART Technologies Inc\SMART Board Software\SMARTBoardService.exe" [2007-11-02 1283336]
    "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
    "WinSSHD Activation State Checker"="c:\program files\Bitvise WinSSHD\WinsshdActStateCheck.exe" [2009-12-02 216832]
    "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
    "AirPort Base Station Agent"="c:\program files\AirPort\APAgent.exe" [2009-11-11 771360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "GrpConv"="grpconv -o" [X]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-7-27 50688]
    QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
    2008-11-11 02:262356088----a-w-c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

    R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
    R2 ArcGIS License Manager;ArcGIS License Manager;c:\program files\ESRI\License\arcgis9x\lmgrd.exe [2008-08-02 1431440]
    R2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2010-01-16 43920]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-13 133104]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-04-06 1265264]
    R2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [2010-03-08 69936]
    R2 SentinelKeysServer;Sentinel Keys Server;c:\program files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [2008-07-11 328992]
    R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME\TomTomHOMEService.exe [2009-11-13 92008]
    R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2006-10-20 37296]
    R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
    R3 Ser2rs;Radioshack USB to Serial Driver;c:\windows\system32\DRIVERS\ser2rs.sys [2007-06-25 76288]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-02-27 1343400]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-09-23 64288]
    S1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [2010-03-08 95024]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    iissvcsREG_MULTI_SZ w3svc was
    apphostREG_MULTI_SZ apphostsvc
    WindowsMobileREG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestrictedREG_MULTI_SZ WcesComm RapiMgr
    .
    Contents of the 'Scheduled Tasks' folder

    2010-04-24 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-19 02:10]

    2010-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-13 05:05]

    2010-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-13 05:05]

    2010-04-24 c:\windows\Tasks\ParetoLogic Registration.job
    - c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 19:25]

    2010-04-18 c:\windows\Tasks\ParetoLogic Update Version2.job
    - c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 19:25]

    2010-04-24 c:\windows\Tasks\RegCure Program Check.job
    - c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]

    2010-04-24 c:\windows\Tasks\RegCure Startup.job
    - c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]

    2010-04-24 c:\windows\Tasks\RegCure.job
    - c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]

    2010-04-24 c:\windows\Tasks\User_Feed_Synchronization-{1D769DAF-DFF1-46DC-B064-2A61CE487549}.job
    - c:\windows\system32\msfeedssync.exe [2009-07-13 01:14]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.pesare-darya.com/
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    uInternet Settings,ProxyOverride =
    IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    Trusted Zone: intuit.com\ttlc
    DPF: {6F0C8A8F-8B0D-11D2-801B-00105AA78F4A} - hxxp://ecare4a.netopia.com/techsupport/ecare4/components/CobAgent_4.2.1.319.cab
    .
    - - - - ORPHANS REMOVED - - - -

    Toolbar-{a298ed31-d405-40e2-880f-b7511948e582} - (no file)
    WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
    HKLM-RunOnce- - (no file)
    AddRemove-AnswerWorks - c:\program files\WexTech\AnswerWorks\Uninst.isu


    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\SECURITY]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2010-04-23 21:32:34
    ComboFix-quarantined-files.txt 2010-04-24 04:32

    Pre-Run: 77,355,212,800 bytes free
    Post-Run: 77,202,366,464 bytes free

    - - End Of File - - 472B97925779E27AA20601FAAC0EFB90
    Please do not attach logs. Instead, copy and paste them in to the post.

    Please download Malwarebytes Anti-Malware from Malwarebytes.org.
    Alternate link: BleepingComputer.com.
    (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

    Double Click mbam-setup.exe to install the application.

    (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)

    • Make SURE a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
    • Please save the log to a location you will remember.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
    • Copy and paste the entire report in your next reply.
    The Log File for mbam

    Malwarebytes' Anti-Malware 1.45
    www.malwarebytes.org

    Database version: 4029

    Windows 6.1.7600 (Safe Mode)
    Internet Explorer 8.0.7600.16385

    4/24/2010 7:56:09 AM - Ardy
    mbam-log-2010-04-24 (07-56-09).txt

    Scan type: Full scan (C:\|D:\|)
    Objects scanned: 380728
    Time elapsed: 1 hour(s), 0 minute(s), 28 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 2
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 3

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qrwaffgj (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ygwsslvv (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Users\Ardy\AppData\Local\inngnjoss\vfuxnrxtssd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Users\Ardy\AppData\Local\ktrfptpku\dcowjmatssd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Users\Ardy\AppData\Local\syssvc.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
    Please run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install
    • Click Start
    • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, you may close the window
    • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    The Log for ESET:

    [emailprotected] as CAB hook log:
    OnlineScanner.ocx - registred OKIs any of this working? I've got the same thing.Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.Scan report for Malwarebytes:

    Malwarebytes' Anti-Malware 1.45
    www.malwarebytes.org

    Database version: 4036

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    4/25/2010 7:47:26 PM - Ardy
    mbam-log-2010-04-25 (19-47-26).txt

    Scan type: Quick scan
    Objects scanned: 110793
    Time elapsed: 9 minute(s), 5 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    To manually create a new Restore Point
    • Go to Control Panel and select System and Maintenance
    • Select System
    • On the left select Advance System Settings and accept the warning if you get one
    • Select System Protection Tab
    • Select Create at the bottom
    • Type in a name i.e. Clean
    • Select Create
    Now we can purge the infected ones
    • Go back to the System and Maintenance page
    • Select Performance Information and Tools
    • On the left select Open Disk Cleanup
    • Select Files from all users and accept the warning if you get one
    • In the drop down box select your main drive i.e. C
    • For a few moments the system will make some calculations
    • Select the More Options tab
    • In the System Restore and Shadow Backups select Clean up
    • Select DELETE on the pop up
    • Select OK
    • Select Delete
    You are now done

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    ==

    Please download TFC by OldTimer to your desktop
    • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • It will close all programs when run, so make sure you have saved all your work before you begin.
    • Click the Start
      button to begin the process. Depending on how often you clean temp
      files, execution time should be anywhere from a few seconds to a minute
      or two. Let it run uninterrupted to completion.
    • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
    ==

    Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    Log As Requested:

    Results of screen317's Security Check version 0.99.3
    Windows 7 (UAC is enabled)
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Disabled!
    Antivirus up to date! (On Access scanning disabled!)
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Ad-Aware
    Free Registry Cleaner For Vista 2.0
    Java(TM) SE Runtime Environment 6
    Adobe Flash Player 10
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Ad-Aware AAWService.exe is disabled!
    Ad-Aware AAWTray.exe is disabled!
    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log```````````` Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

    Software recommendations

    Firewall
    • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
    • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
    • PC Tools Firewall Plus: free and excellent firewall.
    AntiSpyware
    • SpywareBlaster
      SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
    • Spybot - Search & Destroy.
      Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
    NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

    Resident Protection help
    A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

    Rogue programs help
    There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Securing your computer
    • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
    • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
    Please consider using an alternate browser
    Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

    If you are interested:
    See this page for more info about malware and prevention.Thank you DragonMaster. Your help is very much appriciated. I am assuming since Ad-Aware wasn't one of recomanded applications, it most likely is not up to par......I will read the information provided and will tighten up......

    Once again I really appriciate your help. Is ther any way I would be able to donate and or give to this cause.........

    ArdyYou can keep Ad-Aware. It is good.

    There is no way to donate on this site unfortunately. We help for free, so you don't have to pay.
    110.

    Solve : Help with Windows Security Alert virus?

    Answer»

    I am having trouble opening any files, especially .exe files or update my virus protection, etc. Please help!

    SuperDave, you commented on a similar problem a while back, post titled: Application cannot be executed. The file *** is infected. on: November 16, 2009, 09:44:38 AM

    I am reluctant to follow suggestions without expert advice.... Thanks in advance!Hello.

    RKill by Grinler
    Link #1
    Link #2
    Link #3

    • Download Link #1.
    • Save it to your Desktop.
    • Double click the RKill desktop icon.
      If you are using Vista please right click and run as Admin!
    • A black screen will briefly flash indicating a successful run.
    • If this does not occur please delete that application and download Link #2.
    • Continue process until the tool runs.
    • If the tool does not run from any of the links tell me about it.
    This only kills the active infection, the actual infection will not be gone.

    ==============

    Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.DragonMaster Jay,

    Link#1 is no longer a valid page. Therefore, I downloaded Link 2 but it would not run, same for Link 3. I have them saved on my desktop but when I dbl click the icon a black window opens for one second then closes, after which I get a Security Warning window that reads: Application cannot be executed. the file rkill(2).com is infected. Do you want to activate your antivirus software now?

    I figured that I should shut down my virus protection so I can download and run the links but everytime I try to access the add or remove programs it is shut down automatically.

    Hope you can help, thanks.Please try this:

    • Start TASK Manager (Ctrl+Alt+Delete)
    • Then find the following two processes:
    av.exe
    ave.exe
    • Once found, right-click on each of them and select End Process

    • Once done. Then, try the tools again.
    When I ctrl alt delete it brings up the window with Task Manager tab but when I click the tab it is automatically closed and a warning "Windows Security alter" appears. The virus will not allow me to open or run task manager.Let's try to run ComboFix in a different mode.

    Please reboot to Safe Mode with Networking (tap the F8 key just before Windows starts to load and select the Safe Mode with Networking option from the menu).

    Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.DragonMaster Jay, here is the post. I started the system in safe mode and first ran the rkill program, which seemed to work. After that I ran the ComboFix and here is the log:

    ComboFix 10-04-21.01 - ppratt 04/24/2010 17:00:00.1.2 - x86 NETWORK
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.677 [GMT -4:00]
    Running from: c:\documents and settings\Cressida Silvers\Desktop\ComboFix.exe
    AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf\vixqnsftssd.exe
    c:\windows\asam.exe
    c:\windows\eSellerateEngine.dll
    c:\windows\herjek.config

    .
    ((((((((((((((((((((((((( Files Created from 2010-03-24 to 2010-04-24 )))))))))))))))))))))))))))))))
    .

    2010-04-23 17:43 . 2010-04-23 17:4361184----a-w-c:\documents and settings\Cressida Silvers\Local Settings\Application Data\syssvc.exe
    2010-04-23 17:41 . 2010-04-24 21:04--------d-----w-c:\documents and settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf
    2010-04-10 23:51 . 2010-04-10 23:51--------d-----w-c:\program files\WindSolutions
    2010-04-10 23:51 . 2010-04-10 23:54--------d-----w-c:\documents and settings\Cressida Silvers\Application Data\WindSolutions
    2010-04-10 23:51 . 2010-04-10 23:51--------d-----w-c:\documents and settings\All Users\Application Data\WindSolutions

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-04-24 20:33 . 2008-07-18 16:05--------d-----w-c:\program files\Symantec AntiVirus
    2010-04-22 16:39 . 2010-01-05 21:1040252---ha-w-c:\windows\system32\mlfcache.dat
    2010-04-16 00:19 . 2005-10-20 14:25--------d-----w-c:\program files\Mozilla Thunderbird
    2010-03-25 18:14 . 2005-04-22 19:0846800----a-w-c:\documents and settings\Cressida Silvers\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-03-10 06:15 . 2005-06-22 17:52420352----a-w-c:\windows\system32\vbscript.dll
    2010-02-25 06:24 . 2005-06-22 17:52916480----a-w-c:\windows\system32\wininet.dll
    2010-02-24 13:11 . 2005-06-22 17:49455680------w-c:\windows\system32\drivers\mrxsmb.sys
    2010-02-19 23:47 . 2010-02-19 23:473604480----a-w-c:\windows\system32\GPhotos.scr
    2010-02-16 14:08 . 2004-08-03 23:182146304------w-c:\windows\system32\ntoskrnl.exe
    2010-02-16 13:25 . 2004-08-03 22:592024448------w-c:\windows\system32\ntkrnlpa.exe
    2010-02-12 04:33 . 2005-06-22 17:46100864------w-c:\windows\system32\6to4svc.dll
    2010-02-11 12:02 . 2005-06-22 17:51226880------w-c:\windows\system32\drivers\tcpip6.sys
    2010-02-09 19:57 . 2010-02-09 19:5745056----a-w-c:\documents and settings\Cressida Silvers\Application Data\Sun\Java\Deployment\cache\javaws\http\Dqedoc.net\P80\DMqqp\RNlibraries.jar\jniwrap.dll
    2005-07-01 15:55 . 2005-07-01 15:552649----a-w-c:\program files\Psyllids at Andytown update.eml
    2004-05-19 13:51 . 2006-08-31 17:4110339----a-w-c:\program files\sas91_859417.txt
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Google Update"="c:\documents and settings\Cressida Silvers\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-19 135664]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-12-17 1241138]
    "SoundMan"="SOUNDMAN.EXE" [2004-08-30 69632]
    "HP SchedIndexer"="c:\program files\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe" [2002-01-03 94208]
    "HP AutoIndexer"="c:\program files\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe" [2002-01-03 90112]
    "Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
    "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-10-08 125368]
    "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2008-05-20 244208]
    "DMXLauncher"="c:\program files\Roxio\CinePlayer\DMXLauncher.exe" [2008-04-07 113136]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RunNarrator"="Narrator.exe" [2008-04-14 53760]
    "MPlayer2_FixUp"="c:\windows\inf\unregmp2.exe" [2008-04-14 208896]

    c:\documents and settings\ppratt\Start Menu\Programs\Startup\
    HotSync Manager.LNK - c:\program files\palmOne\HOTSYNC.EXE [2004-4-13 299008]

    c:\documents and settings\Cressida Silvers\Start Menu\Programs\Startup\
    HotSync Manager.LNK - c:\program files\palmOne\HOTSYNC.EXE [2004-4-13 299008]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Acrobat SPEED Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2005-7-7 25214]
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-6-30 113664]
    HP LaserJet Director.lnk - c:\program files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe [2005-6-28 204800]
    hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-9 28672]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "filteradministratortoken"= 1 (0x1)
    "ReportControllerMissing"= 1 (0x1)
    "LogonType"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "PreXPSP2ShellProtocolBehavior"= 0 (0x0)
    "NoMSAppLogo5ChannelNotify"= 1 (0x1)
    "NoWebServices"= 1 (0x1)
    "NoOnlinePrintsWizard"= 1 (0x1)
    "NoPublishingWizard"= 1 (0x1)
    "NoWelcomeScreen"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Gateway\\HPA\\GWMenu.exe"=
    "c:\\Program Files\\SAS\\SAS 9.1\\sas.exe"=
    "c:\\Program Files\\Retrospect\\Retrospect Client\\retroclient.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

    S2 Retrospect Client;Retrospect Client;c:\program files\Retrospect\Retrospect Client\RemotSvc.exe [3/20/2006 10:39 AM 61440]
    S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [5/20/2008 9:15 AM 362992]
    S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [5/20/2008 9:13 AM 309744]
    S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [5/20/2008 9:13 AM 166384]
    S2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/7/2007 8:48 PM 116664]
    S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [8/15/2009 1:31 PM 17149]
    S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/13/2009 11:54 AM 101936]
    S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [5/20/2008 9:15 AM 313840]
    S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [5/20/2008 9:12 AM 1120752]
    S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [8/15/2009 1:31 PM 384608]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

    2010-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-861567501-682003330-1003Core.job
    - c:\documents and settings\Cressida Silvers\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-19 22:41]

    2010-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-861567501-682003330-1003UA.job
    - c:\documents and settings\Cressida Silvers\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-19 22:41]
    .
    .
    ------- Supplementary Scan -------
    .
    uDefault_Search_URL = hxxp://www.google.com/ie
    uInternet Settings,ProxyOverride =
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    DPF: {CAFECAFE-0013-0001-0017-ABCDEFABCDEF}
    FF - ProfilePath - c:\documents and settings\Cressida Silvers\Application Data\Mozilla\Firefox\Profiles\w1zfhx73.Default User 2\
    FF - prefs.js: browser.startup.homepage - hxxp://cnn.com
    FF - plugin: c:\documents and settings\Cressida Silvers\Application Data\Move Networks\plugins\npqmp071505000011.dll
    FF - plugin: c:\documents and settings\Cressida Silvers\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJinit13117.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-chwgonkc - c:\documents and settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf\vixqnsftssd.exe
    HKCU-Run-asam - c:\windows\asam.exe
    HKLM-Run-chwgonkc - c:\documents and settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf\vixqnsftssd.exe
    HKLM-Run-asam - c:\windows\asam.exe
    AddRemove-McAfee Security Scan - c:\program files\McAfee Security Scan\uninstall.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-04-24 17:07
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(772)
    c:\windows\system32\Ati2evxx.dll
    .
    Completion time: 2010-04-24 17:10:19
    ComboFix-quarantined-files.txt 2010-04-24 21:10

    Pre-Run: 8,021,364,736 bytes free
    Post-Run: 12,825,636,864 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    - - End Of File - - EB5129E6AA2056EE64DF83BE96E018F7

    Please download Malwarebytes Anti-Malware from Malwarebytes.org.
    Alternate link: BleepingComputer.com.
    (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

    Double Click mbam-setup.exe to install the application.

    (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
    • Please save the log to a location you will remember.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
    • Copy and paste the entire report in your next reply.
    DragonMaster Jay, here is the log from the Malwarebytes program:

    Malwarebytes' Anti-Malware 1.45
    www.malwarebytes.org

    Database version: 4036

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    4/26/2010 6:42:51 AM
    mbam-log-2010-04-26 (06-42-51).txt

    Scan type: Full scan (C:\|)
    Objects scanned: 323637
    Time elapsed: 1 hour(s), 59 minute(s), 21 second(s)

    MEMORY Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 3

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Documents and Settings\Cressida Silvers\Local Settings\Application Data\syssvc.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Documents and Settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf\vixqnsftssd.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\asam.exe.vir (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
    Please run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install
    • Click Start
    • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, you may close the window
    • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    111.

    Solve : Re Direct?

    Answer»

    If I enetr a search topic and then click on a link it takes me to E bay or some other site not connected to where I want to go, how do I prevent this? it started about 5 days ago thanks in advanceHello and welcome to COMPUTER Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    *************************************************************************
    SUPERAntiSpyware

    If you already have SUPERAntiSpyware be sure to check for updates before scanning!

    Download SuperAntispyware Free Edition (SAS)
    * Double-click the icon on your desktop to run the installer.
    * When asked to UPDATE the program definitions, click Yes
    * If you encounter any problems while downloading the updates, manually download and unzip them from here
    * Next click the Preferences button.

    •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
    * Click the Scanning Control tab.
    * Under Scanner Options make sure only the following are checked:

    •Close browsers before scanning
    •Scan for tracking cookies
    •Terminate memory threats before quarantining
    Please leave the others unchecked

    •Click the Close button to leave the control center screen.

    * On the main screen click Scan your computer
    * On the left check the box for the drive you are scanning.
    * On the right choose PERFORM Complete Scan
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete a summary box will appear. Click OK
    * Make sure everything in the white box has a check next to it, then click Next
    * It will quarantine what it found and if it asks if you want to reboot, click Yes

    •To retrieve the removal information please do the following:
    •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
    •Click Preferences. Click the Statistics/Logs tab.

    •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

    •It will open in your default text editor (preferably Notepad).
    •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

    * Save the log SOMEWHERE you can EASILY find it. (normally the desktop)
    * Click close and close again to exit the program.
    *Copy and Paste the log in your post.
    *********************************************
    Please download Malwarebytes Anti-Malware from here.
    Double Click mbam-setup.exe to install the application.

    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
    • Please save the log to a location you will remember.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the entire report in your next reply.
    Extra Note:

    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
    *************************************************
    Download DDS from HERE or HERE and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.
    * Save both reports to your desktop.
    * The instructions here ask you to attach the Attach.txt.



    1) DDS.txt
    2) Attach.txt
    Instead of attaching, please copy/past both logs into your Thread

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copying and pasting it into the reply.

    •Close the program window, and delete the program from your desktop.

    Please note: You may have to disable any script protection running if the scan fails to run.
    After downloading the tool, disconnect from the internet and disable all antivirus protection.
    Run the scan, enable your A/V and reconnect to the internet.
    Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )
    112.

    Solve : Metropolitan Police malware has infected my system?

    Answer»

    Here is the ESET Log

    [emailprotected] as downloader log:
    all ok
    # version=7
    # OnlineScannerApp.exe=1.0.0.1
    # OnlineScanner.ocx=1.0.0.6583
    # api_version=3.0.2
    # EOSSerial=58554bdb09dce644811fbe806f8fc97c
    # end=finished
    # remove_checked=false
    # archives_checked=true
    # unwanted_checked=true
    # unsafe_checked=false
    # antistealth_checked=true
    # utc_time=2012-07-03 12:16:40
    # local_time=2012-07-03 01:16:40 (+0000, GMT Daylight Time)
    # country="United Kingdom"
    # lang=1033
    # osver=5.1.2600 NT Service Pack 3
    # compatibility_mode=512 16777215 100 0 107290 107290 0 0
    # compatibility_mode=768 16777215 100 0 75885219 75885219 0 0
    # compatibility_mode=6401 16777213 66 100 348807 2879305 0 0
    # compatibility_mode=8192 67108863 100 0 0 0 0 0
    # scanned=120787
    # found=0
    # cleaned=0
    # scan_time=9941


    The computer seems to be running fine now with the exception of a missing RUNDLL file upon start up. I have mentioned this before in my original post and in my shortend version.

    Quote from: benni9000 on June 24, 2012, 02:14:36 PM

    I got Metropolitan Police malware on my laptop. I followed the "read this before requesting malware removal help" post which seems to have stopped it, Now I just need to get rid of the damage? I think there are still some files left on my laptop from the malware and I am missing a RUNDLL file from the windows directory.

    I have attache a jpg of the ERROR window as I couldn't seem to get it into the post.

    I believe the RUNDLL file was the source of my malware issue. I will explain my reasoning though I could be wrong. When I got the malware it locked up the laptop. It didn't however start until the internet connection was live. So with the internet disconnected I looked in my startup folder by going right mouse button on Start and browsing all USERS. I found a short cut called cpfmon. I deleted cos I didn't know what it was. Came straight back. So I searched C drive for cpfmon and found a few other files withe the same name. I deleted them and then connected to the internet. No malware issue. When I restarted and connected I got the malware back. So I looked at the properties of the cpfmon shortcut and found where it was linked to, it was a RUNDLL file in the windows directory. Hence why I think the RUNDLL file was the source of the malware or at least what it had infected.

    Apart from this missing file everything is ok that I can see. I appreciate all the help you have given.

    Thank you

    [year+ old attachment deleted by admin]I'm happy that everything is working well but I want to check further on that alert and then we'll so some cleanup.Please download SystemLook from one of the links below and save it to your desktop.

    Link # 1
    Link # 2

    Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double-click SystemLook.exe to run it.

    Copy the contents of the following codebox into the main textfield.
    Code: [Select]:filefind
    jork_0_typ_col.exe
    Click the Look button to start the scan.

    Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer).

    When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt
    SystemLook 30.07.11 by jpshortstuff
    Log created at 18:17 on 05/07/2012 by Benni
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "jork_0_typ_col.exe"
    No files found.

    -= EOF =-

    Double-click SystemLook.exe to run it.

    Copy the contents of the following codebox into the main textfield.
    Code: [Select]:regfind
    jork_0_typ_col.exe
    Click the Look button to start the scan.

    Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer).

    When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt
    Nothing exciting I'm afraid

    SystemLook 30.07.11 by jpshortstuff
    Log created at 19:39 on 06/07/2012 by Benni
    Administrator - Elevation successful

    ========== regfind ==========

    Searching for "jork_0_typ_col.exe"
    No data found.

    -= EOF =-Please download SystemLook from one of the links below and save it to your desktop.

    Link # 1
    Link # 2

    Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double-click SystemLook.exe to run it.

    Copy the contents of the following codebox into the main textfield.
    Code: [Select]:regfind
    "error loading"
    Click the Look button to start the scan.

    Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer).

    When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt
    I'm afraid there is still no joy

    SystemLook 30.07.11 by jpshortstuff
    Log created at 18:08 on 08/07/2012 by Benni
    Administrator - Elevation successful

    ========== regfind ==========

    Searching for ""error loading""
    No data found.

    -= EOF =-Please do this even if you don't have your OS disk.Please let me know what happens.

    Do you have an XP CD?

    If so, place it in your CD ROM drive and follow the instructions below:
    •Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
    *Let this run undisturbed until the window with the blue progress bar goes away
    SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.Unfortunatly I don't have the XP CD. I got the lap top with an XP downgrade as I didn't want Windows Vista. I have the Vista CD though.

    I followed the FSC /Scannow instructions. It went through it all. There was no message after it finished so I assume everything was ok.Quote from: benni9000 on July 11, 2012, 10:36:10 AM
    Unfortunatly I don't have the XP CD. I got the lap top with an XP downgrade as I didn't want Windows Vista. I have the Vista CD though.

    I followed the FSC /Scannow instructions. It went through it all. There was no message after it finished so I assume everything was ok.
    If it didn't ask for the XP disk that means all the OS files are ok. I'm at a loss as to what's causing this error.Ok. No worries. Other than that message on startup everything seems to be working ok. I really appreciate the time and effort you've spent helping me sort my laptop out.

    Thank youWe should do some cleanup before you go.

    Download this program and run it Uninstall ComboFix .It will remove ComboFix for you
    *******************************************
    To turn off Windows XP System Restore:

    NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    8. Restart the computer and follow the instructions in the next section to turn on System Restore.

    To turn on Windows XP System Restore:

    1. Click Start.
    2. Right-click My Computer, and then click Properties.
    3. Click the System Restore tab.
    4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
    5. Click Apply, and then click OK.
    ************************************************
    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
    ************************************************
    Use the Secunia Software Inspector to check for out of date software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all CRITICAL updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - SEARCH & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    113.

    Solve : How do i get rid of a trojan virus on my computer??

    Answer»

    My computer has a trojan virus. There are so many pop-ups..and it randomly shuts down every half hour. how do i REMOVE this virus?Please visit this webpage for a tutorial on downloading and running ComboFix:

    HTTP://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when DONE, POST the LOG back here.

    114.

    Solve : Wireless Router Virus??

    Answer»
    Ok, so I am very paranoid about viruses...but only because I am starting a photography blog/website and I am concerned about spreading a virus to others.

    I have a laptop that is wiped clean. I am using a brand new memory card in my digital camera and only using it with this computer (to prevent viruses) to take photographs for the website.

    My main concern now is that of our home wireless network...the router is hooked up to our main desktop computer...and one other laptop connects to and uses the wireless network (family member).

    My question is...when I connect my clean laptop to the internet via wireless, can I get a virus from one of the other computers in my household because of sites that they have visited? I have heard that this is possible, and am interested in finding out how to ensure that this does not happen (as I do not want my files/photos that I intend to share on the website to infect others).

    I have not connected to the internet on the laptop since I have restored the computer to original factory state...I intend to immediately install MICROSOFT Security Essentials...but I must connect wirelessly to do so...Will this also put me at risk?

    I know that this is kind of a complicated hypothetical thing, but I was interested in a little help/input if at all possible.

    Also, Is there a way to scan the router for infections?

    Thanks :-)Yes. It can. And you can fix it
    Using the reset feature, you can stick a toothpick into the HOLE and force the router back to factory settings.
    But you have to go through the setup again to get the right settings for your local network and internet service. So do this only if you have reason the think the router has been infected.
    If you Google Router Virus Removal
    You can find many recent posts and articles. Here is just one:
    http://forums.majorgeeks.com/showthread.php?t=213939
    Here is another:
    http://forums.cnet.com/7723-7589_102-145685/virus-inside-router/
    Does this help any?


    The router is hooked up to my desktop computer...Instead of using wireless, what if I used a Cat 5 cable and plugged my laptop directly into the router? Would a virus still be a risk?Yes, a virus of some type for form could enter either via cable or wireless.

    The greater danger is the PC itself. There are dozens of places a virus could hide in a PC. In the router, there is less space available for a virus to reside.

    Some say the more common problem is router 'poison' RATHER that a virus. A kind of MALWARE inside the PC alters the settings of the router without actually change the router program code.
    Here is a discussion about the most common router infection,

    Quote
    APR (ARP Poison Routing) is a main feature of the program. It enables sniffing on switched networks and the hijacking of IP traffic between hosts. The name "ARP Poison Routing" derives from the two steps needed to PERFORM such unusual network sniffing: an ARP Poison Attack and routing packets to the correct destination. ...
    http://www.oxid.it/ca_um/topics/apr.htm

    This is of concern in complex networks.This is not a Virus and spyware removal topic. If it is, then please start a new topic, and you will receive help from a Malware Removal Specialist.

    The advice given in this thread is compromised, and should not be followed.

    For those untrained in malware removal and security basics should not be trusted with any advice.

    Topic closed!
    115.

    Solve : Computer Hijack Help?

    Answer»

    Looking for some help on getting CONTROL of my computer back!! I am currently getting fake security warnings and am unable to run ANY program with the message "application cannot be executed". I was trying to install some removal tools but safe mode will not let me, and I can do nothing after a normal boot. Any help/knowledge is greatly appreciated!
    -JeffPlease reboot to Safe Mode with Networking (tap the F8 key just before Windows starts to LOAD and select the Safe Mode with Networking option from the menu).

    Please visit this webpage for a tutorial on downloading and running COMBOFIX:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the AREA: Using ComboFix, and when DONE, post the log back here.

    116.

    Solve : Help removing infections?

    Answer»

    Hi everyone

    I got infected with various things. I ran malware bytes and hijack and think most is gone but would appreciate an expert review my logs

    Here is malware logs

    Malwarebytes' Anti-Malware 1.45
    www.malwarebytes.org

    Database version: 3947

    Windows 5.1.2600 Service PACK 2
    Internet Explorer 6.0.2900.2180

    4/24/10 10:36:08 AM
    mbam-log-2010-04-24 (10-36-08).txt

    Scan type: Full scan (C:\|D:\|)
    Objects scanned: 254838
    Time elapsed: 1 hour(s), 54 minute(s), 7 second(s)

    Memory PROCESSES Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 18
    Registry Values Infected: 6
    Registry DATA Items Infected: 7
    Folders Infected: 10
    Files Infected: 16

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CscrptXt.CscrptXt (Adware.EZlife) -> Quarantined and DELETED successfully.
    HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\cscrptxt.cscrptxt.1.0 (Adware.EZlife) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\ezLife (Adware.EZlife) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Smart-Ads-Solutions (Adware.SmartAds) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart-Ads-Solutions (Adware.SmartAds) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Smart-Ads-Solutions (Adware.SmartAds) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\net (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\adshothlpr.adshothlpr (Adware.Adrotator) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\adshothlpr.adshothlpr.1.0 (Adware.Adrotator) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\adhlpr.adhlpr (Adware.Adrotator) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\adhlpr.adhlpr.1.0 (Adware.Adrotator) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yvibbbha8c (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ezlife (Adware.EZlife) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hsf87efjhdsf87f3jfsdi7fhsujfd (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\gtsou\Local Settings\Application Data\vma.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\gtsou\Local Settings\Application Data\vma.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\gtsou\Local Settings\Application Data\vma.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    C:\Program Files\Smart-Ads-Solutions (Adware.SmartAds) -> Quarantined and deleted successfully.
    C:\Program Files\Smart-Ads-Solutions\SmartAds (Adware.SmartAds) -> Quarantined and deleted successfully.
    C:\Program Files\Smart-Ads-Solutions\SmartAds\1.5.2.0 (Adware.SmartAds) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Application Data\Smart-Ads-Solutions (Adware.SmartAds) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Application Data\Smart-Ads-Solutions\SmartAds (Adware.SmartAds) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Application Data\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Application Data\ezLife\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
    C:\Program Files\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
    C:\Program Files\ezLife\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
    C:\Program Files\ezLife\ezLife\1.5.2.0 (Adware.EzLife) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Documents and Settings\gtsou\Local Settings\Temp\waxsecrmon.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Local Settings\Temp\RarSFX0\hor0410e.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
    C:\Program Files\Smart-Ads-Solutions\SmartAds\1.5.2.0\uninstall.exe (Adware.SmartAds) -> Quarantined and deleted successfully.
    C:\Program Files\ezLife\ezLife\1.5.2.0\uninstall.exe (Adware.EzLife) -> Quarantined and deleted successfully.
    C:\Program Files\Mozilla Firefox\components\nsFFxSHot.xpt (Adware.Adrotator) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Local Settings\Temp\Qmm.exe (Trojan.FakeAlert) -> Delete on reboot.
    C:\Documents and Settings\gtsou\Local Settings\Application Data\vma.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully.
    C:\WINDOWS\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\TEMP\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Local Settings\Temp\services.exe (Password.Stealer) -> Quarantined and deleted successfully.
    C:\WINDOWS\TEMP\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Local Settings\Temp\win32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Local Settings\Temp\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\gtsou\Local Settings\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\TEMP\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
    and here is the hijack log...attachednot sure if the attachment worked and can't SEEM to paste text of hijack log

    117.

    Solve : Test?

    Answer»

    Testsorry...PLEASE IGNORE

    118.

    Solve : Run-time error '372'??

    Answer»

    I believe this is a virus but it may be something wrong with the files on the computer. It may be tl;dr but I need to list all the details.
    Basically, I turned my pc on this morning and it came up with an error (can't remember what it said and I didn't think it was serious so didn't write it down. Anyway, there was a countdown and it said save any work before the computer is turned off. When I rebooted, the windows theme had reverted to CLASSIC rather than xp and when I tried to change this back in the control panel windows classic was the only option.
    Another problem was I can't open ie and firefox can't find any webpages. My wireless connection is also down (this is probs the CAUSE of firefox failing) and the INTERNET connections page is blank when I try to view it. Sometimes a window called BTTray pops up and says "ERROR: Unable to start the Bluetooth stack service". Due to the lack of connection I'm on a DIFFERENT computer now.
    Also, copy and paste is impossible so I cannot download files to fix it and TRANSFER them from computer to computer (unless drag works?).
    I ran CCleaner to clean the registry and then tried to open Malwarebytes.
    This comes up with "Run-time error '372':
    Failed to load control 'vbalGrid' from vbalgrid6.ocx. Your version of vbalgrid6.ocx may be outdated. Make sure you are using the version of the control that was provided with your application.
    Could this may Vundo?

    Thanks for any help.I also cannot open Windows searchPlease visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.

    119.

    Solve : Virus Keep Opening Websites...?

    Answer»

    Hey fellas,

    A little bit help will be very appreciated

    I've got some sort of virus which they want to open some sort of website
    However, it got blocked by Malwarebytes

    So, every few minutes, there will be this popup


    I've tried scanning with both Bit defender and MBAM
    And the virus keep on doing this

    Here's the result from Hijackit
    Code: [Select]Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Nitro PDF\NitroPDFDriverService.exe
    C:\WINDOWS\system32\NLSSRV32.EXE
    C:\Program Files\Raxco Perfect Disk 2008\PD91Agent.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
    C:\Program Files\Internet Download Manager\IDMan.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Internet Download Manager\IEMonitor.exe
    C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\WINDOWS\system32\wuauclt.exe
    D:\Downloads\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: (no name) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - (no file)
    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: (no name) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - (no file)
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
    O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
    O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
    O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [url]http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab[/url]
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. [url]http://www.bitdefender.com[/url] - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: NitroPDFDriverCreatorReadSpool (NitroDriverReadSpool) - Nitro PDF Software - C:\Program Files\Nitro PDF\NitroPDFDriverService.exe
    O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\NLSSRV32.EXE
    O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco Perfect Disk 2008\PD91Agent.exe
    O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco Perfect Disk 2008\PD91Engine.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe

    --
    End of file - 8137 bytes

    Please advise what I'm supposed to do....Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.I have used the ComboFix

    And here's the result...
    Code: [Select]ComboFix 10-04-21.01 - G 24/04/2010 11:10:29.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.314 [GMT 10:00]
    Running from: d:\downloads\ComboFix.exe
    AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
    FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Galih\Application Data\chrtmp
    c:\windows\Fjamea.exe
    c:\windows\Fjameb.exe
    c:\windows\system32\OGACheckControl.dll

    .
    ((((((((((((((((((((((((( Files Created from 2010-03-24 to 2010-04-24 )))))))))))))))))))))))))))))))
    .

    2010-04-23 12:33 . 2010-04-23 12:33 -------- d-----w- c:\program files\MSXML 4.0
    2010-04-23 08:30 . 2010-04-23 08:30 4 ----a-w- c:\windows\system32\aspdict-en.dat
    2010-04-23 08:30 . 2010-04-23 08:30 16 ----a-w- c:\windows\system32\asdict.dat
    2010-04-23 08:21 . 2010-04-23 08:21 -------- d-----w- c:\documents and settings\Galih\Application Data\BitDefender
    2010-04-23 08:20 . 2010-04-23 08:20 -------- d-----w- C:\Binaries
    2010-04-23 08:19 . 2010-04-23 08:25 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender
    2010-04-23 08:19 . 2010-04-23 08:20 -------- d-----w- c:\program files\BitDefender
    2010-04-23 08:16 . 2010-04-23 08:20 -------- d-----w- c:\program files\Common Files\BitDefender
    2010-04-23 05:35 . 2010-04-23 05:35 70656 --sha-r- c:\windows\system32\ialmuHUNT.dll
    2010-04-23 05:32 . 2010-04-23 05:32 -------- d-----w- c:\program files\Common Files\Nitro PDF
    2010-04-23 05:32 . 2010-04-23 05:32 104960 --sh--r- c:\documents and settings\Galih\Application Data\wayh.exe
    2010-04-23 05:26 . 2010-04-23 05:26 -------- d-----w- c:\documents and settings\Galih\Application Data\Nitro PDF
    2010-04-23 05:11 . 2009-12-15 23:50 17728 ----a-w- c:\windows\system32\nitrolocalui.dll
    2010-04-23 05:11 . 2009-12-15 23:50 26432 ----a-w- c:\windows\system32\nitrolocalmon.dll
    2010-04-23 05:11 . 2010-04-23 05:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Nitro PDF
    2010-04-23 05:11 . 2010-04-23 05:32 -------- d-----w- c:\program files\Nitro PDF
    2010-04-23 05:10 . 2010-04-23 05:10 -------- d-----w- c:\documents and settings\Galih\Application Data\Downloaded Installations
    2010-04-17 12:11 . 2010-04-17 12:11 5918776 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
    2010-04-13 02:21 . 2010-04-13 02:21 -------- d-----w- c:\program files\Disable Spyware
    2010-04-12 15:06 . 2010-04-23 13:45 -------- d-----w- c:\program files\Farm Mania 2
    2010-04-12 15:05 . 2010-04-12 15:05 -------- d-----w- c:\program files\ReflexiveArcade
    2010-04-11 10:45 . 2010-04-11 10:45 131 ----a-w- C:\DeletePrintJobs.cmd
    2010-04-10 06:22 . 2010-04-10 06:22 -------- d-----w- c:\windows\system32\Futuremark
    2010-04-10 06:22 . 2008-09-17 05:14 27672 ----a-r- c:\windows\system32\drivers\Entech.sys
    2010-04-10 06:22 . 2010-04-10 06:22 -------- d-----w- c:\program files\Common Files\Futuremark Shared
    2010-04-06 11:43 . 2010-04-06 11:43 -------- d-----w- c:\documents and settings\Galih\Local Settings\Application Data\Cranium_Consulting_and_Cu
    2010-03-31 13:02 . 2010-03-31 13:02 -------- d-----w- c:\program files\iPod
    2010-03-31 13:02 . 2010-04-06 11:45 -------- d-----w- c:\program files\iTunes
    2010-03-31 13:02 . 2010-03-31 13:03 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    2010-03-31 12:58 . 2010-03-31 12:59 -------- d-----w- c:\program files\QuickTime
    2010-03-31 12:54 . 2010-03-31 12:54 -------- d-----w- c:\program files\Bonjour
    2010-03-31 12:51 . 2010-03-31 12:51 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
    2010-03-31 09:20 . 2010-03-31 09:20 -------- d-----w- c:\program files\Common Files\Java
    2010-03-31 09:20 . 2010-03-31 09:20 503808 ----a-w- c:\documents and settings\Galih\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-513900ed-n\msvcp71.dll
    2010-03-31 09:20 . 2010-03-31 09:20 499712 ----a-w- c:\documents and settings\Galih\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-513900ed-n\jmc.dll
    2010-03-31 09:20 . 2010-03-31 09:20 348160 ----a-w- c:\documents and settings\Galih\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-513900ed-n\msvcr71.dll
    2010-03-31 09:20 . 2010-03-31 09:20 12800 ----a-w- c:\documents and settings\Galih\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7801014c-n\decora-d3d.dll
    2010-03-31 09:20 . 2010-03-31 09:20 61440 ----a-w- c:\documents and settings\Galih\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7801014c-n\decora-sse.dll
    2010-03-26 10:30 . 2010-03-26 10:30 -------- d-----w- c:\program files\Your Uninstaller 2010
    2010-03-26 10:19 . 2010-03-26 10:23 -------- d-----w- c:\program files\VS Revo Group
    2010-03-26 10:08 . 2010-03-26 10:09 -------- d-----w- c:\program files\CCleaner

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-04-24 00:54 . 2009-02-15 01:41 -------- d-----w- c:\documents and settings\Galih\Application Data\DMCache
    2010-04-23 08:42 . 2009-02-15 01:39 -------- d-----w- c:\program files\Internet Download Manager
    2010-04-23 08:24 . 2009-02-15 01:40 -------- d-----w- c:\program files\Avast
    2010-04-23 05:27 . 2009-03-18 11:31 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-04-22 12:51 . 2009-02-15 01:53 -------- d-----w- c:\documents and settings\Galih\Application Data\mIRC
    2010-04-22 12:45 . 2009-02-15 01:53 -------- d-----w- c:\program files\mIRC
    2010-04-18 02:29 . 2010-03-19 10:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-04-14 01:56 . 2009-02-15 01:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2010-04-10 06:22 . 2009-02-15 00:34 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-04-06 11:50 . 2010-03-16 13:27 -------- d-----w- c:\program files\iPhone Folders
    2010-03-31 13:02 . 2009-02-16 08:27 -------- d-----w- c:\program files\Common Files\Apple
    2010-03-31 09:18 . 2009-02-16 06:42 -------- d-----w- c:\program files\Java
    2010-03-29 14:46 . 2010-03-19 10:18 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-03-29 14:45 . 2010-03-19 10:18 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-03-26 10:34 . 2009-08-11 11:56 -------- d-----w- c:\program files\Westward III Gold Rush
    2010-03-26 10:34 . 2009-08-07 13:08 -------- d-----w- c:\program files\Ranch Rush
    2010-03-26 10:30 . 2009-04-30 04:27 -------- d-----w- c:\documents and settings\Galih\Application Data\URSoft
    2010-03-25 10:01 . 2009-04-08 11:32 -------- d-----w- c:\program files\Common Files\Adobe
    2010-03-23 13:58 . 2010-03-23 13:58 -------- d-----w- c:\documents and settings\Galih\Application Data\Leawo
    2010-03-23 13:46 . 2010-03-23 13:45 9 ----a-w- c:\windows\system32\iPhone Video Converter0902.dat
    2010-03-23 13:39 . 2010-03-23 13:39 -------- d-----w- c:\documents and settings\Galih\Application Data\ImTOO Software Studio
    2010-03-23 13:19 . 2010-03-23 13:19 -------- d-----w- c:\documents and settings\Galih\Application Data\AnvSoft
    2010-03-19 10:18 . 2010-03-19 10:18 -------- d-----w- c:\documents and settings\Galih\Application Data\Malwarebytes
    2010-03-19 10:18 . 2010-03-19 10:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-03-19 09:36 . 2009-02-16 07:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-03-10 06:15 . 2005-01-07 00:00 420352 ----a-w- c:\windows\system32\vbscript.dll
    2010-03-08 17:28 . 2009-02-16 06:42 411368 ----a-w- c:\windows\system32\deploytk.dll
    2010-03-08 10:49 . 2010-03-08 10:49 -------- d-----w- c:\program files\Unlocker
    2010-03-05 00:59 . 2009-02-15 01:41 -------- d-----w- c:\documents and settings\Galih\Application Data\IDM
    2010-03-05 00:59 . 2009-04-21 10:28 198064 ----a-w- c:\documents and settings\Galih\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
    2010-03-05 00:43 . 2009-04-21 10:26 3153784 ----a-w- c:\documents and settings\Galih\Application Data\IDM\idmupdt.exe
    2010-02-28 10:45 . 2010-02-28 10:45 -------- d-----w- c:\program files\Audacity
    2010-02-25 06:24 . 2005-01-07 00:00 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-02-24 13:11 . 2005-01-07 00:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2010-02-22 04:58 . 2010-02-22 04:58 291352 ----a-w- c:\windows\system32\drivers\bdfsfltr.sys
    2010-02-16 14:08 . 2005-01-07 00:00 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
    2010-02-16 13:25 . 2005-01-07 00:00 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2010-02-12 04:33 . 2005-01-07 00:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
    2010-02-12 00:46 . 2010-02-12 00:46 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-02-12 00:46 . 2010-02-12 00:46 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2010-02-11 12:02 . 2005-01-07 00:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
    2010-02-03 03:57 . 2010-02-03 03:57 153448 ----a-w- c:\windows\system32\drivers\bdfm.sys
    2010-02-03 03:56 . 2010-02-03 03:56 106464 ----a-w- c:\windows\system32\drivers\bdhv.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2010-03-05 3179952]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2005-01-07 208952]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2005-01-07 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2005-01-07 455168]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
    "RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
    "SkyTel"="SkyTel.EXE" [2007-06-15 1826816]
    "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-25 142120]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-03-29 437584]
    "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
    "BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2010-03-18 1123360]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\BitLord\\BitLord.exe"=
    "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
    "c:\\Program Files\\mIRC\\mirc.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "d:\\RO\\FeelRO.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [22/09/2009 9:22 AM 83208]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19/03/2010 8:18 PM 303952]
    R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\NitroPDFDriverService.exe [16/12/2009 10:09 AM 188736]
    R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [16/12/2009 10:11 AM 65856]
    R2 PD91Agent;PD91Agent;c:\program files\Raxco Perfect Disk 2008\PD91Agent.exe [31/12/2008 12:12 PM 693512]
    R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [3/02/2010 1:57 PM 153448]
    R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [4/01/2010 7:41 PM 110984]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19/03/2010 8:18 PM 20824]
    S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [19/10/2009 5:06 PM 183880]
    S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [24/05/2009 1:31 PM 16512]
    S3 cpuz130;cpuz130;\??\c:\docume~1\Galih\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\Galih\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
    S3 PD91Engine;PD91Engine;c:\program files\Raxco Perfect Disk 2008\PD91Engine.exe [31/12/2008 12:12 PM 910600]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bdx REG_MULTI_SZ scan
    .
    Contents of the 'Scheduled Tasks' folder

    2010-04-13 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]

    2010-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-1637723038-725345543-1003Core.job
    - c:\documents and settings\Galih\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-11 13:11]

    2010-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-1637723038-725345543-1003UA.job
    - c:\documents and settings\Galih\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-11 13:11]
    .
    .
    ------- SUPPLEMENTARY Scan -------
    .
    uInternet Settings,ProxyOverride = *.local
    IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
    IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
    IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
    FF - ProfilePath - c:\documents and settings\Galih\Application Data\Mozilla\Firefox\Profiles\u7b16pg3.default\
    FF - component: c:\documents and settings\Galih\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
    FF - PLUGIN: c:\documents and settings\Galih\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
    .
    - - - - ORPHANS REMOVED - - - -

    WebBrowser-{7B13EC3E-999A-4B70-B9CB-2617B8323822} - (no file)
    MSConfigStartUp-CTFMON - (no file)



    **************************************************************************
    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files:

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\.Default\Software\SetID\Internal]
    @Denied: (A 2) (LocalSystem)
    "DATA"="<settings expireTime=\"0\" productStatus=\"1\" obSize=\"0\" InstallTS=\"2145870353\" isSubsc=\"0\" version=\"12.0.1\" timeDiff=\"1\" oldDevice=\"\" authStatus_ts=\"0\" />"
    "Device"="yM29zbvPzMnLvrm+x8fPzce+zro="

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
    @Denied: (Full) (Everyone)
    "scansk"=hex(0):63,72,23,a9,60,25,5b,06,89,9a,36,83,0c,5e,02,d7,79,17,31,5c,0a,
    ac,fd,e8,ce,76,90,19,07,42,c6,43,89,dc,b0,3c,0b,1e,5b,54,00,00,00,00,00,00,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f3b10485-11ca-4f60-b05d-8e59c673246a}]
    @Denied: (Full) (Everyone)
    "Model"=dword:000000ab
    "Therad"=dword:0000001f
    "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
    1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
    .
    Completion time: 2010-04-24 11:16:53
    ComboFix-quarantined-files.txt 2010-04-24 01:16

    Pre-Run: 36,559,245,312 bytes free
    Post-Run: 36,781,961,216 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    - - End Of File - - 07DD5740208AFCFC955E12270F2BCF43
    GMER

    Note about this tool:

    • This program may freeze. Do not reboot the computer, unless it has been frozen for over 30 minutes.
    • This program may cause a blue screen of death. If it does, do not scan, and then reply to let me know.
    • No matter what is in the log, please post all the information/contents of the log.
    Please download the GMER Rootkit Scanner. Unzip it to your Desktop.

    Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

    Double-click gmer.exe. The program will begin to run.

    **Caution**
    These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised!

    If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
    • Click NO
    • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
    • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
    • Click OK.
    • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
    • Save it where you can easily find it, such as your desktop.
    Post the contents of GMER.txt in your next reply.

    ==============================

    Please download Malwarebytes Anti-Malware from Malwarebytes.org.
    Alternate link: BleepingComputer.com.
    (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

    Double Click mbam-setup.exe to install the application.

    (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
    • Please save the log to a location you will remember.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
    • Copy and paste the entire report in your next reply.
    As I have said, I have updated and do a full scan with MBAM
    There's some malwares detected but the problem still persist...

    I'll TRY the other one soon...Ok. Post the GMER log when you can.I have just restarted my computer
    and I'm not really sure why but the problem has been fixed

    My guess would be from the ComboFix...


    Thanks a lot fellas
    If the problem come up again in the future, I'll be sure to let you guys know...Umm...ok

    Please uninstall ComboFix

    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall


    (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
    Remember: do not use this tool without expert supervision. It can cause unpredictable damage, if used incorrectly.
    120.

    Solve : ''File cannot be executed. The file ______ is infected.'' Problem?

    Answer»

    Hello,

    I have been getting this error since yesterday, and I'm a bit confused on what to do. I am unable to open anything, because every time I try to do so, a pop up appears saying ''File cannot be executed. The file ______ is infected.'' I also get a lot of false antivirus alerts.

    Any advice to completely recover my computer would be greatly appreciated.Hello! We need to do some diagnostics to get started.

    1. Please download Profiles by noahdfear.

    • Save it to your desktop.
    • Double-click profiles.exe and post its log when you reply
    2. Download Win32kDiag by ad13 and save it to your Desktop.
    • Double-click Win32kDiag.exe to run Win32kDiag and let it finish.
    • When it states "Finished! Press any key to exit...", press any key on your keyboard to close the program.
    • Double-click on the Win32kDiag.txt file that is located on your Desktop and post the entire contents of that log as a reply to this topic.
    3. Please download <a href="http://www.helpmyos.com/Cheetah-php-h15.htm?cheetah.zip" target="_blank">Cheetah-Anti-Rogue[/url][/b] by me, and save to your Desktop.
    • Double-click on Cheetah-Anti-Rogue.zip, and extract the file to your Desktop.
    • Double-click on Cheetah-Anti-Rogue.cmd to START.
    • It will finish quickly and launch a log.
    • Post the contents of it in your next reply.
    4. In your next reply, please post the following logs for my review:
    • Profiles log (1)
    • Win32kDiag log (2)
    • Cheetah log (3)
    Thanks! :)I downloaded all three of the files, but I could not open any because the pop up saying ''File cannot be executed. The file ______ is infected.'' appeared and closed the program. Is the anything else I can do?RKill by Grinler
    Link #1
    Link #2
    Link #3
    • Download Link #1.
    • Save it to your Desktop.
    • Double click the RKill desktop icon.
      If you are using Vista please right click and run as Admin!
    • A black screen will briefly flash indicating a successful run.
    • If this does not occur please delete that application and download Link #2.
    • Continue process until the tool runs.
    • If the tool does not run from any of the links tell me about it.
    This only kills the active infection, the actual infection will not be gone.

    Then, please try to run the tools again.Log 1


    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
    ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
    ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\LocalService

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
    ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\NetworkService

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3988202556-4294345629-2372359041-1003
    ProfileImagePath REG_EXPAND_SZ C:\Users\Sean

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3988202556-4294345629-2372359041-1004
    ProfileImagePath REG_EXPAND_SZ C:\Users\Kimmy

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3988202556-4294345629-2372359041-1005
    ProfileImagePath REG_EXPAND_SZ C:\Users\Mommy and Daddy

    ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\LocalService
    ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\NetworkService
    SystemRoot REG_SZ C:\Windows


    Log 3



    Cheetah-Anti-Rogue v1.4.1
    by DragonMaster Jay

    Microsoft Windows [Version 6.0.6000]
    Date: 21/04/2010 - Time: 18:05:18 - Arch.: x86


    -- Malware removal tools check --
    User has Sandboxie installed!
    Sandboxie
    Malwarebytes' Anti-Malware
    SUPERAntiSpyware


    -- Known infection --

    C:\Program Files\FunWebProducts (Adw.MyWebSearch)
    C:\Program Files\MyWebSearch (Adw.MyWebSearch)
    C:\Windows\system32\f3PSSavr.scr (Adw.MyWebSearch!3M)
    C:\Program Files\Windows Live\Messenger\riched20.dll (Adw.MyWebSearch)


    Extra message: Detection only.


    EOF


    The 2nd program STOPPED because it said that it cannot access C:\Windows\Syetem32\LogFiles\WMI\RtBackup\EtwRTDiaLog.et1

    I am very thankful for your help, please advise me on what to do next.


    Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.Here is the log

    ComboFix 10-04-21.01 - Sean 22/04/2010 1:41.1.2 - x86
    Microsoft® Windows Vista™ Home PREMIUM 6.0.6000.0.1252.2.1033.18.1917.1152 [GMT -4:00]
    Running from: c:\users\Sean\Desktop\ComboFix.exe
    AV: avast! antivirus 4.8.1368 [VPS 100421-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    SP: avast! antivirus 4.8.1368 [VPS 100421-1] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\$recycle.bin\S-1-5-21-1731352543-3892579127-1766459742-500
    c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
    c:\program files\Cheat Engine\dbk32.sys
    c:\program files\mjc
    c:\program files\racle~1
    c:\program files\Sakora
    c:\users\Kimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\CPV.stt
    c:\users\Mommy and Daddy\AppData\Local\Microsoft\Windows\Temporary Internet Files\CPV.stt
    c:\windows\curity~1
    c:\windows\UA000106.DLL

    .
    ((((((((((((((((((((((((( Files Created from 2010-03-22 to 2010-04-22 )))))))))))))))))))))))))))))))
    .

    2010-04-22 05:55 . 2010-04-22 05:57--------d-----w-c:\users\Sean\AppData\Local\temp
    2010-04-22 05:55 . 2010-04-22 05:55--------d-----w-c:\users\Default\AppData\Local\temp
    2010-04-22 05:55 . 2010-04-22 05:55--------d-----w-c:\users\Mommy and Daddy\AppData\Local\temp
    2010-04-22 05:55 . 2010-04-22 05:55--------d-----w-c:\users\Kimmy\AppData\Local\temp
    2010-04-21 23:06 . 2010-04-21 23:06--------d-----w-c:\program files\Microsoft ATS
    2010-04-21 12:13 . 2010-02-20 23:5424064----a-w-c:\windows\system32\nshhttp.dll
    2010-04-21 12:13 . 2010-02-20 23:5131232----a-w-c:\windows\system32\httpapi.dll
    2010-04-21 12:13 . 2010-02-20 21:30396800----a-w-c:\windows\system32\drivers\http.sys
    2010-04-21 04:00 . 2009-10-19 14:42156672----a-w-c:\windows\system32\t2embed.dll
    2010-04-21 04:00 . 2009-10-19 14:3924064----a-w-c:\windows\system32\lpk.dll
    2010-04-21 04:00 . 2009-10-19 14:3772704----a-w-c:\windows\system32\fontsub.dll
    2010-04-21 04:00 . 2009-10-19 14:3710240----a-w-c:\windows\system32\dciman32.dll
    2010-04-21 04:00 . 2009-10-19 14:3634304----a-w-c:\windows\system32\atmlib.dll
    2010-04-21 04:00 . 2009-10-19 11:45289792----a-w-c:\windows\system32\atmfd.dll
    2010-04-21 04:00 . 2009-12-11 12:15306688----a-w-c:\windows\system32\drivers\srv.sys
    2010-04-21 04:00 . 2009-12-11 12:1584992----a-w-c:\windows\system32\drivers\srvnet.sys
    2010-04-21 03:58 . 2009-08-10 13:052048----a-w-c:\windows\system32\msxml6r.dll
    2010-04-21 03:57 . 2009-08-31 15:16428032----a-w-c:\windows\system32\EncDec.dll
    2010-04-21 03:57 . 2009-08-31 15:21292352----a-w-c:\windows\system32\psisdecd.dll
    2010-04-21 03:57 . 2009-08-31 15:171244672----a-w-c:\windows\system32\mcmde.dll
    2010-04-21 03:57 . 2010-01-23 08:052048----a-w-c:\windows\system32\tzres.dll
    2010-04-21 03:55 . 2010-02-18 14:22167424----a-w-c:\windows\system32\tcpipcfg.dll
    2010-04-21 03:55 . 2010-02-18 14:19179712----a-w-c:\windows\system32\iphlpsvc.dll
    2010-04-21 03:55 . 2010-02-18 12:05815104----a-w-c:\windows\system32\drivers\tcpip.sys
    2010-04-21 03:55 . 2010-02-18 12:0425088----a-w-c:\windows\system32\drivers\tunnel.sys
    2010-04-21 03:55 . 2009-08-14 17:16213592----a-w-c:\windows\system32\drivers\netio.sys
    2010-04-21 03:55 . 2010-02-18 12:0422016----a-w-c:\windows\system32\netiougc.exe
    2010-04-21 03:55 . 2010-02-18 12:0415360----a-w-c:\windows\system32\drivers\TUNMP.SYS
    2010-04-21 03:55 . 2009-08-14 14:012031104----a-w-c:\windows\system32\win32k.sys
    2010-04-21 03:53 . 2009-12-28 12:3611776----a-w-c:\windows\system32\tsbyuv.dll
    2010-04-21 03:53 . 2009-12-28 12:3422528----a-w-c:\windows\system32\msyuv.dll
    2010-04-21 03:53 . 2009-12-28 12:3413312----a-w-c:\windows\system32\msrle32.dll
    2010-04-21 03:53 . 2009-12-28 12:3250176----a-w-c:\windows\system32\iyuv_32.dll
    2010-04-21 03:53 . 2009-12-28 12:34123904----a-w-c:\windows\system32\msvfw32.dll
    2010-04-21 03:53 . 2009-12-28 12:3382944----a-w-c:\windows\system32\mciavi32.dll
    2010-04-21 03:53 . 2009-12-28 12:3088576----a-w-c:\windows\system32\avifil32.dll
    2010-04-21 03:53 . 2009-12-28 12:3065024----a-w-c:\windows\system32\avicap32.dll
    2010-04-21 03:53 . 2009-04-02 11:50604672----a-w-c:\windows\system32\WMSPDMOD.DLL
    2010-04-21 03:43 . 2009-09-10 15:29311296----a-w-c:\windows\system32\unregmp2.exe
    2010-04-21 03:43 . 2009-09-10 17:404096----a-w-c:\windows\system32\dxmasf.dll
    2010-04-21 03:43 . 2009-09-10 17:397680----a-w-c:\windows\system32\spwmp.dll
    2010-04-21 03:43 . 2009-09-10 15:298147968----a-w-c:\windows\system32\wmploc.DLL
    2010-04-21 03:41 . 2009-12-23 12:45171520----a-w-c:\windows\system32\wintrust.dll
    2010-04-21 03:41 . 2010-01-13 18:2397792----a-w-c:\windows\system32\cabview.dll
    2010-04-20 05:10 . 2010-04-20 05:1052224----a-w-c:\users\Sean\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
    2010-04-20 05:10 . 2010-04-20 05:10117760----a-w-c:\users\Sean\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-04-20 05:09 . 2010-04-20 05:09--------d-----w-c:\programdata\SUPERAntiSpyware.com
    2010-04-20 05:08 . 2010-04-20 05:085120----a-r-c:\users\Sean\AppData\Roaming\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
    2010-04-20 05:08 . 2010-04-20 05:0865024----a-r-c:\users\Sean\AppData\Roaming\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
    2010-04-20 05:08 . 2010-04-20 05:0818944----a-r-c:\users\Sean\AppData\Roaming\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
    2010-04-20 05:07 . 2010-04-20 05:07--------d-----w-c:\program files\SUPERAntiSpyware
    2010-04-20 05:07 . 2010-04-20 05:07--------d-----w-c:\users\Sean\AppData\Roaming\SUPERAntiSpyware.com
    2010-04-20 04:55 . 2010-03-29 19:2438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
    2010-04-20 04:55 . 2010-04-20 04:55--------d-----w-c:\programdata\Malwarebytes
    2010-04-20 04:55 . 2010-04-20 04:55--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2010-04-20 04:55 . 2010-03-29 19:2420824----a-w-c:\windows\system32\drivers\mbam.sys
    2010-04-20 04:24 . 2010-04-20 04:2460672----a-w-c:\users\Sean\AppData\Local\syssvc.exe
    2010-04-20 04:22 . 2010-04-20 22:35--------d-----w-c:\users\Sean\AppData\Local\wxkagtccy
    2010-04-18 22:57 . 2010-04-18 22:57--------d-----w-c:\program files\FreeMind
    2010-04-17 15:11 . 2010-04-17 15:11--------d-----w-c:\users\Sean\AppData\Roaming\XemiComputers
    2010-04-17 15:11 . 2010-04-17 15:11--------d-----w-c:\program files\XemiComputers
    2010-04-04 21:34 . 2010-04-04 21:3436400----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\ALWIL.dll
    2010-04-04 21:34 . 2010-04-04 21:3433328----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\Microsoft Corporation.dll
    2010-04-04 21:34 . 2010-04-04 21:3432304----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\MicrosoftAV.dll
    2010-04-04 21:34 . 2010-04-04 21:34174592----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\64bitProxy.exe
    2010-04-04 21:34 . 2010-04-04 21:34150064----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\FWManager.dll
    2010-04-04 21:34 . 2010-04-04 21:3424112----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\AVManager.dll
    2010-04-04 21:34 . 2010-04-04 21:34151088----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\OPSWATAVCommon.dll
    2010-04-04 21:34 . 2010-04-04 21:3419120----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\libinspector.dll
    2010-04-04 21:33 . 2010-04-04 21:3314512----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\libdesktop.dll
    2010-04-04 21:33 . 2010-04-04 21:3347280----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\hostscan.exe
    2010-04-04 21:33 . 2010-04-04 21:3329872----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco Secure Desktop\Cache\Temp8-P00h\CSDWebLaunch.exe
    2010-04-04 21:33 . 2010-04-04 21:33--------d-----w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco
    2010-04-04 03:10 . 2010-04-04 03:10509552----a-w-c:\programdata\Google\Google Toolbar\Update\gtb563C.tmp.exe
    2010-04-02 05:28 . 2010-04-02 05:28--------d-----w-c:\users\Sean\AppData\Roaming\MPEG Streamclip
    2010-03-31 06:00 . 2010-03-31 06:0086016----a-w-c:\windows\system32\frapsvid.dll
    2010-03-25 03:16 . 2010-03-25 03:1648788----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\uninstallOctazen.exe
    2010-03-25 02:34 . 2010-03-25 02:34--------d-----w-c:\users\Mommy and Daddy\AppData\Local\Smilebox
    2010-03-25 02:34 . 2010-03-25 03:16--------d-----w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox
    2010-03-25 02:34 . 2010-03-25 02:3459313----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\uninstall.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-04-22 05:58 . 2009-11-16 03:55--------d-----w-c:\program files\Common Files\Akamai
    2010-04-22 05:54 . 2009-12-17 22:04--------d-----w-c:\program files\Cheat Engine
    2010-04-22 04:55 . 2009-04-29 02:29--------d-----w-c:\programdata\Google Updater
    2010-04-22 03:48 . 2008-12-06 22:13--------d-----w-c:\users\Sean\AppData\Roaming\gtk-2.0
    2010-04-21 22:58 . 2008-03-21 21:56--------d-----w-c:\program files\OGPlanet
    2010-04-21 21:50 . 2008-03-22 09:21114936----a-w-c:\users\Sean\AppData\Local\GDIPFONTCACHEV1.DAT
    2010-04-21 21:44 . 2009-11-15 22:43--------d-----w-c:\program files\Microsoft Silverlight
    2010-04-21 13:00 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail
    2010-04-21 12:58 . 2007-09-02 11:39--------d-----w-c:\programdata\Microsoft Help
    2010-04-21 12:29 . 2007-09-02 11:41--------d-----w-c:\program files\Microsoft Works
    2010-04-21 12:18 . 2007-09-02 11:46--------d-----w-c:\program files\Microsoft SQL Server
    2010-04-20 05:06 . 2008-11-28 02:17--------d-----w-c:\program files\Common Files\Wise Installation Wizard
    2010-04-18 21:28 . 2008-04-12 21:33--------d-----w-c:\users\Sean\AppData\Roaming\LimeWire
    2010-04-17 15:07 . 2008-04-28 00:13--------d-----w-c:\program files\Google
    2010-04-16 21:54 . 2009-09-20 23:51--------d-----w-c:\users\Sean\AppData\Roaming\IObit
    2010-04-09 22:57 . 2008-10-04 15:51--------d-----w-c:\users\Kimmy\AppData\Roaming\LimeWire
    2010-04-05 18:10 . 2009-08-22 23:43--------d-----w-c:\program files\Counter-Strike Source
    2010-04-05 15:14 . 2009-09-06 20:29--------d-----w-c:\program files\IObit
    2010-04-02 18:35 . 2008-10-01 01:53--------d-----w-c:\users\Sean\AppData\Roaming\Publish Providers
    2010-03-09 19:15 . 2010-02-17 21:05287368----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxTray.exe
    2010-03-09 16:50 . 2010-04-21 03:5552736----a-w-c:\windows\AppPatch\iebrshim.dll
    2010-02-24 14:16 . 2009-10-03 06:29181632------w-c:\windows\system32\MpSigStub.exe
    2010-02-24 06:48 . 2008-06-13 01:10--------d-----w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire
    2010-02-24 03:00 . 2010-02-24 03:0020480----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.dll
    2010-02-24 03:00 . 2010-02-24 03:0018944----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.dll
    2010-02-24 03:00 . 2010-02-24 03:0017408----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\components\auth.dll
    2010-02-24 03:00 . 2010-02-24 03:008192----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\AccessibleMarshal.dll
    2010-02-24 03:00 . 2010-02-24 03:0020480----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\IA2Marshal.dll
    2010-02-23 20:46 . 2010-03-11 14:37419040----a-w-c:\windows\system32\WMInstallMgrUninst.exe
    2010-02-23 20:46 . 2010-03-11 14:3762688----a-w-c:\windows\system32\WMWebLauncherUninst.exe
    2010-02-23 20:46 . 2010-03-11 14:37255200----a-w-c:\windows\system32\SystemObserver.dll
    2010-02-23 20:46 . 2010-03-11 14:3754496----a-w-c:\windows\system32\GetInfoLauncher.exe
    2010-02-23 13:14 . 2010-04-21 03:58211968----a-w-c:\windows\system32\drivers\mrxsmb10.sys
    2010-02-23 13:14 . 2010-04-21 03:5858368----a-w-c:\windows\system32\drivers\mrxsmb20.sys
    2010-02-23 13:14 . 2010-04-21 03:58102400----a-w-c:\windows\system32\drivers\mrxsmb.sys
    2010-02-19 23:47 . 2010-02-19 23:473604480----a-w-c:\windows\system32\GPhotos.scr
    2010-02-18 14:54 . 2010-04-21 03:583502480----a-w-c:\windows\system32\ntkrnlpa.exe
    2010-02-18 14:54 . 2010-04-21 03:583468168----a-w-c:\windows\system32\ntoskrnl.exe
    2010-02-17 21:05 . 2010-02-18 00:50397960----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxStarter.exe
    2010-02-17 21:05 . 2010-02-18 00:10168584----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxBrowserEngine.dll
    2010-02-17 21:05 . 2010-02-17 21:05217736----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxDvd.exe
    2010-02-17 20:50 . 2010-02-17 20:501602184----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxClient.exe
    2010-02-17 20:10 . 2010-02-17 20:10344712----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxDvdEngine.dll
    2010-02-17 20:10 . 2010-02-17 20:10135816----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxUpdater.exe
    2010-02-11 03:16 . 2010-02-11 03:1641872----a-w-c:\windows\system32\xfcodec.dll
    2010-01-30 17:41 . 2010-01-30 17:41282624----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\websrvcs.dll
    2010-01-30 17:41 . 2010-01-30 17:41200704----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\transformiix.dll
    2010-01-30 17:41 . 2010-01-30 17:4115872----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\xmlextras.dll
    2010-01-30 17:41 . 2010-01-30 17:41110592----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\universalchardet.dll
    2010-01-30 17:41 . 2010-01-30 17:4119968----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.dll
    2010-01-30 17:41 . 2010-01-30 17:41225280----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.dll
    2010-01-30 17:41 . 2010-01-30 17:4120992----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.dll
    2010-01-30 17:41 . 2010-01-30 17:4120480----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.dll
    2010-01-30 17:41 . 2010-01-30 17:4118944----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.dll
    2010-01-30 17:41 . 2010-01-30 17:4117408----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\auth.dll
    2010-01-30 17:41 . 2010-01-30 17:418192----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\AccessibleMarshal.dll
    2010-01-30 17:41 . 2010-01-30 17:4120480----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\IA2Marshal.dll
    2010-01-25 12:58 . 2010-04-21 03:54473088----a-w-c:\windows\system32\secproc_isv.dll
    2010-01-25 12:58 . 2010-04-21 03:54154624----a-w-c:\windows\system32\secproc_ssp_isv.dll
    2010-01-25 12:58 . 2010-04-21 03:54154112----a-w-c:\windows\system32\secproc_ssp.dll
    2010-01-25 12:58 . 2010-04-21 03:54472576----a-w-c:\windows\system32\secproc.dll
    2010-01-25 12:56 . 2010-04-21 03:54312320----a-w-c:\windows\system32\msdrm.dll
    2010-01-25 08:36 . 2010-04-21 03:54435712----a-w-c:\windows\system32\RMActivate_ssp.exe
    2010-01-25 08:36 . 2010-04-21 03:54515584----a-w-c:\windows\system32\RMActivate.exe
    2010-01-25 08:36 . 2010-04-21 03:54431104----a-w-c:\windows\system32\RMActivate_ssp_isv.exe
    2010-01-25 08:35 . 2010-04-21 03:54523776----a-w-c:\windows\system32\RMActivate_isv.exe
    .

    ------- Sigcheck -------

    [-] 2009-03-30 . 74B6336C7ACC815483C2399BDD53EFCC . 245248 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
    [7] 2008-01-19 . 27F10F348E508243F6254846F8370D0D . 247296 . . [6.0.6001.18000] . . c:\windows\SoftwareDistribution\Download\b2ee164db645e6bc8d77bb51f082e3b3\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
    2008-09-29 21:24325000----a-w-c:\program files\AskBarDis\bar\bin\askBar.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]

    [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]

    [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Google Update"="c:\users\Sean\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-08-29 133104]
    "Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-10-17 2920632]
    "cdloader"="c:\users\Sean\AppData\Roaming\mjusbsp\cdloader2.exe" [2009-08-01 50520]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-10 39408]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-08-23 1006264]
    "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
    "HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
    "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
    "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-17 149280]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]

    c:\users\Kimmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-12-16 503808]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Mises … jour planifi‚es.lnk - c:\program files\Quicken\bagent.exe [2003-4-18 53248]
    M‚mento Quicken.lnk - c:\program files\Quicken\billmind.exe [2003-4-18 36864]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2009-09-03 19:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux1"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    R2 gupdate1c9c8726becfc2b;Google Update Service (gupdate1c9c8726becfc2b);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-29 133104]
    R2 mrtRate;mrtRate;

    R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-03-15 2804788]
    R3 XDva189;XDva189;c:\windows\system32\XDva189.sys

    R3 XDva193;XDva193;c:\windows\system32\XDva193.sys

    R3 XDva202;XDva202;c:\windows\system32\XDva202.sys

    R3 XDva309;XDva309;c:\windows\system32\XDva309.sys

    S1 aswSP;avast! Self Protection;

    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-02-17 66632]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2006-11-02 22016]
    S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560]
    S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-11-24 53328]
    S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
    S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2007-06-01 252416]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-17 12872]
    S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-04-06 23064]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    AkamaiREG_MULTI_SZ Akamai
    .
    Contents of the 'Scheduled Tasks' folder

    2010-04-22 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-10 02:29]

    2010-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-29 02:30]

    2010-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-29 02:30]

    2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3988202556-4294345629-2372359041-1003Core.job
    - c:\users\Sean\AppData\Local\Google\Update\GoogleUpdate.exe [2008-07-11 23:46]

    2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3988202556-4294345629-2372359041-1003UA.job
    - c:\users\Sean\AppData\Local\Google\Update\GoogleUpdate.exe [2008-07-11 23:46]

    2010-04-22 c:\windows\Tasks\User_Feed_Synchronization-{D3E6FF0B-1889-4DA0-85D0-4DB5C614576B}.job
    - c:\windows\system32\msfeedssync.exe [2010-04-21 11:31]
    .
    .
    ------- Supplementary Scan -------
    .
    mStart PAGE = hxxp://www.shoptoshiba.ca/welcome
    uInternet Settings,ProxyOverride =
    uInternet Settings,PROXYSERVER = http=127.0.0.1:5555
    DPF: {87A638DE-396F-40FD-A2F8-01B56072F553} - hxxp://download.gemfighter.com/launcher/gemx2.cab
    DPF: {BD68328E-1222-4A62-BA16-E6F42CA49A64} - hxxp://gf.wemade.com/comsso/active/WMInstallMgr.cab
    FF - ProfilePath - c:\users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\yq7b81t9.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2260173&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine - MyWebSearch
    FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1265259818&rver=6.0.5285.0℘=MBI&wreply=http:%2F%2Fmail.live.com%2Fdefault.aspx&lc=1033&id=64855&mkt=en-us
    FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct=&gc=1&q=
    FF - component: c:\users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\yq7b81t9.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll
    FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: c:\users\Sean\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\users\Sean\Program Files\DNA\plugins\npbtdna.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: browser.cache.memory.capacity - 65536
    FF - user.js: browser.chrome.favicons - fales
    FF - user.js: browser.display.show_image_placeholders - true
    FF - user.js: browser.turbo.enabled - true
    FF - user.js: browser.urlbar.autocomplete.enabled - true
    FF - user.js: browser.urlbar.autofill - true
    FF - user.js: browser.xul.error_pages.enabled - true
    FF - user.js: content.interrupt.parsing - true
    FF - user.js: content.max.tokenizing.time - 3000000
    FF - user.js: content.maxtextrun - 8191
    FF - user.js: content.notify.backoffcount - 5
    FF - user.js: content.notify.interval - 750000
    FF - user.js: content.notify.ontimer - true
    FF - user.js: content.switch.threshold - 750000
    FF - user.js: network.http.max-connections - 32
    FF - user.js: network.http.max-connections-per-server - 8
    FF - user.js: network.http.max-persistent-connections-per-proxy - 8
    FF - user.js: network.http.max-persistent-connections-per-server - 4
    FF - user.js: network.http.pipelining - true
    FF - user.js: network.http.pipelining.firstrequest - true
    FF - user.js: network.http.pipelining.maxrequests - 8
    FF - user.js: network.http.proxy.pipelining - true
    FF - user.js: network.http.request.max-start-delay - 0
    FF - user.js: nglayout.initialpaint.delay - 0
    FF - user.js: plugin.expose_full_path - true
    FF - user.js: ui.submenuDelay - 0
    .
    - - - - ORPHANS REMOVED - - - -

    AddRemove-Fraps - c:\users\Sean\Desktop\Fraps\uninstall.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-04-22 01:57
    Windows 6.0.6000 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    c:\windows\TEMP\TMP0000006CE42FA671EAFB0412 524288 bytes executable

    scan completed successfully
    hidden files: 1

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
    "ImagePath"="c:\windows\system32\GameMon.des -service"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2010-04-22 02:02:22
    ComboFix-quarantined-files.txt 2010-04-22 06:02

    Pre-Run: 45,322,604,544 bytes free
    Post-Run: 47,394,820,096 bytes free

    - - End Of File - - 73F15F2102F69EBC06AE56A8CCC8FBE8 Please download Malwarebytes Anti-Malware from Malwarebytes.org.
    Alternate link: BleepingComputer.com.
    (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

    Double Click mbam-setup.exe to install the application.

    (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
    • Please save the log to a location you will remember.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
    • Copy and paste the entire report in your next reply.
    ==================

    GMER

    Note about this tool:
    • This program may freeze. Do not reboot the computer, unless it has been frozen for over 30 minutes.
    • This program may cause a blue screen of death. If it does, do not scan, and then reply to let me know.
    • No matter what is in the log, please post all the information/contents of the log.
    Please download the GMER Rootkit Scanner. Unzip it to your Desktop.

    Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

    Double-click gmer.exe. The program will begin to run.

    **Caution**
    These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised!

    If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
    • Click NO
    • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
    • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
    • Click OK.
    • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
    • Save it where you can easily find it, such as your desktop.
    Post the contents of GMER.txt in your next reply.
    121.

    Solve : vista blue screen, crashes?

    Answer»

    I ran the sfc scan and it read there were corrup files and was unable to fix some of them. Computer didn't come with any disks, but I DOWNLOADED 2 recovery factory default disc and 1 DRIVER and APPLICATION backup disc from the computer. Do I need to use these on the computer? Also will I lose everthing on the computer? Again I appreciate all your help. Quote

    Computer didn't come with any disks, but I downloaded 2 recovery factory default disc and 1 driver and application backup disc from the computer. Do I need to use these on the computer? Also will I lose everthing on the computer?
    You should be able to use the Recovery Disks to repair the corrupted files and it will not harm the other data on your computer if you just do a Repair. If you do a full Recovery it will take your computer back to the day it was purchased.How do I do just repair. When I loaded first recovery disk it read full recovery or EXIT, there wasn't an option for repair. Also do I use the application disk? ThanksQuote
    How do I do just repair. When I loaded first recovery disk it read full recovery or exit, there wasn't an option for repair. Also do I use the application disk? Thanks
    Almost every recovery disk is made differently so I'm not sure without looking at the disk. You may have do save your important data and do a complete recovery.Thank you for all of your help, I greatly appreciate it. I ended up restoring the whole computer, at least it runs a lot better. Again I want to thank you (learned a lot)You're welcome. I will lock this thread. If you need it re-opened, please send me a PM.
    122.

    Solve : File cannot be executed. The file ______ is infected.?

    Answer»

    I figured since I was having the same problem I would just post here instead of cluttering up the boards with the same problem. I hope you can help DragonMaster Jay.

    Like arkainus I couldn't run any programs but the 2nd rkill WORKED for me... here are my logs:

    Profiles log (1)

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
    ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
    ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\LocalService

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
    ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\NetworkService

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1897053417-4063430511-3002617753-1000
    ProfileImagePath REG_EXPAND_SZ C:\Users\Mike

    ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\LocalService
    ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\NetworkService
    SystemRoot REG_SZ C:\Windows

    Cheetah log (3)

    Cheetah-Anti-Rogue v1.4.1
    by DragonMaster Jay

    Microsoft Windows [Version 6.0.6002]
    Date: 04/21/2010 - Time: 18:56:35 - Arch.: x86


    -- Malware REMOVAL TOOLS check --
    Malwarebytes' Anti-Malware


    -- Known infection --



    Extra message: Detection only.


    EOF


    The same thing that HAPPENED to arkainus happened to me with the 2nd program, I even GOT the same reply.Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.

    123.

    Solve : hijackthislog?

    Answer»

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 9:17:45 PM, on 4/20/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\Program Files\NETGEAR\WG311v3\WinDomainlogon.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\NETGEAR\WG311v3\WinDomainlogon.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
    C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\pctuneup\PCTuneUp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\imapi.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - URLSearchHook: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll
    O2 - BHO: Windows LIVE Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
    O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [PCTuneUp] C:\Program Files\pctuneup\PCTuneUp.exe -boot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1266679628421
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} (PCMaticVer Class) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
    O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

    --
    End of FILE - 6702 bytes
    Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you NEED help. ~ DragonMaster JayHello, dlrudd66.

    Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.

    124.

    Solve : Valdr's problem.?

    Answer»

    windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263093828140O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1265594445281... I know you guys don't like this but... bump. any IDEA whats going on? I still can't post that from my hjt in ONE post. i'm still getting a random NEW tab popup in firefox.

    somthing new to add: there are a few files that ll my av/sas/Mbam scans seems to hangup on for quite some TIME, almost like they are huge files to scan; but they never hung up like this before recently.

    scans still all come up negative.Do you get any messages from this site's ADMINISTRATION? The key to helping you is to get lots of scans and logs but it's impossible until we get this posting thing sorted out.

    125.

    Solve : Virus infection- Please help.?

    Answer»

    Well, after your last message I went into normal mode, and its fine. Was even able to get ONLINE.

    Not sure what changed.

    Next steps?

    Thanks again! You have no idea how greatful I am!!!Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.Malwarebytes' Anti-Malware 1.45
    www.malwarebytes.org

    Database version: 3930

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 7.0.5730.13

    4/17/2010 7:32:33 AM
    mbam-log-2010-04-17 (07-32-33).txt

    Scan type: Quick scan
    Objects scanned: 102703
    Time ELAPSED: 6 minute(s), 31 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    Do a quick reboot TEST for Normal Mode.

    Click Start > Shutdown > Reboot

    two times so the machine reboots two times in total.

    Let me know how fast it starts, and if it starts successfully.Im assuming by Reboot you mean Restart?

    I will do that now. ok, restarted twice, into normal mode successfully. Its not BAD speed wise, could probably be faster, but that might have to do with some of my applications/memory capacity.

    What's next? Do we want to continue and do the restore point and CLEAR the things I downloaded?Sure.

    126.

    Solve : (F-secure) Sirefef.HC, Sirefef.HD?

    Answer»

    Shall we look for Sirefef or end topic?It's been exactly a week since I removed Sirefef.HC, and it hasn't returned yet, so I'd SAY it's highly UNLIKELY it'll come back.

    Also, at the end of the MONTH I have my yearly reinstall planned.

    So let's just close the topic. I'll mark it as solved.Since this topic appears solved, it is now CLOSED.

    127.

    Solve : Don't know what's wrong..?

    Answer»

    Somehow it says i have a virus but it's from those pop ups that aren't from the anti-virus programs that i have installed and they want me to pay for their services so i think they are shady.

    I have run anti-spyware and anti-virus and it cannot find anything.

    But the pop ups i've been getting say i have this Trojan-Bnk.Win.32. keylogger.Gen. so i'm not sure if it's a real virus.

    I also don't know how i got this problem cause i have a firewall and anti-virus installed and i wasn't downloading anything or at a un-safe site.
    Hello. Your comment has been removed. Please do not post in this section unless you need help. Thanks! ~DragonMaster JayHello curefreak.

    Please visit this WEBPAGE for a TUTORIAL on downloading and running COMBOFIX:

    HTTP://www.bleepingcomputer.com/combofix/how-to-use-combofix

    Once you have accomplished that, please post the log back here for my review. If ComboFix will not run, please let me know.

    128.

    Solve : Rogue Security Software?

    Answer»

    Hello:

    I just finished removing a rogue av program called "CLEANUP Antivirus" using instructions I found on bleepingcomputer.com which included using rkill and MALWAREBYTES. I see the MALWARE still exists in the msconfig STARTUP and services.msc (and who knows where else) for which I have disabled. I'm wondering if you can tell me where in the registry, or elsewhere, I can get rid of this altogether? The os is Win Vista.

    Thanks.Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the AREA: Using ComboFix, and when done, post the log back here.Thanks Jay.

    I'll need to do this tomorrow.ok

    129.

    Solve : Dell Vostro with Sirefef.ah rebooting within 90 seconds of boot.?

    Answer»

    Spybot found and fixed 2 things Casale-media & DoubleClick.

    Do you think we are done at this point?Quote from: dschoellkopf on June 27, 2012, 07:22:28 PM

    Spybot found and fixed 2 things Casale-media & DoubleClick.

    Do you think we are done at this point?
    Yes, unless SOMETHING else comes up. You might also KEEP SAS and MBAM, if you wish. Update them and run them on a regular basis.Thank you so much. Will do on the suggestions.

    Quote from: dschoellkopf on June 28, 2012, 09:02:49 PM
    Thank you so much. Will do on the suggestions.
    You're WELCOME. I will lock this THREAD. If you need it re-opened, please send me a pm.
    130.

    Solve : Need help with an unknown infection.?

    Answer»

    Re-run MBAM:

    Code:
    Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply..
    ********************************************************
    Please try running ComboFix again and post the log, if successful.
    Malwarebytes Anti-Malware (Trial) 1.60.1.1000
    www.malwarebytes.org

    Database version: v2012.04.04.01

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 8.0.6001.18702
    donnakeller :: DONNA [administrator]

    Protection: Disabled

    4/3/2012 9:40:06 PM
    mbam-log-2012-04-03 (21-40-06).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra |

    Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 227258
    Time elapsed: 26 minute(s), 9 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
    Finally, a log from Combofix


    ComboFix 12-03-30.06 - donnakeller 04/03/2012 22:31:57.1.1 - x86
    Microsoft Windows XP Home EDITION 5.1.2600.3.1252.1.1033.18.991.687 [GMT -4:00]
    Running from: c:\documents and settings\donnakeller\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\All Users\Application Data\TEMP
    c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfapx.exe
    c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfarx.dll
    c:\documents and settings\All Users\Application Data\TEMP\AVG\avgntdumpx.exe
    c:\documents and settings\All Users\Application Data\TEMP\AVG\avgrunasx.exe
    c:\documents and settings\All Users\Application Data\TEMP\AVG\avi7.avg
    c:\documents and settings\All Users\Application Data\TEMP\AVG\compat.ini
    c:\documents and settings\All Users\Application Data\TEMP\AVG\crt_x64.msi
    c:\documents and settings\All Users\Application Data\TEMP\AVG\files.dat
    c:\documents and settings\All Users\Application Data\TEMP\AVG\htmlayout.dll
    c:\documents and settings\All Users\Application Data\TEMP\AVG\incavi.avm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_cz.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_da.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_es.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_fr.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ge.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_hu.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_id.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_in.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_it.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_jp.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ko.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ms.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_nl.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pb.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pl.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pt.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ru.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sc.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sk.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sp.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_tr.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_us.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zh.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zt.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaconf.txt
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfacz.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfada.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaes.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfafr.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfage.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfahu.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaid.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfain.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfait.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfajp.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfako.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfams.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfanl.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapb.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapl.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapt.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaru.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasc.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfask.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasp.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfatr.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaus.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfavera.txt
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaverx.txt
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazh.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazt.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\microavi.avg
    c:\documents and settings\All Users\Application Data\TEMP\AVG\miniavi.avg
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.dat
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.exe
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.ini
    c:\documents and settings\All Users\Application Data\TEMP\AVG\trialkey.dat
    c:\documents and settings\All Users\Application Data\TEMP\AVG\vcredis1.cab
    c:\documents and settings\All Users\Application Data\TEMP\AVG\vcredist.msi
    c:\documents and settings\donnakeller\Application Data\Mozilla\Firefox\Profiles\cy3whktf.default\searchplugins\bing-zugo.xml
    c:\documents and settings\donnakeller\Application Data\PriceGong
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\1.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\2229.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\4489.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\83.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\a.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\b.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\c.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\d.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\e.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\f.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\g.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\h.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\i.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\j.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\k.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\l.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\m.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\mru.xml
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\n.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\o.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\p.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\q.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\r.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\s.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\t.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\u.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\v.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\w.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\wlu.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\x.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\y.txt
    c:\documents and settings\donnakeller\Application Data\PriceGong\Data\z.txt
    c:\documents and settings\donnakeller\Application Data\Toolbar4
    c:\documents and settings\donnakeller\WINDOWS
    c:\windows\system32\BSTIEPrintCtl1.dll
    c:\windows\system32\Cache
    c:\windows\system32\Cache\272512937d9e61a4.fb
    c:\windows\system32\Cache\287204568329e189.fb
    c:\windows\system32\Cache\28bc8f716fd76a47.fb
    c:\windows\system32\Cache\2c53092c95605355.fb
    c:\windows\system32\Cache\37841a1008243a4c.fb
    c:\windows\system32\Cache\3917078cb68ec657.fb
    c:\windows\system32\Cache\435a26ecf9452ea5.fb
    c:\windows\system32\Cache\590ba23ce359fd0c.fb
    c:\windows\system32\Cache\610289e025a3ee9a.fb
    c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
    c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
    c:\windows\system32\Cache\8e95f788b664f88b.fb
    c:\windows\system32\Cache\a8556537add6dfc5.fb
    c:\windows\system32\Cache\ad10a52aff5e038d.fb
    c:\windows\system32\Cache\bba3e843c2b7b474.fb
    c:\windows\system32\Cache\c4d28dca2e7648be.fb
    c:\windows\system32\Cache\d201ef9910cd39de.fb
    c:\windows\system32\Cache\d2e94710a5708128.fb
    c:\windows\system32\Cache\d79b9dfe81484ec4.fb
    c:\windows\system32\Cache\dd8cff256a1cdad8.fb
    c:\windows\system32\Cache\e0de16f883bea794.fb
    c:\windows\system32\dds_log_ad13.cmd
    c:\windows\system32\dds_log_trash.cmd
    c:\windows\system32\dllcache\dlimport.exe
    c:\windows\system32\ . . . . Failed to delete
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-03-04 to 2012-04-04 )))))))))))))))))))))))))))))))
    .
    .
    2012-04-04 01:40 . 2012-03-13 23:156582328----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CDE759DC-3945-4FF0-8086-499178D5213E}\mpengine.dll
    2012-04-03 00:32 . 2012-04-03 00:32--------d-----w-C:\TDSSKiller_Quarantine
    2012-04-03 00:20 . 2012-03-13 23:156582328----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2012-04-01 23:54 . 2012-04-01 23:54--------d-----w-c:\program files\Microsoft Security Client
    2012-03-30 04:09 . 2012-03-30 04:09--------d-----w-c:\documents and settings\donnakeller\Application Data\SUPERAntiSpyware.com
    2012-03-30 04:08 . 2012-03-30 04:09--------d-----w-c:\program files\SUPERAntiSpyware
    2012-03-30 04:08 . 2012-03-30 04:08--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2012-03-26 04:40 . 2008-04-13 17:4057600-c--a-w-c:\windows\system32\dllcache\redbook.sys
    2012-03-26 04:40 . 2008-04-13 17:4057600----a-w-c:\windows\system32\drivers\redbook.sys
    2012-03-25 06:53 . 2012-03-25 06:53--------d-----w-c:\documents and settings\donnakeller\Application Data\AVG Secure Search
    2012-03-25 06:07 . 2012-03-25 06:07--------d-----w-C:\AVGTemp
    2012-03-20 04:40 . 2012-03-20 04:40--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2012-03-20 03:54 . 2012-03-20 03:54--------d-----w-c:\program files\VS Revo Group
    2012-03-20 03:49 . 2010-02-19 03:451079272----a-w-c:\program files\revosetup.exe
    2012-03-19 03:02 . 2012-01-11 19:063072-c----w-c:\windows\system32\dllcache\iacenc.dll
    2012-03-19 03:02 . 2012-01-11 19:063072------w-c:\windows\system32\iacenc.dll
    2012-03-19 02:57 . 2012-03-19 02:57--------d-----w-c:\windows\system32\config\systemprofile\Application Data\IObit
    2012-03-19 02:49 . 2012-03-19 02:52--------d-----w-c:\program files\TCPOptimizer
    2012-03-18 20:50 . 2011-12-30 21:0321336----a-w-c:\windows\system32\RegistryDefragBootTime.exe
    2012-03-18 20:15 . 2012-03-18 20:15--------d-----w-c:\documents and settings\All Users\Application Data\IObit
    2012-03-18 20:14 . 2012-03-18 20:14--------d-----w-c:\documents and settings\donnakeller\Application Data\IObit
    2012-03-18 20:14 . 2012-03-18 20:14--------d-----w-c:\program files\IObit
    2012-03-18 20:03 . 2012-04-01 23:46--------d-----w-c:\documents and settings\donnakeller\Application Data\TeamViewer
    2012-03-12 04:32 . 2012-03-12 04:32414368----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-03-12 03:38 . 2012-03-12 03:38356556----a-w-c:\windows\system32\PerfStringBackup.TMP
    2012-03-05 03:59 . 2012-03-05 03:59--------d-----w-c:\documents and settings\donnakeller\Application Data\Malwarebytes
    2012-03-05 03:59 . 2012-03-05 03:59--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
    2012-03-05 03:22 . 2012-03-25 07:53--------d-----w-c:\documents and settings\Administrator
    2012-03-05 03:20 . 2012-03-13 03:53--------d-----w-c:\documents and settings\All Users\Application Data\AVG Secure Search
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-02-03 09:22 . 2004-08-04 12:001860096---ha-w-c:\windows\system32\win32k.sys
    2012-01-31 12:44 . 2009-10-03 07:48237072------w-c:\windows\system32\MpSigStub.exe
    2012-01-09 16:20 . 2007-12-24 14:00139784---ha-w-c:\windows\system32\drivers\rdpwd.sys
    2010-08-06 16:31 . 2009-11-15 20:28119808---ha-w-c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Nero PhotoShow Media Manager"="c:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-05-10 249856]
    "Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-12-29 620376]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "VTTimer"="VTTimer.exe" [2004-01-16 49152]
    "SoundMan"="SOUNDMAN.EXE" [2006-11-17 577536]
    "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
    .
    c:\documents and settings\donnakeller\Start Menu\Programs\Startup\
    Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-2-14 390432]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
    KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2011-05-04 17:54551296----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
    backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    2010-08-06 16:3130192---ha-w-c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2012-03-12 04:38136176----atw-c:\documents and settings\donnakeller\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 00:121695232------w-c:\program files\Messenger\msmsgs.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2008-06-22 04:3368856---ha-w-c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\LIMEWIRE\\LimeWire.exe"=
    "c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "c:\\WINDOWS\\system32\\dpvsetup.exe"=
    "c:\\WINDOWS\\system32\\GPhotos.scr"=
    "c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=
    "c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"=
    "c:\\WINDOWS\\system32\\msfeedssync.exe"=
    "c:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe"=
    "c:\\Program Files\\Google\\Update\\GoogleUpdate.exe"=
    "c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
    "c:\\Program Files\\Google\\Picasa3\\PicasaUpdater.exe"=
    "c:\\Program Files\\Google\\Picasa3\\Picasa3.exe"=
    "c:\\WINDOWS\\system32\\wscript.exe"=
    "c:\\Documents and Settings\\donnakeller\\Local Settings\\Application Data\\Google\\Update\\GoogleUpdate.exe"=
    "c:\\Documents and Settings\\donnakeller\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
    "c:\\WINDOWS\\system32\\mshta.exe"=
    "c:\\Program Files\\IObit\\Advanced SystemCare 5\\ASC.exe"=
    "c:\\Program Files\\IObit\\Advanced SystemCare 5\\AutoUpdate.exe"=
    "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpHost.exe"=
    "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
    "c:\\Program Files\\VS Revo Group\\Revo Uninstaller\\revouninstaller.exe"=
    .
    R1 mchInjDrv;madCodeHook DLL injection driver;c:\windows\system32\drivers\mchInjDrv.sys [1/28/2009 3:28 PM 2560]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 12:27 PM 12880]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 5:55 PM 67664]
    R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 7:38 PM 116608]
    R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [3/18/2012 4:14 PM 497496]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/2/2010 7:15 PM 135664]
    S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3/20/2012 12:40 AM 652360]
    S2 vToolbarUpdater10.2.0;vToolbarUpdater10.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe --> c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [?]
    S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [6/22/2008 12:34 AM 30192]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/2/2010 7:15 PM 135664]
    S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys --> c:\windows\system32\drivers\mbam.sys [?]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    dladresn
    nimcdfxk
    isamsmt
    mr2kserv
    CVPND
    E1000
    atalk
    screadspool
    rt73
    s716bus
    opcenum
    rpcnet
    FVXSCSI
    websensecommunicationagent
    mi-raysat_3dsmax9_32
    houdiniserver
    HPSLPSVC
    iksysflt
    61883
    bvrp_pci
    CrystalSysInfo
    iaimfp2
    w550mdm
    wampmysqld
    irsir
    MxlW2k
    TPPWRIF
    DfwWebAgent
    hwdatacard
    CAM1210
    bthport
    TryAndDecideService
    SunkFilt
    cis1284
    AmeLanPc
    PGPdisk
    prosync1
    sfrem01
    RR2Mjpeg
    winmtsrv
    w800bus
    uclauncherservice
    ipsraidn
    apphostsvc
    SNC
    TPM
    fsbwsys
    magictuneengine
    HFACSVC
    enethusb
    areschatserver
    asp.net
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 04:39]
    .
    2012-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 04:39]
    .
    2012-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-573735546-682003330-1004Core.job
    - c:\documents and settings\donnakeller\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-12 04:38]
    .
    2012-04-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-573735546-682003330-1004UA.job
    - c:\documents and settings\donnakeller\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-12 04:38]
    .
    2012-04-04 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
    .
    2012-04-04 c:\windows\Tasks\MpIdleTask.job
    - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
    .
    2012-04-04 c:\windows\Tasks\User_Feed_Synchronization-{1E05FE6E-10DE-4035-830E-8D851BC6B289}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://home.joobers.com/
    uSearchAssistant = hxxp://search.joobers.com/toolbar/SearchAssistant
    uCustomizeSearch = hxxp://search.joobers.com/toolbar/CustomizeSearch
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    Trusted Zone: cnet.com\download
    Trusted Zone: com.tw\asia.msi
    Trusted Zone: com.tw\global.msi
    Trusted Zone: com.tw\www.msi
    TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll
    FF - ProfilePath - c:\documents and settings\donnakeller\Application Data\Mozilla\Firefox\Profiles\cy3whktf.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3007394&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
    FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3007394&SearchSource=13
    FF - prefs.js: keyword.URL - hxxp://www.basicscan.com/?tmp=nemo_results_removelink&prt=BscscnPB&keywords=
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    FF - Ext: ShopAtHome.com Intelligent Shopping Toolbar: [emailprotected] - %profile%\extensions\[emailprotected]
    FF - Ext: vShare: [emailprotected] - %profile%\extensions\[emailprotected]
    FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
    FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    FF - Ext: PHPNukeEN Community Toolbar: {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - %profile%\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}
    FF - Ext: WhiteSmoke Bar Community Toolbar: {167d9323-f7cc-48f5-948a-6f012831a69f} - %profile%\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}
    FF - Ext: Java Quick Starter: [emailprotected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
    FF - Ext: AVG Security Toolbar: [emailprotected] - c:\documents and settings\All Users\Application Data\AVG Secure Search\10.0.0.7
    FF - user.js: yahoo.homepage.dontask - true
    .
    - - - - ORPHANS REMOVED - - - -
    .
    BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll
    Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
    HKLM-Run-NWEReboot - (no file)
    HKLM-Run-hpqSRMon - (no file)
    HKLM-Run-SelectRebates - c:\program files\SelectRebates\SelectRebates.exe
    HKLM-Run-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
    HKLM-Run-vProt - c:\program files\AVG Secure Search\vprot.exe
    MSConfigStartUp-AVG_TRAY - c:\program files\AVG\AVG2012\avgtray.exe
    AddRemove-648f1ec7 - c:\windows\system32\648f1ec7.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-04-03 22:45
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(704)
    c:\program files\SUPERAntiSpyware\SASWINLO.DLL
    c:\windows\system32\WININET.dll
    .
    - - - - - - - > 'explorer.exe'(2756)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\wdfmgr.exe
    c:\windows\system32\VTTimer.exe
    c:\windows\SOUNDMAN.EXE
    c:\windows\system32\wscntfy.exe
    c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
    c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
    c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
    c:\windows\system32\GPhotos.scr
    .
    **************************************************************************
    .
    Completion time: 2012-04-03 22:52:45 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-04-04 02:52
    .
    Pre-Run: 6,865,932,288 bytes free
    Post-Run: 6,980,030,464 bytes free
    .
    - - End Of File - - BE106CED2EAA598FC57971758C7ACBAB
    P2P - I see you have P2P software installed on your machine. (LimeWire)We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

    I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
    ***************************************************
    Update Your Java (JRE)

    Old versions of Java have vulnerabilities that malware can use to infect your system.

    First Verify your Java Version

    If there are any other version(s) installed then update now.

    Get the new version (if needed)

    If your version is out of date install the newest version of the Sun Java Runtime Environment.

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close ALL open web browsers before starting the installation.

    Remove any old versions

    1. Download JavaRa and unzip the file to your Desktop.
    2. Open JavaRA.exe and choose Remove Older Versions
    3. Once complete exit JavaRA.

    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
    ****************************************************
    SysProt Antirootkit

    Download
    SysProt Antirootkit from the link below (you will find it at the bottom
    of the page under attachments, or you can get it from one of the
    mirrors).

    http://sites.google.com/site/sysprotantirootkit/

    Unzip it into a folder on your desktop.

    • Double click Sysprot.exe to start the program.
    • Click on the Log tab.
    • In the Write to log box select the following items.
      • Process << Selected
      • Kernel Modules << Selected
      • SSDT << Selected
      • Kernel Hooks << Selected
      • IRP Hooks << NOT Selected
      • Ports << NOT Selected
      • Hidden Files << Selected
    • At the bottom of the page
      • Hidden Objects Only << Selected
    • Click on the Create Log button on the bottom right.
    • After a few seconds a new window should appear.
    • Select Scan Root Drive. Click on the Start button.
    • When it is complete a new window will appear to indicate that the scan is finished.
    • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
    SysProt AntiRootkit v1.0.1.0
    by swatkat

    ******************************************************************************************
    ******************************************************************************************

    No Hidden Processes found

    ******************************************************************************************
    ******************************************************************************************
    Kernel Modules:
    Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
    Service Name: ---
    Module Base: F563D000
    Module End: F5655000
    Hidden: Yes

    Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    Service Name: ---
    Module Base: F7C5D000
    Module End: F7C5F000
    Hidden: Yes

    ******************************************************************************************
    ******************************************************************************************
    No SSDT Hooks found

    ******************************************************************************************
    ******************************************************************************************
    No Kernel Hooks found

    ******************************************************************************************
    ******************************************************************************************
    Hidden files/folders:
    Object: C:\Documents and Settings\All Users\Application Data\Google\Google Toolbar\Update\
    Status: Hidden

    Object: C:\Program Files\AVG\AVG2012\
    Status: Hidden

    Object: C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\
    Status: Hidden

    Object: C:\Program Files\Google\Common\Google Updater\
    Status: Hidden

    Object: C:\Program Files\Google\Update\
    Status: Hidden

    Object: C:\Program Files\Java\jre6\bin\
    Status: Hidden

    Object: C:\Qoobox\BackEnv\AppData.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Cache.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Cookies.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Desktop.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Favorites.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\History.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Music.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\NetHood.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Personal.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Pictures.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Programs.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Recent.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\SendTo.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\SetPath.bat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\StartUp.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\SysPath.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Templates.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\VikPev00
    Status: Access denied

    How's your computer running now?

    I'd like to scan your machine with ESET OnlineScan

    •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
    •Click the button.
    •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
    •Check
    •Click the button.
    •Accept any security warnings from your browser.
    •Check
    •Push the Start button.
    •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    •When the scan completes, push
    •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    •Push the button.
    •Push
    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
    Super Dave,
    After the online scan, it gave me 2 options (optional) if i desired before clicking finished. 1st was delete eset from your computer.
    The 2nd was delete threat files. Based on the log, it appears they were deleted, I didnt choose either of them options as your instructions didnt mention to. As ar as the computers performance goes, its defitnely running a bit better. Last night the start menu>accessories reappeared. Previsouly it was mia ubder the start menu. Before getting assistance with you on this site, I was informed to run msinfo32. At that time nothing happened when i typed it in run. So that led me to services > help and support. I tried to manually start the service and got an error. Ive just tried both of those options again with the exact same result. Nothing comes up when i type in run>msinfo32 and i get an error when trying to start help and support in services. Im not sure if the help and support was damaged by the infection, but thought this info might help. Also I have pending windows updates Ive yet to install because I didnt want to change anything while weve been working at this. Is it safe to do so now? A pop up to upgrade to internet explorer 8 keeps coming up, but according to i.e, im already running i.e 8? The contexual toolbar which was in add/remove programs previously alerted me with threat detections (from avg) everytime i attempted to uninstall it from there. That tool bar is now gone from the add/remove programs which according to a google search, it was not a good file for my computer! Other than that, anything else I can take a look at to see if computer is indeed running better? Thanks A MILLION!


    C:\Documents and Settings\donnakeller\Desktop\music\boom boom boom (rare track).snda variant of WMA/TrojanDownloader.GetCodec.gen trojancleaned - quarantined
    C:\Documents and Settings\donnakeller\Desktop\music\boom boom came out in 2009 greatest hit 2009.wmaprobably a variant of Win32/Agent.CFDFCZI trojancleaned by deleting - quarantined
    C:\Documents and Settings\donnakeller\Desktop\music\prom queen lil wanye 2009.mp3a variant of WMA/TrojanDownloader.GetCodec.gen trojancleaned - quarantined
    C:\Program Files\vShare\imedix-silent.exeWin32/Toolbar.Zugo applicationdeleted - quarantined
    C:\System Volume Information\_restore{B5B2433D-7C5E-4FF8-8417-FE18E7328867}\RP1\A0000006.exeWin32/InstallBrain applicationcleaned by deleting - quarantined
    C:\System Volume Information\_restore{B5B2433D-7C5E-4FF8-8417-FE18E7328867}\RP19\A0006180.exeWin32/Toolbar.Zugo applicationdeleted - quarantined
    C:\TDSSKiller_Quarantine\02.04.2012_20.31.37\mbr0000\tdlfs0000\tsk0007.dtaa variant of Win32/Olmasco.O trojancleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\02.04.2012_20.31.37\mbr0000\tdlfs0000\tsk0010.dtaWin64/Olmasco.R trojancleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\02.04.2012_20.31.37\mbr0000\tdlfs0000\tsk0011.dtaa variant of Win32/Olmasco.Q trojancleaned by deleting - quarantined
    Update: Shortly after posting my previous reply msinfo32 did come up, but it took some time to do so. Help and support also came up, but under services is still saying its stopped. When i try to start it, I still get error message.
    ThanksQuote
    Also I have pending windows updates Ive yet to install because I didnt want to change anything while weve been working at this. Is it safe to do so now? A pop up to upgrade to internet explorer 8 keeps coming up, but according to i.e, im already running i.e 8? The contexual toolbar which was in add/remove programs previously alerted me with threat detections (from avg) everytime i attempted to uninstall it from there. That tool bar is now gone from the add/remove programs which according to a google search, it was not a good file for my computer! Other than that, anything else I can take a look at to see if computer is indeed running better?
    Yes, go ahead and get your updates. After that is done we can do some cleanup.
    As for msinfo32, it is just information about your computer. Not needed.

    To uninstall ComboFix

    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall


    (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
    *************************************************
    Update Your Java (JRE)

    Old versions of Java have vulnerabilities that malware can use to infect your system.

    First Verify your Java Version

    If there are any other version(s) installed then update now.

    Get the new version (if needed)

    If your version is out of date install the newest version of the Sun Java Runtime Environment.

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close ALL open web browsers before starting the installation.

    Remove any old versions

    1. Download JavaRa and unzip the file to your Desktop.
    2. Open JavaRA.exe and choose Remove Older Versions
    3. Once complete exit JavaRA.

    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
    *******************************************************
    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
    ****************************************************
    Looking over your log it seems you don't have any evidence of a third party firewall.

    Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

    Remember only install ONE firewall

    1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
    2) Online Armor
    3) Agnitum Outpost
    4) PC Tools Firewall Plus

    If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
    *****************************************************
    Use the Secunia Software Inspector to check for out of date software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online SCAMS, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you INTERACT with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!Super Dave,
    I cant THANK you ENOUGH! Computer appears clean and is running like it should be!!!!!! I followed all steps My final question, and then you can lock this thread. Am I to delete the
    sysprot folder, TDSKILLER, ANTI-MALLWARE BYTES, SPYWARE SWEEPER along with all the setup files for the other programs that I wont be keeping? Are all the logs now safe to delete?
    Thanks!Quote
    Am I to delete the
    sysprot folder, TDSKILLER, ANTI-MALLWARE BYTES, SPYWARE SWEEPER along with all the setup files for the other programs that I wont be keeping? Are all the logs now safe to delete?
    If I were you the only two I would keep is SAS and MBAM. Update them and run them on a regular basis. Uninstall/delete all the rest.
    You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
    131.

    Solve : Security Essentials detected the Win32/sirefef.AC and .AH?

    Answer»

    Please run SysProt-AntiRootkit and post the log.

    I'd like to scan your machine with ESET OnlineScan

    •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
    •Click the button.
    •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

    • Click on to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
    •Check
    •Click the button.
    •Accept any SECURITY warnings from your browser.
    •Check
    •Push the Start button.
    •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    •When the scan completes, push
    •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    •Push the button.
    •Push
    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
    Sysrot crashed during the scan and threw up an error involving these files

    C:\Users\Bradley Adam\AppData\Local\Temp\WER7655.tmp.version.txt
    C:\Users\Bradley Adam\AppData\Local\Temp\WER8C84.tmp.appcompat.txt
    C:\Users\Bradley Adam\AppData\Local\Temp\WER8C85.tmp.mdmp

    It did produce a log file

    SysProt AntiRootkit v1.0.1.0
    by swatkat

    ******************************************************************************************
    ******************************************************************************************

    Process:
    Name: C:\Windows\System32\PING.EXE
    PID: 5220
    Hidden: Yes
    Window Visible: No

    Name: C:\Windows\System32\PING.EXE
    PID: 1692
    Hidden: Yes
    Window Visible: No

    Name: C:\Windows\System32\PING.EXE
    PID: 708
    Hidden: Yes
    Window Visible: No

    ******************************************************************************************
    ******************************************************************************************
    Kernel Modules:
    Module Name: \SystemRoot\System32\Drivers\dump_iaStor.sys
    Service Name: ---
    Module Base: 8F008000
    Module End: 8F0D6000
    Hidden: Yes

    ******************************************************************************************
    ******************************************************************************************
    No SSDT Hooks found

    ******************************************************************************************
    ******************************************************************************************
    No Kernel Hooks found

    ******************************************************************************************
    ******************************************************************************************ok ran eset online and the log is below

    C:\Documents and Settings\Bradley Adam\Music\iTunes\iTunes Media\Mobile Applications\Fango 53.ipaJS/Exploit.CVE-2011-1250.A trojandeleted - quarantined
    C:\Windows\System32\drivers\cdrom.sysWin32/Sirefef.DA trojanunable to clean
    Operating memoryWin32/Sirefef.DN trojan

    Regards
    Brad
    * Go to Start > Run and type mrt.exe then press Enter on the keyboard).
    * (Vista and Windows 7 users go to Start and type mrt.exe in the search box then press Enter on the keyboard.
    * Click Next.
    * Choose Full Scan and click Next.
    * Once the scan is FINISHED click View detailed results of the scan.

    Look through the list and let me know if anything was found infected.ran mrt scan and it reported no malicous software detected.

    Google opens a new window now if I open one of my favourite SITES up

    Regards
    Brad Quote
    Google opens a new window now if I open one of my favourite sites up

    Does that mean the it's working properly now?Sorry, yes all is good, Thank you for your help. That's good news. Now we can do some cleanup.

    To set a new Restore Point.

    Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an ADMINISTRATOR password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
    Click the Start button , click Control Panel, click System and Maintenance, and then click System.
    In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
    To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
    This will give you a new, clean Restore Point.
    **********************************************************
    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
    ********************************************************
    Use the Secunia Software Inspector to check for out of date software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    132.

    Solve : Please help - www.searchnu.com/406 virus has infected my computer?

    Answer» THANK you so very MUCH. You GUYS are TRULY AWESOME.
    133.

    Solve : virus resource hog-Need help with removing it?

    Answer»

    Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

    Software recommendations

    Firewall

    • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
    • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The OPTIONAL security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
    • PC Tools Firewall Plus: free and excellent firewall.
    AntiSpyware
    • SpywareBlaster
      SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
    • Spybot - Search & Destroy.
      Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
    NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

    Resident Protection help
    A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive PROTECTORS such as SpywareBlaster can be run with any of them.

    Rogue programs help
    There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Securing your computer
    • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the LATEST critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
    • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other BAD sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
    Please consider using an alternate browser
    Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

    If you are interested:
    See this page for more info about malware and prevention. Thank you for helping me, my computer is running faster than it was before. I will also look in to those other options you sent me. You're welcome.
    134.

    Solve : Windows explorer error on boot?

    Answer»

    Usually on the first boot of the day, I get the "Windows Explorer has encountered an error and needs to close" statement. I researched previous entries on the topic, and found an old one from 2008, which pointed to a malware problem.

    Is this always the case ? I have been using Avira forever, and periodically run Ad-Aware and Spybot, and lately Advanced System CARE. (I also used CC cleaner last year). I will install a firewall now, because I noticed that Windows firewall is not perfect.

    I'm using WinXP 2002 SP3.

    I have the TECHNICAL error data for the Explorer problem, if anyone needs that to give me advice.
    Thanks in advance (my first POST)Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.Thanks. I ran the Malware removal recommendations and that cured the problem. I will keep your Combofix suggestion for further use.

    Thank you very muchActually, don't use ComboFix in the future without supervision of an expert. Come back here for any further problems. If used unsupervised, ComboFix can cause damage to your operating system, and can create other severe issues. Thanks.

    To uninstall ComboFix

    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall


    (Note: Make sure there's a space between the WORD ComboFix and the forward-slash.)

    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and RESETS System Restore.
    Thanks.........I'm glad I read that before installing ComboFix !

    This thread can be closed now.
    135.

    Solve : HJT Report?

    Answer»

    I've just run HJT.
    Can you please check the log for unwanted entries and advise as to which ones I should remove.
    Thanks

    [recovering disk space - old attachment deleted by admin]Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    - R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

    - O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103470 -\"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; GTB6.4; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; AskTB5.6)\" -\"htt p://www.miniclip.com/games/tropi-golf/en/\"

    - O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    Go to add remove programs and uninstall anything with Norton, Symantec or Live Update (Symantec Corporation) in the name.

    Download the Norton Removal Tool (SymNRT) to your desktop.

    Once downloaded please close ALL open browsers, also save any work because this may require a restart.

    * Go to your desktop and double click on the 'Norton_Removal_Tool' and then click Setup.
    * Once open Click Next
    * Accept the license agreement and click Next
    * Type in the letters/numbers that you see into the text box then click Next.
    * Then click Next and the tool will start running.
    * Once finished restart the PC.
    * Delete the 'Norton_Removal_Tool' from your desktop.

    ----------

    Download Disable/Remove Windows MESSENGER to the desktop to remove Windows Messenger.

    Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

    Exit out of MessengerDisable then delete the two files that were put on the desktop.

    ----------


    - How is the computer running now and why did you start this topic?
    - Did you have a malware issue?
    Hi Evil,

    Thanks for your help.

    I'm running a small network at home and I've receently had problems on one of the computers.
    Super Dave has been helping me out which has been brilliant and we've almost resolved everything.
    The log I posted here was for another machine which has also been 'playing up'
    I was unsure whether to start a NEW THREAD (seeing as though it is a seperate computer) and I thought this would be best so as not to confuse the two issues.

    It seems to be better but it still takes an age to boot up and can be very slow when using.
    Is there anything else you can suggest to get it moving faster.

    Many thanks

    DavidHave you done a defrag lately?Yes, still not that great.
    Any other suggestions?
    ThanksIf you already have ComboFix be sure to delete it and download a new copy.

    Download ComboFix© by sUBs from one of the below links. Be sure to save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your ANTIVIRUS and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFix

    136.

    Solve : Is this a spyware/malware/virus problem? Problem shutting down?

    Answer»

    I'm not seeing anything to indicate a malware issue.

    When was the last time you updated Windows?I have the Automatic Updates turned on and I just assumed that the computer was doing everything itself.

    Also, in terms of the original problem, which was that the computer was not shutting down properly, I recently noted that ONE of the programs I use to listen to MUSIC, a Cowan program called jetAudio, was acting weirdly. When I turned on the music, usually the program itself would appear minimized at the bottom of the page so I could shut off the music when I wanted. But recently this stopped happening--the program never minimized but the music kept playing!

    So I thought that maybe the reason I couldn't shut down was because this program maybe kept on and on, even though it didn't show up in my "task manager" which made me feel even more suspicious toward it. Also, I kept LOOKING around and somewhere in the microsoft site I THINK it was I saw a note that SAID to disable screen savers.
    Anyway, I both deleted this jet audio program (wait till my son finds out!) and turned off the screen saver (a Microsoft one), and now I don't have trouble shutting down.

    I do want to thank you for looking at these logs. If you say there is no malware, then my heart is totally at ease!
    Thanks and have a great weekend.

    Dr. D.You are still using XP SP2 when you should be at SP3 now. SP3 was released a few years ago so not all of the updates are there. You should get SP3.OK I will try to do that. Anything else I need to do?

    Dr. D.Not that I can see.Thanks so much for everything.

    Dr.D.

    137.

    Solve : Keyboard wont work after malware?

    Answer»

    I am running Win XP. I opened my computer this afternoon and the screen was full of malware saying my computer was INFECTED and buy thier removal tool. I could not open any programs or even use the keyboard. I restarted in safe mode and did a system restore for 2 days AGO and everything looks OK except the keyboard wont work. The lights come on but none of the keys will work. Some of the hot buttons work. The board will work in CMOS but not when windows loads. I have uninstalled through the device manager and keyboard in control panel and restarted. There is a screen that says that computer has detected new hardware and so I want to install, I click yes reboot and it is still x'ed out in device manager and won't work. I did troubleshoot and get this.
    "Windows cannot load the device driver for this hardware because a previous instance of the device driver is still in memory. ( Code 38)"
    Can anyone please help, I have done the uninstall and reboot ten times and same result. Thanks for any and all advice.
    Here is a copy of HighJackThis:
    Logfile of HijackThis v1.99.1
    Scan saved at 4:59:20 AM, on 4/9/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\vssvc.exe
    C:\WINDOWS\system32\dllhost.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\PRISMSVR.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\INTEL\Modem Event Monitor\IntelMEM.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
    C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Dell Wireless\PRISMCFG.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\osk.exe
    C:\WINDOWS\system32\MSSWCHX.EXE
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~2.DLL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~2.DLL
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
    O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\Speeditup Free\SpeedItUp.exe -MINI
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - UNKNOWN file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O11 - Options group: [INTERNATIONAL] International
    O15 - Trusted Zone: *.intuit.com
    O15 - Trusted Zone: http://*.turbotax.com
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://s.nx.com/activex/public_new/nxpm.cab
    O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
    O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_6.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
    O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
    O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless MEDIA Upload) - http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
    O16 - DPF: {BA2D9665-D672-446F-98F4-E3E41FA12A01} (PCAObj Class) - http://www.mypccenter.com/PCA.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://chill.comcast.net/Gameshell/GameHost/1.0/OberonGameHost.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - file:///C:/Documents%20and%20Settings/John%20&%20Leanna%20Harper.4HARPERS/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/popcaploader_v10.cab
    O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (MSN Games – Backgammon) - http://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: McAfee Application Installer Cleanup (0014141270250149) (0014141270250149mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\001414~1.EXE (file missing)
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe" /svc (file missing)
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe



    Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.

    138.

    Solve : Need help with possible malware infection?

    Answer»

    As of this morning, my computer has shown some odd symptoms while in normal mode:

    -Cannot connect to the internet or open internet explorer
    -Cannot open any icons or programs whatsoever
    -The bottom taskbar, system tray, and start menu button have all disappeared

    In order for me to get internet access, I had to reboot in Safe Mode. I have followed all the instructions on what to do, and here is what has happened so far (while in Safe Mode):

    -I cannot install Java. I was able to download apparantly 2 different versions of it - one from Java's website, and one from the MajorGeeks link that was provided. When I try to install the program from Java's website, I get the following error message: "Error - Java(TM) Installer Installer cannot proceed with the current Internet Connection settings."
    I get a different error message when I try to install Java from the MajorGeeks link. It says: "WINDOWS Installer The system administrator has set policies to prevent this installation."

    -In Safe Mode, while running SAS and MalwareBytes I could not connect to their databases to search for the latest updates. I could however download and actually run the programs successfully.

    -I have also noticed that while in Safe Mode I cannot enable any of the SHIELDS in my anti-virus program (Avast), but the scanning function worked fine.

    I think this may or may nor be a malware infection, but I am also worried that it might have something to do with the microsoft updates my computer installed yesterday. Hopefully you guys can help. Here are all my logs:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 06/14/2012 at 01:01 PM

    Application Version : 5.1.1002

    Core Rules Database Version : 8734
    Trace Rules Database Version: 6546

    Scan type : Complete Scan
    Total Scan Time : 01:15:40

    Operating System Information
    Windows XP Home Edition 32-bit, Service Pack 3 (Build 5.01.2600)
    Administrator

    Memory items scanned : 325
    Memory threats detected : 0
    Registry items scanned : 34677
    Registry threats detected : 52
    File items scanned : 90425
    File threats detected : 4

    Adware.CouponBar
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Implemented Categories
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\InprocServer32
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\InprocServer32#ThreadingModel
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\ProgID
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Programmable
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\TypeLib
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\VersionIndependentProgID
    HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
    HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\InprocServer32
    HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\InprocServer32#ThreadingModel
    HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\ProgID
    HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\Programmable
    HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\TypeLib
    HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\VersionIndependentProgID
    HKLM\Software\Classes\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}
    HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}
    HKCR\TTB000001.TTB000001.1
    HKCR\TTB000001.TTB000001.1\CLSID
    HKCR\TTB000001.TTB000001
    HKCR\TTB000001.TTB000001\CLSID
    HKCR\TTB000001.TTB000001\CurVer
    HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}
    HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0
    HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0\0
    HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0\0\win32
    HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0\FLAGS
    HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0\HELPDIR
    C:\WINDOWS\COUPONSBAR.DLL
    HKLM\Software\Classes\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
    HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
    HKCR\ToolBand.TTB000000.1
    HKCR\ToolBand.TTB000000.1\CLSID
    HKCR\ToolBand.TTB000000
    HKCR\ToolBand.TTB000000\CLSID
    HKCR\ToolBand.TTB000000\CurVer
    C:\WINDOWS\COUPON~1.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
    HKU\S-1-5-21-3432606718-3590316964-593038263-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5BED3930-2E9E-76D8-BACC-80DF2188D455}
    HKU\S-1-5-21-3432606718-3590316964-593038263-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
    HKLM\Software\Microsoft\Internet Explorer\Toolbar#{5BED3930-2E9E-76D8-BACC-80DF2188D455}
    HKU\S-1-5-21-3432606718-3590316964-593038263-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{5BED3930-2E9E-76D8-BACC-80DF2188D455}
    C:\WINDOWS\SYSTEM32\CPNPRT2.CID
    HKCR\Interface\{0D700D4A-F8C1-8888-C5BA-CB09D464A4E8}
    HKCR\Interface\{0D700D4A-F8C1-8888-C5BA-CB09D464A4E8}\ProxyStubClsid
    HKCR\Interface\{0D700D4A-F8C1-8888-C5BA-CB09D464A4E8}\ProxyStubClsid32
    HKCR\Interface\{0D700D4A-F8C1-8888-C5BA-CB09D464A4E8}\TypeLib
    HKCR\Interface\{0D700D4A-F8C1-8888-C5BA-CB09D464A4E8}\TypeLib#Version
    HKCR\Interface\{6D69B86A-B94C-59EE-BCB8-5F5DF46B2BE8}
    HKCR\Interface\{6D69B86A-B94C-59EE-BCB8-5F5DF46B2BE8}\ProxyStubClsid
    HKCR\Interface\{6D69B86A-B94C-59EE-BCB8-5F5DF46B2BE8}\ProxyStubClsid32
    HKCR\Interface\{6D69B86A-B94C-59EE-BCB8-5F5DF46B2BE8}\TypeLib
    HKCR\Interface\{6D69B86A-B94C-59EE-BCB8-5F5DF46B2BE8}\TypeLib#Version

    Adware.Tracking Cookie
    C:\Documents and Settings\Ralph\Cookies\6F9MZWI4.txt [ /revsci.net ]


    Malwarebytes Anti-Malware 1.61.0.1400
    www.malwarebytes.org

    Database version: v2012.06.11.05

    Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking)
    Internet Explorer 8.0.6001.18702
    Ralph :: YODA [administrator]

    6/14/2012 13:25:18
    mbam-log-2012-06-14 (13-25-18).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 218277
    Time elapsed: 4 minute(s), 37 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)



    .
    DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
    Internet Explorer: 8.0.6001.18702
    Run by Ralph at 14:27:23 on 2012-06-14
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1156 [GMT -4:00]
    .
    AV: COMODO Antivirus *Enabled/Updated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
    AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: COMODO Firewall *Enabled*
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    C:\Program Files\Windows Defender\MsMpEng.exe
    svchost.exe
    svchost.exe
    C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\ctfmon.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Settings,ProxyOverride =
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: File Print FedEx Kinko's: {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: File Print FedEx Kinko's: {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    EB: MoneySide: {9404901d-06da-4b23-a0ee-3ea4f64ec9b3} - c:\program files\microsoft money\system\mnyviewer.dll
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
    uRun: [Akamai NetSession Interface] "c:\documents and settings\ralph\local settings\application data\akamai\netsession_win.exe"
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [BCMSMMSG] BCMSMMSG.exe
    mRun: [DVDSentry] c:\windows\system32\DSentry.exe
    mRun: [MoneyStartUp10.0] "c:\program files\microsoft money\system\Activation.exe"
    mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    mRun: [AdaptecDirectCD] "c:\program files\roxio\easy cd creator 5\directcd\DirectCD.exe"
    mRun: [MPTBox] c:\progra~1\canon\multip~1\MPTBox.exe
    mRun: [nwiz] nwiz.exe /install
    mRun: [DIGStream] c:\program files\digstream\digstream.exe
    mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
    mRun: [avast] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    dRunOnce: [AutoLaunch] c:\program files\lavasoft\ad-aware\AutoLaunch.exe monthly
    StartupFolder: c:\docume~1\ralph\startm~1\programs\startup\kuma_t~1.lnk - c:\program files\history channel games\kgsystray\Kuma_tray.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pictur~2.lnk - c:\program files\sony corporation\picture package\picture package menu\SonyTray.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony corporation\picture package\picture package applications\Residence.exe
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
    IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll
    DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://activation.rr.com/install/download/tgctlcm.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
    DPF: {4B48D5DF-9021-45F7-A240-60304302A215} - hxxp://download.microsoft.com/download/b/d/b/bdb4e4ee-63b2-45ff-9d84-33205bf43143/WebCleaner.cab
    DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
    DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229540297140
    DPF: {69432678-2906-2705-1128-068943397621}
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1263759585985
    DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} - hxxp://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{17137E2C-E8BA-4E93-A8D8-F81A0696AAA5} : DhcpNameServer = 192.168.1.1
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
    AppInit_DLLs:
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-9-30 64160]
    R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2010-9-10 15592]
    R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-9-10 25240]
    R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
    R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-10-9 442200]
    S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-1-27 320856]
    S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-9-10 239240]
    S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
    S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
    S2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2002-8-29 14336]
    S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-1-27 20568]
    S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-1-27 44768]
    S2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2010-9-10 1901056]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-10-7 136176]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1036104]
    S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\viewpoint\common\viewpointservice.exe" --> c:\program files\viewpoint\common\ViewpointService.exe [?]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-10-7 136176]
    S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
    S3 MTK;Media Technology Kernel Driver;c:\windows\system32\drivers\mtk.sys --> c:\windows\system32\drivers\mtk.sys [?]
    S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-12-4 7408]
    .
    =============== Created Last 30 ================
    .
    2012-06-14 15:29:20--------d-----w-c:\documents and settings\all users\application data\SUPERSetup
    2012-06-14 11:30:01--------d-----w-c:\documents and settings\ralph\local settings\application data\PCHealth
    .
    ==================== Find3M ====================
    .
    2012-05-15 13:20:331863168----a-w-c:\windows\system32\win32k.sys
    2012-05-02 13:46:36139656----a-w-c:\windows\system32\drivers\rdpwd.sys
    2012-04-04 19:56:4022344----a-w-c:\windows\system32\drivers\mbam.sys
    2004-07-25 01:46:460--sh--r-c:\program files\q330994.exe
    .
    ============= FINISH: 14:28:41.28 ===============




    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 4/18/2003 8:39:51 PM
    System Uptime: 6/14/2012 2:10:12 PM (0 hours ago)
    .
    Motherboard: Dell Computer Corp. | | 0J0592
    Processor: Intel(R) Pentium(R) 4 CPU 2.53GHz | Microprocessor | 2524/533mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 56 GiB total, 15.886 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP2113: 5/17/2012 7:43:02 AM - Software Distribution Service 3.0
    RP2114: 5/18/2012 6:53:24 AM - Software Distribution Service 3.0
    RP2115: 5/19/2012 7:21:10 AM - Software Distribution Service 3.0
    RP2116: 5/20/2012 7:03:43 AM - Software Distribution Service 3.0
    RP2117: 5/21/2012 8:27:28 AM - Software Distribution Service 3.0
    RP2118: 5/22/2012 6:16:31 AM - Software Distribution Service 3.0
    RP2119: 5/23/2012 6:27:54 AM - Software Distribution Service 3.0
    RP2120: 5/23/2012 6:43:22 AM - Software Distribution Service 3.0
    RP2121: 5/24/2012 7:29:18 AM - Software Distribution Service 3.0
    RP2122: 5/25/2012 6:41:40 AM - Software Distribution Service 3.0
    RP2123: 5/26/2012 6:25:19 AM - Software Distribution Service 3.0
    RP2124: 5/27/2012 6:38:37 AM - Software Distribution Service 3.0
    RP2125: 5/28/2012 7:04:40 AM - Software Distribution Service 3.0
    RP2126: 5/29/2012 6:54:09 AM - Software Distribution Service 3.0
    RP2127: 5/30/2012 6:37:56 AM - Software Distribution Service 3.0
    RP2128: 5/31/2012 6:47:42 AM - Software Distribution Service 3.0
    RP2129: 6/1/2012 6:35:47 AM - Software Distribution Service 3.0
    RP2130: 6/2/2012 8:27:50 AM - Software Distribution Service 3.0
    RP2131: 6/3/2012 6:57:35 AM - Software Distribution Service 3.0
    RP2132: 6/4/2012 6:09:03 AM - Software Distribution Service 3.0
    RP2133: 6/5/2012 7:40:16 AM - Software Distribution Service 3.0
    RP2134: 6/6/2012 6:24:21 AM - Software Distribution Service 3.0
    RP2135: 6/7/2012 8:45:22 AM - Software Distribution Service 3.0
    RP2136: 6/8/2012 11:21:32 AM - Software Distribution Service 3.0
    RP2137: 6/9/2012 9:15:23 AM - Software Distribution Service 3.0
    RP2138: 6/10/2012 7:06:15 AM - Software Distribution Service 3.0
    RP2139: 6/11/2012 6:19:26 AM - Software Distribution Service 3.0
    RP2140: 6/12/2012 7:41:53 AM - Software Distribution Service 3.0
    RP2141: 6/13/2012 8:02:38 AM - System Checkpoint
    RP2142: 6/13/2012 7:47:49 PM - Software Distribution Service 3.0
    RP2143: 6/14/2012 6:05:22 AM - Software Distribution Service 3.0
    RP2144: 6/14/2012 6:19:32 AM - Software Distribution Service 3.0
    .
    ==== Installed Programs ======================
    .
    .
    AAC Decoder
    Acrobat.com
    Ad-Aware
    Adobe AIR
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 11 ActiveX
    Adobe Reader 9.4.1
    Adobe® Photoshop® Album Starter Edition 3.0
    Adobe® Photoshop® Album Starter Edition 3.0.1
    Akamai NetSession Interface
    Any Video Converter 3.0.7
    Apple Software Update
    AutoUpdate
    avast! Free Antivirus
    Banctec Service Agreement
    BCM V.92 56K Modem
    BlackBerry Desktop Software 6.0
    Canon Camera Access Library
    Canon Camera Support Core Library
    Canon G.726 WMP-Decoder
    Canon MultiPASS Suite 4.20a
    Canon Utilities Easy-PhotoPrint
    CCleaner
    CDex extraction audio
    COMODO Internet Security
    Coupon Printer for Windows
    CouponBar
    Critical Update for Windows Media Player 11 (KB959772)
    Cucusoft MPEG to DVD Author 1.09
    DAO
    dBpoweramp Music Converter
    Dell Digital Jukebox Driver
    Dell Picture Studio - Dell Image Expert
    Dell Solution Center
    Dell Support
    Dell Support Center
    DellSupport
    DivX Codec
    DivX Converter
    DivX Player
    DivX Plus DirectShow Filters
    DivX Version Checker
    DivX Web Player
    DVD Audio Extractor 4.5.4
    DVD Flick 1.3.0.7
    DVDSentry
    Earthlink Installer - uninstall 'Earthlink 5.0' entry first if present
    Easy CD Creator 5 Basic
    ELNKInst
    ESPNMotion
    eTrust EZ Antivirus
    Exact Audio Copy 0.99pb4
    File, Print FedEx Kinko's
    FLAC 1.2.1b (remove only)
    Google Update Helper
    H.264 Decoder
    Help and Support Customization
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB2570791)
    Hotfix for Windows XP (KB2633952)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    ImageMixer VCD2
    ImagXpress
    ImgBurn
    Intel(R) PRO Ethernet Adapter and Software
    Intel(R) PROSet II
    InterActual Player
    Japanese Fonts Support For Adobe Reader 9
    Java Auto Updater
    Java(TM) 6 Update 29
    LightScribe System Software
    LimeWire 5.5.8
    Macromedia Shockwave Player
    Malwarebytes' Anti-Malware
    MetaFrame Presentation Server Web Client for Win32
    Microsoft .NET Framework (English)
    Microsoft .NET Framework (English) v1.0.3705
    Microsoft .NET Framework 1.0 Hotfix (KB928367)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2656353)
    Microsoft .NET Framework 1.1 Security Update (KB2656370)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Data Access Components KB870669
    Microsoft Interactive Training
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Money 2002
    Microsoft Money 2002 System Pack
    Microsoft National Language Support Downlevel APIs
    Microsoft Office XP Media Content
    Microsoft Office XP Professional
    Microsoft Publisher 2002
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    MKV Splitter
    Modem Helper
    MotoHelper MergeModules
    Move Media Player
    MSN Music Assistant
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6 Service Pack 2 (KB973686)
    neroxml
    NVIDIA Display Driver
    NVIDIA Windows 2000/XP Display Drivers
    Paint Shop Pro 7
    PCFriendly
    Picasa 3
    Picture Package
    PL-2303 USB-to-Serial
    PowerDVD
    QuickTime
    RealPlayer Basic
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
    Security Update for Microsoft Windows (KB2564958)
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB929969)
    Security Update for Windows Internet Explorer 7 (KB931768)
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB2416400)
    Security Update for Windows Internet Explorer 8 (KB2482017)
    Security Update for Windows Internet Explorer 8 (KB2497640)
    Security Update for Windows Internet Explorer 8 (KB2510531)
    Security Update for Windows Internet Explorer 8 (KB2530548)
    Security Update for Windows Internet Explorer 8 (KB2544521)
    Security Update for Windows Internet Explorer 8 (KB2559049)
    Security Update for Windows Internet Explorer 8 (KB2586448)
    Security Update for Windows Internet Explorer 8 (KB2618444)
    Security Update for Windows Internet Explorer 8 (KB2647516)
    Security Update for Windows Internet Explorer 8 (KB2675157)
    Security Update for Windows Internet Explorer 8 (KB2699988)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2160329)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2296199)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2412687)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2436673)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476490)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2479628)
    Security Update for Windows XP (KB2479943)
    Security Update for Windows XP (KB2481109)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485376)
    Security Update for Windows XP (KB2485663)
    Security Update for Windows XP (KB2503658)
    Security Update for Windows XP (KB2503665)
    Security Update for Windows XP (KB2506212)
    Security Update for Windows XP (KB2506223)
    Security Update for Windows XP (KB2507618)
    Security Update for Windows XP (KB2507938)
    Security Update for Windows XP (KB2508272)
    Security Update for Windows XP (KB2508429)
    Security Update for Windows XP (KB2509553)
    Security Update for Windows XP (KB2511455)
    Security Update for Windows XP (KB2524375)
    Security Update for Windows XP (KB2535512)
    Security Update for Windows XP (KB2536276-v2)
    Security Update for Windows XP (KB2536276)
    Security Update for Windows XP (KB2544893-v2)
    Security Update for Windows XP (KB2544893)
    Security Update for Windows XP (KB2555917)
    Security Update for Windows XP (KB2562937)
    Security Update for Windows XP (KB2566454)
    Security Update for Windows XP (KB2567053)
    Security Update for Windows XP (KB2567680)
    Security Update for Windows XP (KB2570222)
    Security Update for Windows XP (KB2570947)
    Security Update for Windows XP (KB2584146)
    Security Update for Windows XP (KB2585542)
    Security Update for Windows XP (KB2592799)
    Security Update for Windows XP (KB2598479)
    Security Update for Windows XP (KB2603381)
    Security Update for Windows XP (KB2618451)
    Security Update for Windows XP (KB2619339)
    Security Update for Windows XP (KB2620712)
    Security Update for Windows XP (KB2621440)
    Security Update for Windows XP (KB2624667)
    Security Update for Windows XP (KB2631813)
    Security Update for Windows XP (KB2633171)
    Security Update for Windows XP (KB2639417)
    Security Update for Windows XP (KB2641653)
    Security Update for Windows XP (KB2646524)
    Security Update for Windows XP (KB2647518)
    Security Update for Windows XP (KB2653956)
    Security Update for Windows XP (KB2659262)
    Security Update for Windows XP (KB2660465)
    Security Update for Windows XP (KB2685939)
    Security Update for Windows XP (KB2686509)
    Security Update for Windows XP (KB2695962)
    Security Update for Windows XP (KB2709162)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371-v2)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982665)
    Security Update for Windows XP (KB982802)
    Shockwave
    Sony USB Driver
    SpywareBlaster 4.4
    Steam
    SUPERAntiSpyware
    Theorica Divx ;-) Codecs (remove only)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB2598845)
    Update for Windows Internet Explorer 8 (KB971930)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB980182)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB2541763)
    Update for Windows XP (KB2607712)
    Update for Windows XP (KB2616676)
    Update for Windows XP (KB2641690)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971029)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    VC80CRTRedist - 8.0.50727.762
    VCRedistSetup
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    WebFldrs XP
    Windows Defender
    Windows Defender Signatures
    Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Imaging Component
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Resource Kit Tools - SubInAcl.exe
    Windows XP Service Pack 3
    WinRAR archiver
    Wolfenstein 3D
    Xvid 1.2.2 final uninstall
    .
    ==== Event Viewer Messages From Past Week ========
    .
    6/9/2012 9:15:33 AM, error: WinDefend [2003] - Windows Defender has encountered an error trying to update the engine. New Engine Version: Previous Engine Version: 1.1.8304.0 Update Source: User User: NT AUTHORITY\SYSTEM Error Code: 0x80070005 Error description: Access is denied.
    6/9/2012 9:15:33 AM, error: WinDefend [2001] - Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.125.886.0 Update Source: User Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8304.0 Error code: 0x80070005 Error description: Access is denied.
    6/8/2012 11:21:44 AM, error: WinDefend [2003] - Windows Defender has encountered an error trying to update the engine. New Engine Version: Previous Engine Version: 1.1.8304.0 Update Source: User User: NT AUTHORITY\SYSTEM Error Code: 0x80070005 Error description: Access is denied.
    6/8/2012 11:21:44 AM, error: WinDefend [2001] - Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.125.886.0 Update Source: User Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8304.0 Error code: 0x80070005 Error description: Access is denied.
    6/7/2012 8:45:38 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender - KB915597 (Definition 1.127.1364.0).
    6/7/2012 8:45:29 AM, error: WinDefend [2003] - Windows Defender has encountered an error trying to update the engine. New Engine Version: Previous Engine Version: 1.1.8304.0 Update Source: User User: NT AUTHORITY\SYSTEM Error Code: 0x80070005 Error description: Access is denied.
    6/7/2012 8:45:29 AM, error: WinDefend [2001] - Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.125.886.0 Update Source: User Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8304.0 Error code: 0x80070005 Error description: Access is denied.
    6/14/2012 9:59:22 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    6/14/2012 9:58:47 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
    6/14/2012 9:58:28 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    6/14/2012 9:58:22 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswRdr aswSnx aswSP aswTdi cdudf_xp cmdGuard cmdHlp Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL
    6/14/2012 9:58:22 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
    6/14/2012 9:58:22 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/14/2012 9:58:22 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/14/2012 9:58:22 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    6/14/2012 6:20:02 AM, error: WinDefend [2003] - Windows Defender has encountered an error trying to update the engine. New Engine Version: Previous Engine Version: 1.1.8304.0 Update Source: User User: NT AUTHORITY\SYSTEM Error Code: 0x80070005 Error description: Access is denied.
    6/14/2012 6:20:02 AM, error: WinDefend [2001] - Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.125.886.0 Update Source: User Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8304.0 Error code: 0x80070005 Error description: Access is denied.
    6/14/2012 6:18:37 AM, error: DCOM [10001] - Unable to start a DCOM Server: {58FC39EB-9DBD-4EA7-B7B4-9404CC6ACFAB} as /. The error: "%5" Happened while starting this command: c:\PROGRA~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE -s -Embedding
    6/14/2012 6:14:54 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 2.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2656369).
    6/14/2012 6:08:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 1.1 SP1 on Windows XP, Windows Vista, and Windows Server 2008 x86 (KB2656370).
    6/14/2012 6:08:30 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 2.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2686828).
    6/14/2012 6:08:23 AM, error: Service Control Manager [7000] - The Windows Installer service failed to start DUE to the following error: Access is denied.
    6/14/2012 6:08:23 AM, error: DCOM [10005] - DCOM got error "%5" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
    6/14/2012 2:16:22 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
    6/14/2012 10:04:27 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSnx aswSP aswTdi cdudf_xp cmdGuard Fips intelppm SASDIFSV SASKUTIL
    6/14/2012 10:04:04 AM, error: Dhcp [1002] - The IP address lease 192.168.1.3 for the Network Card with network address 0007E9881D1C has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    6/14/2012 10:01:54 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    6/14/2012 1:50:21 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    6/13/2012 7:48:05 PM, error: WinDefend [2003] - Windows Defender has encountered an error trying to update the engine. New Engine Version: Previous Engine Version: 1.1.8304.0 Update Source: User User: NT AUTHORITY\SYSTEM Error Code: 0x80070005 Error description: Access is denied.
    6/13/2012 7:48:05 PM, error: WinDefend [2001] - Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.125.886.0 Update Source: User Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8304.0 Error code: 0x80070005 Error description: Access is denied.
    6/13/2012 6:58:12 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the NVSvc service.
    6/12/2012 7:42:17 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender - KB915597 (Definition 1.127.1815.0).
    6/12/2012 7:42:02 AM, error: WinDefend [2003] - Windows Defender has encountered an error trying to update the engine. New Engine Version: Previous Engine Version: 1.1.8304.0 Update Source: User User: NT AUTHORITY\SYSTEM Error Code: 0x80070005 Error description: Access is denied.
    6/12/2012 7:42:02 AM, error: WinDefend [2001] - Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.125.886.0 Update Source: User Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8304.0 Error code: 0x80070005 Error description: Access is denied.
    6/11/2012 6:19:33 AM, error: WinDefend [2003] - Windows Defender has encountered an error trying to update the engine. New Engine Version: Previous Engine Version: 1.1.8304.0 Update Source: User User: NT AUTHORITY\SYSTEM Error Code: 0x80070005 Error description: Access is denied.
    6/11/2012 6:19:33 AM, error: WinDefend [2001] - Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.125.886.0 Update Source: User Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8304.0 Error code: 0x80070005 Error description: Access is denied.
    6/10/2012 7:06:37 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender - KB915597 (Definition 1.127.1592.0).
    6/10/2012 7:06:23 AM, error: WinDefend [2003] - Windows Defender has encountered an error trying to update the engine. New Engine Version: Previous Engine Version: 1.1.8304.0 Update Source: User User: NT AUTHORITY\SYSTEM Error Code: 0x80070005 Error description: Access is denied.
    6/10/2012 7:06:23 AM, error: WinDefend [2001] - Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.125.886.0 Update Source: User Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8304.0 Error code: 0x80070005 Error description: Access is denied.
    6/10/2012 10:06:00 PM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for with the following error: Access is denied.
    6/10/2012 10:06:00 PM, error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: Access is denied.
    6/10/2012 10:06:00 PM, error: DCOM [10005] - DCOM got error "%5" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}
    .
    ==== End Of File ===========================
    You have three antivirus installed. (eTrust EZ Antivirus - COMODO Internet Security - avast! Free Antivirus)
    This is never good. Please uninstall all but one before continuing.
    I suggest keeping avast! and uninstalling the others.

    Also uninstall both of these:

    • Viewpoint Manager (Remove Only)
    • Viewpoint Media Player
    ----------

    Be sure to restart the computer after uninstalling everything.

    Can you update Malwarebytes now and run a new scan?

    I kept Avast and uninstalled everything except for Comodo, since that is the firewall that I use. After I restarted the computer nothing changed. I still can't update the definitions for MalwareBytes or SAS. If you already have ComboFix be sure to delete it and download a new copy.

    Download ComboFix© by sUBs from one of the below links. Be sure to save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.

    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixOddly enough, it seems as if everything went back to normal on my computer last night. In normal mode, I am now able to connect to the internet, open programs and icons, update my Java, and update all my definitions for SAS, Malwarebytes, etc. It did this once I removed the other programs you suggested.

    I tried running ComboFix but it stalled toward the end. I guess I can try running it again. If you think I should do scans with SAS and Malwarebytes again since I updated the definitions I will do that. See if Combofix created a log. It will be located in C:\combofix.txt
    139.

    Solve : Open With Problem 2?

    Answer»

    Hi Dave,

    ComboFix & HJT logs attatched as requested.

    Can I ask why HJT had to be renamed to sniper and also whenever you have referred
    to HJT should I be running sniper?

    Thanks

    [recovering disk space - old attachment deleted by admin]P2P - I see you have P2P software installed on your MACHINE. (BitTorrent) We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this ACTIVITY and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

    I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove this program, you can do so via Control Panel >> Add or Remove Programs.

    =======================

    ESET Online Scan

    Scan your computer with the ESET FREE Online Virus Scan

    * Click the ESET Online Scanner button.

    * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
    * Double click on the esetsmartinstaller_enu.exe icon on your desktop.
    * Place a check mark next to YES, I accept the Terms of Use.

    * Click the Start button.
    * Accept any security WARNINGS from your browser.
    * Leave the check mark next to Remove found threats and place a check next to Scan archives.
    * Click the Start button.
    * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
    * When the scan completes, click List of found threats.
    * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
    * Click the Back button then click Finish.

    In your next reply please include the ESET Online Scan LogHi Dave,

    Did the ESET scan which returned no threats but it didn't give me the option to save a report it only gave the option to either uninstal it or close it.

    Any ideas.

    ThanksQuote

    Did the ESET scan which returned no threats but it didn't give me the option to save a report it only gave the option to either uninstal it or close it.

    No threats is good news. When that happens, it doesn't produce a log. I never did find out what your original problem was with your computer. Is it working any better now?Hi Dave,

    The computer seems to be working perfectly and I think, better than ever so than you so much for your brilliant support, I really appreciate it.

    Obvioulsy I should be running anti viurs software (which I am) but what else would you recommend I install to keep the computer safe and running well.

    Cheers

    DavidQuote
    The computer seems to be working perfectly and I think, better than ever so than you so much for your brilliant support, I really appreciate it.
    Your Welcome. I'm glad I was able to help. Now it's time for some cleanup. You can uninstall HJT. You may keep SAS, MBAM and ESET if you wish. Update SAS and MBAM and run them on a regular basis. If you don't want to keep ESET, just delete it.

    To uninstall ComboFix

    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall


    (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
    ==============================

    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be ANYWHERE from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

    ===============================

    Looking over your log it seems you don't have any evidence of a third party firewall.

    Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

    Remember only install ONE firewall

    1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
    2) Online Armor
    3) Agnitum Outpost
    4) PC Tools Firewall Plus

    If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
    ===============================

    Use the Secunia Software Inspector to check for out of date software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing! I also forgot to mention that you already have MicroSoft Malicious software removal Tool on your computer. Just go to run, and type in mrt.exe to run the scans. It doesn't produce a log so I never use to clean other computer but I use it on both my computers. If it's not there, you can download from the MS download site.
    140.

    Solve : Trojan problem?

    Answer»

    Hi, here the log, but I have a quetion: I must to create a clean restore point and then to get rid it? Or the second part is only an example?
    Thank you

    Results of screen317's Security Check version 0.99.2
    Windows XP Service Pack 3
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    avast! Free Antivirus
    ESET Online Scanner v3
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Java(TM) 6 Update 19
    Out of date Java installed!
    Adobe Flash Player 10
    Adobe Reader 9.1.3 - Español
    Out of date Adobe Reader installed!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Alwil Software Avast5 AvastSvc.exe
    ALWILS~1 Avast5 avastUI.exe
    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log````````````


    Quote from: DragonMaster Jay on April 07, 2010, 07:59:04 PM

    Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions INSIDE of the black box.
    • A NOTEPAD document should open automatically called checkup.txt; please post the contents of that document.
    You will not get rid of the new one you create. Whenever you get rid of the System Restore points, it always leaves one just in case. So, by creating a new one, then purging the old ones, you will be clean and have a fresh restore point.

    ===============

    Please download the newest version of Adobe Acrobat Reader from Adobe.com

    Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and FEATURES in Vista/7).
    Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

    Once old versions are gone, please install the newest version.

    ================

    Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

    Software recommendations

    Firewall
    • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
    • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
    • PC Tools Firewall Plus: free and excellent firewall.
    AntiSpyware
    • SpywareBlaster
      SpywareBlaster is a program that prevents SPYWARE from installing on your computer. A tutorial on using SpywareBlaster may be found here.
    • Spybot - Search & Destroy.
      Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
    NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

    Resident Protection help
    A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

    Rogue programs help
    There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Securing your computer
    • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
    • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
    Please consider using an alternate browser
    Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

    If you are interested:
    See this PAGE for more info about malware and prevention.Ok DragonMaster Jay, I did everything, Thank you very much,

    HaolitYou're welcome.

    Since this appears to be resolved, this topic is now closed. Glad we could help!

    =>CLOSED
    141.

    Solve : multiple virus,?

    Answer»

    although I have norton 360/spybot/ccleaner/etc they still got in. have to many to list but will try and attached loLogfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:16:20 PM, on 8/27/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Panasonic\TrapMonitor\Trapmnnt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Online Backup\OnlineBackup.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\interMute\PopSubtract\PopSub.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R3 - URLSearchHook: Yahoo! TOOLBAR - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    O4 - HKCU\..\Run: [NVIEW] "rundll32.exe" nview.dll,nViewLoadHook
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
    O4 - HKCU\..\Run: [@BackupScheduler] C:\Program Files\Online Backup\OnlineBackup.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O4 - Global Startup: PopSubtract.lnk = C:\Program Files\interMute\PopSubtract\PopSub.exe
    O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine ADVANTAGE Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
    O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM_ca.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153681721437
    O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://mvt.mcafee.com/mvt/bin/3,0,1,0/mvt.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {CE0B5CFF-74B6-405F-B6B2-2C5C27BBA29D} (BLiveDeskShareX Class) - https://www.blivenow.com/static-content/plugin/blivedsx.ocx
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Panasonic Trap Monitor Service - Panasonic - C:\Program Files\Panasonic\TrapMonitor\Trapmnnt.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O24 - Desktop Component 0: (no name) - http://www.gradywhite.com/downloads/wallpaper/files/306_1024x768.jpg

    --
    End of file - 10572 bytes
    gs as you have indicated. If I screw up the first time please be patient. This date is wrong. I will rerun the OTHERS and send a link.Please download OTS by OldTimer and save it to your Desktop.

    Note: You must be logged on to the system with an account that has Administrator privileges to run this program.

    • Close ALL OTHER PROGRAMS.
    • Double-click on OTS to start the program (if you are running on Vista then right-click the program and
      choose Run as Administrator).
    • At the top, tick on Scan All Users section and Include MD5.
    • At File Age set it to 90 Days
    • In the Processes, Modules, Services, Drivers, and Registry
      section, please set on Safe List.
    • In the Files Created Within and Files Modified Within section, set it to File Age
    • At the bottom, tick on all Safe List and Use Company Name WhiteList option
    • Under Additional Scans, tick on the "Extras" button and then click the checkboxes in front of the following items to select them:
        Reg - Disabled MS Config Items
        Reg - Drivers32
        Reg - Ext
        Reg - IE
        Explorer Bar
        Reg - NetSvcs
        Reg - Safeboot Minimal
        Reg - Safeboot Network
        File - Lop Check
        File - Purity Scan
      • Do NOT change any other settings.
      • Then, in the Custom Scans box, place this in:

        %systemroot%\*. /mp /s
        %systemroot%\system32\*.dll /lockedfiles
        %systemroot%\system32\*.exe /lockedfiles
        %systemroot%\Tasks\*.job /lockedfiles
        %systemroot%\system32\drivers\*.sys /lockedfiles
        %systemroot%\System32\config\*.sav
        %system%\*.sys
        %system%\drivers\*.dll
        %system%\drivers\*.ini
        %system%\drivers\*.exe
        %SYSTEMDRIVE%\*.*
        %PROGRAMFILES%\*.
        %appdata%\*.*


      • Now click the Run Scan button on the toolbar.
      • Let it run unhindered until it finishes.
      • When the scan is complete Notepad will open with the report file loaded in it.
      • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
      142.

      Solve : antivirus soft virus...?

      Answer»

      I have the ANTIVIRUS soft virus. where it prompts you to buy the software to get rid of various viruses that it says it found on my laptop. i was unable to do anything with my laptop (because it kept saying that everything i tried to run was infected) until i changed my startup programs. then i was able to follow the directions in "Read this before requesting malware removal help" post. now i am posting the logs.

      [Saving space, attachment deleted by ADMIN]Please visit this webpage for a tutorial on downloading and running ComboFix:

      http://www.bleepingcomputer.com/combofix/how-to-use-combofix

      See the area: Using ComboFix, and when done, post the log back here.here's the combofix log

      [Saving space, attachment deleted by admin]Please download Stealth MBR Rootkit Detector by GMER from GMER.net, and SAVE to your Desktop.

      • Double-click mbr.exe to start the program.
      • When done scanning, it will save a log on the Desktop called mbr.log.
      • Please post the contents of that log in your next reply.
      mbr log

      [Saving space, attachment deleted by admin]Please download Profiles by noahdfear.
      • Save it to your desktop.
      • Double-click profiles.exe and post its log when you reply
      ===

      Due to lack of feedback, this topic is now closed. If you need the topic re-opened, PM a moderator and they shall unlock it.

      =>CLOSED
      143.

      Solve : Not sure if i have a virus or something?

      Answer»

      Ok. First, we'll work on the internet connection problem which will probably solve the other problem.

      Please download MiniToolBox to Desktop and run it.



      Checkmark the following boxes:


        • Flush DNS
        • Report IE Proxy Settings
        • Reset IE Proxy Settings
        • List content of Hosts
        • List IP Configuration
        • Lst Last 10 Event Viewer Errors
        • List Users, Partitions and Memory Size
        • [/b]
        Click Go and copy/paste the log (Result.txt) into your next post.
        *************************************************************
        Please download Farbar Service Scanner and run it on the computer with the issue.
        • Press "Scan".
        • It will create a log (FSS.txt) in the same directory the tool is run.
        • Please copy and paste the log to your reply.
        MiniToolBox by Farbar Version: 18-01-2012
        Ran by Michal (administrator) on 19-04-2012 at 19:38:49
        Windows 7 Ultimate (X64)
        Boot Mode: Normal
        ***************************************************************************

        ========================= Flush DNS: ===================================

        Windows IP Configuration

        Successfully flushed the DNS Resolver Cache.

        ========================= IE Proxy Settings: ==============================

        Proxy is not enabled.
        No Proxy Server is set.

        "Reset IE Proxy Settings": IE Proxy Settings were reset.
        ========================= Hosts content: =================================

        127.0.0.1 localhost

        ========================= IP Configuration: ================================



        # ----------------------------------
        # IPv4 Configuration
        # ----------------------------------
        pushd interface ipv4

        reset
        set global


        popd
        # End of IPv4 configuration



        Windows IP Configuration

        Host Name . . . . . . . . . . . . : Michal-PC
        Primary Dns Suffix . . . . . . . :
        Node Type . . . . . . . . . . . . : Hybrid
        IP Routing Enabled. . . . . . . . : No
        WINS Proxy Enabled. . . . . . . . : No

        Ethernet adapter Local Area Connection:

        Connection-specific DNS Suffix . :
        Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
        Physical Address. . . . . . . . . : 1C-6F-65-44-BD-7C
        DHCP Enabled. . . . . . . . . . . : Yes
        Autoconfiguration Enabled . . . . : Yes
        Link-local IPv6 Address . . . . . : fe80::49dc:6bd9:c334:af66%13(Preferred)
        IPv4 Address. . . . . . . . . . . : 192.168.0.14(Preferred)
        Subnet Mask . . . . . . . . . . . : 255.255.255.0
        Lease Obtained. . . . . . . . . . : Thursday, April 19, 2012 11:53:21 AM
        Lease Expires . . . . . . . . . . : Friday, April 20, 2012 2:22:41 PM
        Default Gateway . . . . . . . . . : 192.168.0.1
        DHCP Server . . . . . . . . . . . : 192.168.0.1
        DHCPv6 IAID . . . . . . . . . . . : 320630629
        DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-28-B3-BF-1C-6F-65-44-BD-7C
        DNS Servers . . . . . . . . . . . : 209.18.47.61
        209.18.47.62
        NetBIOS over Tcpip. . . . . . . . : Enabled

        Tunnel adapter isatap.{AB9A3967-9594-4881-8F89-5FD219C10889}:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :
        Description . . . . . . . . . . . : Microsoft ISATAP Adapter
        Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
        DHCP Enabled. . . . . . . . . . . : No
        Autoconfiguration Enabled . . . . : Yes

        Tunnel adapter Teredo Tunneling Pseudo-Interface:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :
        Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
        Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
        DHCP Enabled. . . . . . . . . . . : No
        Autoconfiguration Enabled . . . . : Yes
        Server: dns-cac-lb-01.rr.com
        Address: 209.18.47.61

        Name: google.com
        Addresses: 74.125.228.64
        74.125.228.65
        74.125.228.66
        74.125.228.67
        74.125.228.68
        74.125.228.69
        74.125.228.70
        74.125.228.71
        74.125.228.72
        74.125.228.73
        74.125.228.78


        Pinging google.com [72.14.204.138] with 32 bytes of data:
        Reply from 72.14.204.138: bytes=32 time=36ms TTL=54
        Reply from 72.14.204.138: bytes=32 time=23ms TTL=54

        Ping statistics for 72.14.204.138:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
        Approximate round trip times in milli-seconds:
        Minimum = 23ms, Maximum = 36ms, Average = 29ms
        Server: dns-cac-lb-01.rr.com
        Address: 209.18.47.61

        Name: yahoo.com
        Addresses: 98.139.183.24
        209.191.122.70
        72.30.38.140


        Pinging yahoo.com [209.191.122.70] with 32 bytes of data:
        Reply from 209.191.122.70: bytes=32 time=76ms TTL=51
        Reply from 209.191.122.70: bytes=32 time=59ms TTL=51

        Ping statistics for 209.191.122.70:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
        Approximate round trip times in milli-seconds:
        Minimum = 59ms, Maximum = 76ms, Average = 67ms
        Server: dns-cac-lb-01.rr.com
        Address: 209.18.47.61

        Name: bleepingcomputer.com
        Address: 208.43.87.2


        Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
        Reply from 208.43.87.2: Destination host unreachable.
        Reply from 208.43.87.2: Destination host unreachable.

        Ping statistics for 208.43.87.2:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

        Pinging 127.0.0.1 with 32 bytes of data:
        Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
        Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

        Ping statistics for 127.0.0.1:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
        Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 0ms, Average = 0ms
        ===========================================================================
        Interface List
        13...1c 6f 65 44 bd 7c ......Realtek PCIe GBE Family Controller
        1...........................Software Loopback Interface 1
        11...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
        12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
        ===========================================================================

        IPv4 Route Table
        ===========================================================================
        Active Routes:
        Network Destination Netmask Gateway Interface Metric
        0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.14 20
        127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
        127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
        127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
        192.168.0.0 255.255.255.0 On-link 192.168.0.14 276
        192.168.0.14 255.255.255.255 On-link 192.168.0.14 276
        192.168.0.255 255.255.255.255 On-link 192.168.0.14 276
        224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
        224.0.0.0 240.0.0.0 On-link 192.168.0.14 276
        255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
        255.255.255.255 255.255.255.255 On-link 192.168.0.14 276
        ===========================================================================
        Persistent Routes:
        None

        IPv6 Route Table
        ===========================================================================
        Active Routes:
        If Metric Network Destination Gateway
        1 306 ::1/128 On-link
        13 276 fe80::/64 On-link
        13 276 fe80::49dc:6bd9:c334:af66/128
        On-link
        1 306 ff00::/8 On-link
        13 276 ff00::/8 On-link
        ===========================================================================
        Persistent Routes:
        None

        ========================= Event log errors: ===============================

        Application errors:
        ==================
        Error: (04/19/2012 07:42:32 PM) (Source: Windows Search Service) (USER: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:38:31 PM) (Source: Windows Search Service) (User: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:34:29 PM) (Source: Windows Search Service) (User: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:30:27 PM) (Source: Windows Search Service) (User: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:26:26 PM) (Source: Windows Search Service) (User: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:22:25 PM) (Source: Windows Search Service) (User: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:18:23 PM) (Source: Windows Search Service) (User: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:14:21 PM) (Source: Windows Search Service) (User: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:10:19 PM) (Source: Windows Search Service) (User: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:06:17 PM) (Source: Windows Search Service) (User: )
        Description: Unable to initialize the filter host process. Terminating.

        Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)


        System errors:
        =============
        Error: (04/19/2012 11:56:55 AM) (Source: WMPNetworkSvc) (User: )
        Description: WMPNetworkSvc0x80004002

        Error: (04/19/2012 11:56:53 AM) (Source: Service Control Manager) (User: )
        Description: The Background Intelligent Transfer Service service DEPENDS on the COM+ Event System service which failed to start because of the following error:
        %%0

        Error: (04/19/2012 11:56:53 AM) (Source: DCOM) (User: )
        Description: 1068BITS{4991D34B-80A1-4291-83B6-3328366B9097}

        Error: (04/19/2012 11:54:49 AM) (Source: Service Control Manager) (User: )
        Description: The Internet Connection Sharing (ICS) service hung on starting.

        Error: (04/19/2012 11:53:20 AM) (Source: Service Control Manager) (User: )
        Description: The System Event Notification Service service depends on the COM+ Event System service which failed to start because of the following error:
        %%0

        Error: (04/19/2012 11:53:19 AM) (Source: EventLog) (User: )
        Description: The previous system SHUTDOWN at 11:49:35 AM on ?4/?19/?2012 was unexpected.

        Error: (04/19/2012 11:51:01 AM) (Source: Service Control Manager) (User: )
        Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.

        Error: (04/19/2012 11:50:31 AM) (Source: Service Control Manager) (User: )
        Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.

        Error: (04/19/2012 11:50:01 AM) (Source: Service Control Manager) (User: )
        Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.

        Error: (04/19/2012 11:49:31 AM) (Source: Service Control Manager) (User: )
        Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.


        Microsoft Office Sessions:
        =========================
        Error: (04/19/2012 07:42:32 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:38:31 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:34:29 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:30:27 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:26:26 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:22:25 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:18:23 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:14:21 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:10:19 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)

        Error: (04/19/2012 07:06:17 PM) (Source: Windows Search Service)(User: )
        Description: Details:
        This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4)


        ========================= Memory info: ===================================

        Percentage of memory in use: 26%
        Total physical RAM: 3959.49 MB
        Available physical RAM: 2905.25 MB
        Total Pagefile: 7917.13 MB
        Available Pagefile: 6296.39 MB
        Total Virtual: 4095.88 MB
        Available Virtual: 3970.79 MB

        ========================= Partitions: =====================================

        1 Drive c: () (Fixed) (Total:97.56 GB) (Free:23.37 GB) NTFS
        2 Drive d: () (Fixed) (Total:99.61 GB) (Free:99.39 GB) NTFS
        3 Drive e: () (Fixed) (Total:734.25 GB) (Free:733.21 GB) NTFS

        ========================= Users: ========================================

        User accounts for \\MICHAL-PC

        Administrator Guest Michal


        **** End of log ****






        Farbar Service Scanner Version: 16-04-2012
        Ran by Michal (administrator) on 19-04-2012 at 20:40:24
        Running from "C:\Users\Michal\Desktop"
        Windows 7 Ultimate (X64)
        Boot Mode: Normal
        ****************************************************************

        Internet Services:
        ============

        Connection Status:
        ==============
        Localhost is accessible.
        LAN connected.
        Google IP is accessible.
        Yahoo IP is accessible.


        File Check:
        ========
        C:\Windows\System32\nsisvc.dll => MD5 is legit
        C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
        C:\Windows\System32\dhcpcore.dll => MD5 is legit
        C:\Windows\System32\drivers\afd.sys
        [2012-03-24 12:05] - [2011-12-27 23:59] - 0499200 ____A (Microsoft Corporation) DB9D6C6B2CD95A9CA414D045B627422E

        C:\Windows\System32\drivers\tdx.sys => MD5 is legit
        C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
        C:\Windows\System32\dnsrslvr.dll => MD5 is legit
        C:\Windows\System32\svchost.exe => MD5 is legit
        C:\Windows\System32\rpcss.dll => MD5 is legit


        **** End of log ****Quote
        But I can still access the Internet, although any type of video from Youtube, Facebook etc. is extremely choppy, not even watchable.
        That would indicate a lack of enough memory. Please run the program below. It's supposed to fix a number of problems.

        Please download and run MS Fix-it from here.

        There is a program in Windows 7 that is specifically made to diagnose and repair problems with Windows updates. Could you please run it?I keep getting an error when trying to run Fix It

        There is a program in Windows 7 that is specifically made to diagnose and repair problems with Windows updates. Could you please run it?


        I'm no sure what this is either

        Yeah I'm clueless.Can you please try running Action Center?
        144.

        Solve : possible hacker in my pc?

        Answer»

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 12:37:03 AM, on 3/5/2010
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\system32\cisvc.exe
        C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\PROGRA~1\AVG\AVG8\avgnsx.exe
        C:\Program Files\GOOGLE\Update\1.2.183.17\GoogleCrashHandler.exe
        C:\WINDOWS\system32\lxddcoms.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
        C:\PROGRA~1\AVG\AVG8\avgemc.exe
        C:\WINDOWS\system32\SearchIndexer.exe
        C:\Program Files\AVG\AVG8\avgcsrvx.exe
        C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
        C:\Program Files\Microsoft Security Essentials\msseces.exe
        C:\Program Files\COMODO\livePCsupport\ELPS.exe
        C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
        C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\msb.exe
        C:\Program Files\AVG\AVG8\avgtray.exe
        C:\WINDOWS\system32\cidaemon.exe
        C:\Program Files\COMODO\COMODO livePCsupport\CLPS.exe
        C:\Program Files\CA Yahoo! Anti-Spy\CAYahooAntispy.exe
        C:\WINDOWS\explorer.exe
        C:\WINDOWS\system32\SearchProtocolHost.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HREF="http://www.metalink.net">http://www.metalink.net
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,;*.local
        R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
        R3 - URLSearchHook: WorldTV Bar Toolbar - {44c0b463-5a8a-452c-8e72-dc751dac6ec1} - C:\Program Files\WorldTV_Bar\tbWor1.dll
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
        R3 - URLSearchHook: Download Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
        R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
        R3 - URLSearchHook: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFre1.dll
        R3 - URLSearchHook: Sigma Team Toolbar - {5a089bcd-c7f1-4064-8702-f58d8bd5d61f} - C:\Program Files\Sigma_Team\tbSig0.dll
        R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
        F1 - win.ini: run= C:\WESTWOOD\REDALERT\INSTICON.EXE
        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
        O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Download Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: WorldTV Bar Toolbar - {44c0b463-5a8a-452c-8e72-dc751dac6ec1} - C:\Program Files\WorldTV_Bar\tbWor1.dll
        O2 - BHO: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFre1.dll
        O2 - BHO: Sigma Team Toolbar - {5a089bcd-c7f1-4064-8702-f58d8bd5d61f} - C:\Program Files\Sigma_Team\tbSig0.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
        O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
        O2 - BHO: Updater For My.Freeze.com Toolbar - {C26CD490-5F01-41E3-B150-EB29F19DA056} - (no file)
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
        O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
        O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: WorldTV Bar Toolbar - {44c0b463-5a8a-452c-8e72-dc751dac6ec1} - C:\Program Files\WorldTV_Bar\tbWor1.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
        O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
        O3 - Toolbar: Download Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
        O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
        O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
        O3 - Toolbar: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFre1.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O3 - Toolbar: Sigma Team Toolbar - {5a089bcd-c7f1-4064-8702-f58d8bd5d61f} - C:\Program Files\Sigma_Team\tbSig0.dll
        O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
        O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
        O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
        O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Google Update] "C:\DOCUMENTS and Settings\DJ j-dog\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
        O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
        O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
        O4 - HKCU\..\Run: [ROUA3O12PW] C:\WINDOWS\msb.exe
        O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
        O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe
        O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Application Data\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
        O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
        O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
        O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
        O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
        O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
        O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.paulding-net.com
        O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
        O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
        O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.fubar.com/imgs/ImageUploader5.cab
        O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v51/bejeweled/bejeweled.cab
        O16 - DPF: {64CD313F-F079-4D93-959F-4D28B5519449} (Jeopardy Control) - http://www.worldwinner.com/games/v50/jeopardy/jeopardy.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1243616579203
        O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
        O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
        O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} (BejeweledTwist Control) - http://www.worldwinner.com/games/v51/bejeweledtwist/bejeweledtwist.cab
        O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab
        O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v49/luxor/luxor.cab
        O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v67/swapit/swapit.cab
        O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
        O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
        O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
        O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
        O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
        O22 - SharedTaskScheduler: PsmeruliDms - {921C4EE3-11BB-4A96-8291-7374E4F5B74C} - (no file)
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
        O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
        O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
        O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
        O23 - Service: Google Update Service (gupdate1c9e85899db27d4) (gupdate1c9e85899db27d4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
        O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
        O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

        --
        End of file - 16096 bytes
        Hello! We need to do some diagnostics to get started.

        1. Please download Profiles by noahdfear.

        • Save it to your desktop.
        • Double-click profiles.exe and post its log when you reply
        2. Download Win32kDiag by ad13 and save it to your Desktop.
        • Double-click Win32kDiag.exe to run Win32kDiag and let it finish.
        • When it states "Finished! Press any key to exit...", press any key on your keyboard to close the program.
        • Double-click on the Win32kDiag.txt file that is located on your Desktop and post the entire contents of that log as a reply to this topic.
        3. Please download <a href="http://www.helpmyos.com/Cheetah-php-h15.htm?cheetah.zip" target="_blank">Cheetah-Anti-Rogue[/url][/b] by me, and save to your Desktop.
        • Double-click on Cheetah-Anti-Rogue.zip, and extract the file to your Desktop.
        • Double-click on Cheetah-Anti-Rogue.cmd to start.
        • It will finish quickly and launch a log.
        • Post the contents of it in your next reply.
        4. In your next reply, please post the following logs for my review:
        • Profiles log (1)
        • Win32kDiag log (2)
        • Cheetah log (3)
        THANKS! :)Due to lack of feedback, this topic is now closed. If you need the topic re-opened, PM a moderator and they shall unlock it.

        =>CLOSED
        145.

        Solve : Google Redirect Virus?

        Answer»

        I'm stumped. I'm going to check with a colleague about this problem.Ok. Thank you.Please download MiniToolBox to Desktop and run it.



        Checkmark the following boxes:


          • Flush DNS
          • Report IE Proxy Settings
          • Reset IE Proxy Settings
          • List content of Hosts
          • List IP Configuration
          • Lst Last 10 Event Viewer Errors
          • List Users, Partitions and Memory Size
          • [/b]
          Click Go and copy/paste the log (Result.txt) into your next post.
          MiniToolBox by Farbar Version: 18-01-2012
          Ran by USER (administrator) on 07-04-2012 at 20:27:20
          Microsoft Windows XP Professional Service Pack 3 (X86)
          Boot Mode: Normal
          ***************************************************************************

          ========================= Flush DNS: ===================================


          Windows IP Configuration



          Successfully flushed the DNS Resolver Cache.


          ========================= IE Proxy Settings: ==============================

          Proxy is not enabled.
          No Proxy Server is set.

          "Reset IE Proxy Settings": IE Proxy Settings were reset.
          ========================= Hosts content: =================================

          127.0.0.1 localhost

          ========================= IP Configuration: ================================

          Intel(R) 82562V-2 10/100 Network Connection = Local Area Connection (Connected)


          # ----------------------------------
          # Interface IP Configuration
          # ----------------------------------
          pushd interface ip


          # Interface IP Configuration for "Local Area Connection"

          set address name="Local Area Connection" source=dhcp
          set dns name="Local Area Connection" source=dhcp register=PRIMARY
          set wins name="Local Area Connection" source=dhcp


          popd
          # End of interface IP configuration




          Windows IP Configuration



          Host Name . . . . . . . . . . . . : user-ffe079d9b5

          Primary Dns Suffix . . . . . . . :

          Node Type . . . . . . . . . . . . : Unknown

          IP Routing Enabled. . . . . . . . : No

          WINS Proxy Enabled. . . . . . . . : No



          Ethernet adapter Local Area Connection:



          Connection-specific DNS Suffix . :

          DESCRIPTION . . . . . . . . . . . : Intel(R) 82562V-2 10/100 Network Connection

          Physical Address. . . . . . . . . : 00-21-9B-0B-BC-88

          Dhcp Enabled. . . . . . . . . . . : Yes

          Autoconfiguration Enabled . . . . : Yes

          IP Address. . . . . . . . . . . . : 192.168.1.4

          Subnet Mask . . . . . . . . . . . : 255.255.255.0

          Default Gateway . . . . . . . . . : 192.168.1.1

          DHCP Server . . . . . . . . . . . : 192.168.1.1

          DNS Servers . . . . . . . . . . . : 192.168.1.1

          Lease Obtained. . . . . . . . . . : Saturday, April 07, 2012 8:27:13 PM

          Lease Expires . . . . . . . . . . : SUNDAY, April 08, 2012 8:27:13 PM

          Server: UnKnown
          Address: 192.168.1.1

          Name: google.com
          Addresses: 74.125.226.196, 74.125.226.197, 74.125.226.198, 74.125.226.199
          74.125.226.200, 74.125.226.201, 74.125.226.206, 74.125.226.192, 74.125.226.193
          74.125.226.194, 74.125.226.195



          Pinging google.com [74.125.226.231] with 32 bytes of data:



          Reply from 74.125.226.231: bytes=32 time=34ms TTL=53

          Reply from 74.125.226.231: bytes=32 time=33ms TTL=53



          Ping statistics for 74.125.226.231:

          Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

          Approximate round trip times in milli-seconds:

          MINIMUM = 33ms, Maximum = 34ms, Average = 33ms

          Server: UnKnown
          Address: 192.168.1.1

          Name: yahoo.com
          Addresses: 72.30.38.140, 98.139.183.24, 209.191.122.70



          Pinging yahoo.com [209.191.122.70] with 32 bytes of data:



          Reply from 209.191.122.70: bytes=32 time=76ms TTL=50

          Reply from 209.191.122.70: bytes=32 time=75ms TTL=50



          Ping statistics for 209.191.122.70:

          Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

          Approximate round trip times in milli-seconds:

          Minimum = 75ms, Maximum = 76ms, Average = 75ms

          Server: UnKnown
          Address: 192.168.1.1

          Name: bleepingcomputer.com
          Address: 208.43.87.2



          Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:



          Reply from 208.43.87.2: Destination host unreachable.

          Reply from 208.43.87.2: Destination host unreachable.



          Ping statistics for 208.43.87.2:

          Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

          Approximate round trip times in milli-seconds:

          Minimum = 0ms, Maximum = 0ms, Average = 0ms



          Pinging 127.0.0.1 with 32 bytes of data:



          Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

          Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



          Ping statistics for 127.0.0.1:

          Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

          Approximate round trip times in milli-seconds:

          Minimum = 0ms, Maximum = 0ms, Average = 0ms

          ===========================================================================
          Interface List
          0x1 ........................... MS TCP Loopback interface
          0x2 ...00 21 9b 0b bc 88 ...... Intel(R) 82562V-2 10/100 Network Connection - Agnitum firewall miniport
          ===========================================================================
          ===========================================================================
          Active Routes:
          Network Destination Netmask Gateway Interface Metric
          0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.4 20
          127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
          192.168.1.0 255.255.255.0 192.168.1.4 192.168.1.4 20
          192.168.1.4 255.255.255.255 127.0.0.1 127.0.0.1 20
          192.168.1.255 255.255.255.255 192.168.1.4 192.168.1.4 20
          224.0.0.0 240.0.0.0 192.168.1.4 192.168.1.4 20
          255.255.255.255 255.255.255.255 192.168.1.4 192.168.1.4 1
          Default Gateway: 192.168.1.1
          ===========================================================================
          Persistent Routes:
          None

          ========================= Event log errors: ===============================

          Application errors:
          ==================
          Error: (04/04/2012 04:28:33 PM) (Source: Application Hang) (User: )
          Description: Fault bucket -1413921487.

          Error: (04/04/2012 04:28:31 PM) (Source: Application Hang) (User: )
          Description: Hanging application firefox.exe, version 11.0.0.4454, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

          Error: (04/03/2012 06:33:04 PM) (Source: Application Error) (User: )
          Description: Fault bucket -1391902482.
          The Wep key exchange did not result in a secure connection setup after 802.1x authentication. The current setting has been marked as failed and the Wireless connection will be disconnected.

          Error: (04/03/2012 06:33:01 PM) (Source: Application Error) (User: )
          Description: Faulting application FlashPlayerUpdateService.exe, version 11.2.202.228, faulting module FlashPlayerUpdateService.exe, version 11.2.202.228, fault address 0x0000abd8.
          Processing media-specific event for [FlashPlayerUpdateService.exe!ws!]

          Error: (04/01/2012 09:00:55 PM) (Source: Application Hang) (User: )
          Description: Fault bucket 1217514343.

          Error: (04/01/2012 09:00:52 PM) (Source: Application Hang) (User: )
          Description: Hanging application SysProt.exe, version 1.0.1.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

          Error: (04/01/2012 08:59:56 PM) (Source: Application Hang) (User: )
          Description: Fault bucket 1217514343.

          Error: (04/01/2012 08:59:53 PM) (Source: Application Hang) (User: )
          Description: Hanging application SysProt.exe, version 1.0.1.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

          Error: (03/31/2012 08:14:17 PM) (Source: Application Error) (User: )
          Description: Faulting application oasrv.exe, version 5.5.0.1557, faulting module oasrv.exe, version 5.5.0.1557, fault address 0x00004a6f.
          Processing media-specific event for [oasrv.exe!ws!]

          Error: (03/21/2012 11:36:57 AM) (Source: Application Hang) (User: )
          Description: Hanging application firefox.exe, version 11.0.0.4454, hang module hungapp, version 0.0.0.0, hang address 0x00000000.


          System errors:
          =============
          Error: (04/07/2012 08:27:08 AM) (Source: Dhcp) (User: )
          Description: The IP address lease 0.0.0.0 for the Network Card with network address 00219B0BBC88 has been
          denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

          Error: (04/07/2012 08:27:05 AM) (Source: Dhcp) (User: )
          Description: The IP address lease 192.168.1.2 for the Network Card with network address 00219B0BBC88 has been
          denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

          Error: (04/01/2012 03:01:13 PM) (Source: Service Control Manager) (User: )
          Description: The SAS Core Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.


          Microsoft Office Sessions:
          =========================
          Error: (04/04/2012 04:28:33 PM) (Source: Application Hang)(User: )
          Description: -1413921487

          Error: (04/04/2012 04:28:31 PM) (Source: Application Hang)(User: )
          Description: firefox.exe11.0.0.4454hungapp0.0.0.0000 00000

          Error: (04/03/2012 06:33:04 PM) (Source: Application Error)(User: )
          Description: -1391902482

          Error: (04/03/2012 06:33:01 PM) (Source: Application Error)(User: )
          Description: FlashPlayerUpdateService.exe11.2.202.22 8FlashPlayerUpdateService.exe11.2.202.2 280000abd8

          Error: (04/01/2012 09:00:55 PM) (Source: Application Hang)(User: )
          Description: 1217514343

          Error: (04/01/2012 09:00:52 PM) (Source: Application Hang)(User: )
          Description: SysProt.exe1.0.1.0hungapp0.0.0.00000000 0

          Error: (04/01/2012 08:59:56 PM) (Source: Application Hang)(User: )
          Description: 1217514343

          Error: (04/01/2012 08:59:53 PM) (Source: Application Hang)(User: )
          Description: SysProt.exe1.0.1.0hungapp0.0.0.00000000 0

          Error: (03/31/2012 08:14:17 PM) (Source: Application Error)(User: )
          Description: oasrv.exe5.5.0.1557oasrv.exe5.5.0.15570 0004a6f

          Error: (03/21/2012 11:36:57 AM) (Source: Application Hang)(User: )
          Description: firefox.exe11.0.0.4454hungapp0.0.0.0000 00000


          ========================= Memory info: ===================================

          Percentage of memory in use: 24%
          Total physical RAM: 3326.1 MB
          Available physical RAM: 2521.16 MB
          Total Pagefile: 5210.32 MB
          Available Pagefile: 4515.76 MB
          Total Virtual: 2047.88 MB
          Available Virtual: 1974.96 MB

          ========================= Partitions: =====================================

          1 Drive c: () (Fixed) (Total:298.08 GB) (Free:280.93 GB) NTFS

          ========================= Users: ========================================

          User accounts for \\USER-FFE079D9B5

          Administrator Guest HelpAssistant
          Sharon DePuy SUPPORT_388945a0 USER


          **** End of log ****
          Comments removed.
          146.

          Solve : Trouble downloading HijackThis to correct location?

          Answer»

          My comp is freezing, crashing and restarting. I'm WORKING through the pre-post "to-do" list. I've been unable to complete scans using SAS (comp restarts) and Malware Bytes (comp freezes).

          I'm to the point of downloading HijackThis but I don't GET the install prompts and AUTOMATIC placement of HJT in the location listed in the directions. I can rename it and then choose where to place it (DESKTOP, etc...). Would I just select the C drive to get it to the right place?

          Please visit this webpage for a tutorial on downloading and running ComboFix:

          http://www.bleepingcomputer.com/combofix/how-to-use-combofix

          See the area: Using ComboFix, and when done, post the log back here.Due to lack of feedback, this topic is now closed. If you need the topic re-opened, PM a moderator and they SHALL unlock it.

          =>CLOSED

          147.

          Solve : PLEASE HELP?

          Answer»

          i cant watch videos and everytime i try downloading flash player i have this message posted in wordpad on my desktop. What the *censored* isit and how can i get rid of it!! i want to cry haha
          #
          # A fatal error has been detected by the Java Runtime Environment:
          #
          # EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x46bfe9ed, pid=512, tid=3696
          #
          # JRE version: 6.0_17-b04
          # Java VM: Java HotSpot(TM) Client VM (14.3-b01 mixed mode, sharing windows-x86 )
          # Problematic frame:
          # C 0x46bfe9ed
          #
          # If you would like to submit a bug report, please visit:
          # http://java.sun.com/webapps/bugreport/crash.jsp
          # The crash happened outside the Java Virtual Machine in native code.
          # See problematic frame for where to report the bug.
          #

          --------------- T H R E A D ---------------

          Current thread (0x03122800): JavaThread "thread applet-com.diginet.digichat.client.DigiChatApplet-1" [_thread_in_native, id=3696, stack(0x03320000,0x03370000)]

          siginfo: ExceptionCode=0xc0000005, reading address 0x46bfe9ed

          Registers:
          EAX=0x0336d62c, EBX=0x00000188, ECX=0x03117618, EDX=0x00000004
          ESP=0x0336d60c, EBP=0x0336de38, ESI=0x0336d62c, EDI=0x00000188
          EIP=0x46bfe9ed, EFLAGS=0x00010202

          Top of Stack: (sp=0x0336d60c)
          0x0336d60c: 6d6171fe 00002360 0336d62c 00000188
          0x0336d61c: 00000000 03122800 26df2bd8 26df2bd0
          0x0336d62c: 20544547 6769442f 61684369 69442f74
          0x0336d63c: 6c436967 65737361 6c432f73 746e6569
          0x0336d64c: 315f355f 315f305f 616a2e39 54482072
          0x0336d65c: 312f5054 0a0d312e 746e6f63 2d746e65
          0x0336d66c: 65707974 7061203a 63696c70 6f697461
          0x0336d67c: 2d782f6e 6176616a 6372612d 65766968

          Instructions: (pc=0x46bfe9ed)
          0x46bfe9dd:
          [error occurred during error reporting (printing registers, top of stack, instructions near pc), id 0xc0000005]

          Stack: [0x03320000,0x03370000], sp=0x0336d60c, free space=309k
          Native frames: (J=compiled Java code, j=interpreted, Vv=VM code, C=native code)
          C 0x46bfe9ed
          j java.net.SocketOutputStream.socketWrite 0(Ljava/io/FileDescriptor;[BII)V+0
          j java.net.SocketOutputStream.socketWrite([BII)V+44
          j java.net.SocketOutputStream.write([BII)V+4
          j java.io.BufferedOutputStream.flushBuffe r()V+20
          j java.io.BufferedOutputStream.flush()V+1
          j java.io.PrintStream.flush()V+12
          j sun.net.www.MessageHeader.print(Ljava/io/PrintStream;)V+101
          j sun.net.www.http.HttpClient.writeReques ts(Lsun/net/www/MessageHeader;Lsun/net/www/http/PosterOutputStream;)V+13
          j sun.net.www.protocol.http.HttpURLConnec tion.writeRequests()V+647
          j sun.net.www.protocol.http.HttpURLConnec tion.getInputStream()Ljava/io/InputStream;+278
          j com.sun.deploy.net.HttpUtils.followRedi rects(Ljava/net/URLConnection;)Ljava/net/HttpURLConnection;+20
          j com.sun.deploy.net.BasicHttpRequest.doR equest(Ljava/net/URL;Z[Ljava/lang/String;[Ljava/lang/String;ZJ)Lcom/sun/deploy/net/HttpResponse;+193
          j com.sun.deploy.net.BasicHttpRequest.doG etRequestEX(Ljava/net/URL;[Ljava/lang/String;[Ljava/lang/String;J)Lcom/sun/deploy/net/HttpResponse;+8
          j com.sun.deploy.net.DownloadEngine.isUpd ateAvailable(Ljava/net/URL;Ljava/lang/String;ZLjava/util/Map;)Z+329
          j com.sun.deploy.cache.DeployCacheHandler .get(Ljava/net/URI;Ljava/lang/String;Ljava/util/Map;)Ljava/net/CacheResponse;+134
          j sun.net.www.protocol.http.HttpURLConnec tion.plainConnect()V+54
          j sun.net.www.protocol.http.HttpURLConnec tion.connect()V+1
          j sun.net.www.protocol.http.HttpURLConnec tion.getInputStream()Ljava/io/InputStream;+187
          j sun.plugin.PluginURLJarFileCallBack.dow nloadJAR(Ljava/net/URLConnection;Z)V+34
          j sun.plugin.PluginURLJarFileCallBack.acc ess$000(Lsun/plugin/PluginURLJarFileCallBack;Ljava/net/URLConnection;Z)V+3
          j sun.plugin.PluginURLJarFileCallBack$2.run()Ljava/lang/Object;+103
          v ~StubRoutines::call_stub
          V [jvm.dll+0xecf9c]
          V [jvm.dll+0x1741d1]
          V [jvm.dll+0xed01d]
          V [jvm.dll+0x11c2bf]
          C [java.dll+0x1047]
          j sun.plugin.PluginURLJarFileCallBack.ret rieve(Ljava/net/URL;)Ljava/util/jar/JarFile;+73
          j sun.net.www.protocol.jar.URLJarFile.ret rieve(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+10
          j sun.net.www.protocol.jar.URLJarFile.get JarFile(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+19
          j sun.net.www.protocol.jar.JarFileFactory .get(Ljava/net/URL;Z)Ljava/util/jar/JarFile;+192
          j sun.net.www.protocol.jar.JarURLConnecti on.connect()V+19
          j sun.plugin.net.protocol.jar.CachedJarUR LConnection.connect()V+116
          j sun.plugin.net.protocol.jar.CachedJarUR LConnection.getJarFileInternal()Ljava/util/jar/JarFile;+213
          j sun.plugin.net.protocol.jar.CachedJarUR LConnection.getJarFile()Ljava/util/jar/JarFile;+2
          j sun.misc.URLClassPath$JarLoader.getJarFile(Ljava/net/URL;)Ljava/util/jar/JarFile;+69
          j sun.misc.URLClassPath$JarLoader.access$600(Lsun/misc/URLClassPath$JarLoader;Ljava/net/URL;)Ljava/util/jar/JarFile;+2
          j sun.misc.URLClassPath$JarLoader$1.run()Ljava/lang/Object;+55
          v ~StubRoutines::call_stub
          V [jvm.dll+0xecf9c]
          V [jvm.dll+0x1741d1]
          V [jvm.dll+0xed01d]
          V [jvm.dll+0x11c2bf]
          C [java.dll+0x1047]
          j sun.misc.URLClassPath$JarLoader.ensureOpen()V+15
          j sun.misc.URLClassPath$JarLoader.(Ljava/net/URL;Ljava/net/URLStreamHandler;Ljava/util/HashMap;)V+60
          j sun.misc.URLClassPath$3.run()Ljava/lang/Object;+82
          v ~StubRoutines::call_stub
          V [jvm.dll+0xecf9c]
          V [jvm.dll+0x1741d1]
          V [jvm.dll+0xed01d]
          V [jvm.dll+0x11c2bf]
          C [java.dll+0x1047]
          j sun.misc.URLClassPath.getLoader(Ljava/net/URL;)Lsun/misc/URLClassPath$Loader;+9
          j sun.misc.URLClassPath.getLoader(I)Lsun/misc/URLClassPath$Loader;+73
          j sun.misc.URLClassPath.getResource(Ljava/lang/String;Z)Lsun/misc/Resource;+42
          j sun.plugin2.applet.Plugin2ClassLoader$2.run()Ljava/lang/Object;+51
          v ~StubRoutines::call_stub
          V [jvm.dll+0xecf9c]
          V [jvm.dll+0x1741d1]
          V [jvm.dll+0xed01d]
          V [jvm.dll+0x11c2bf]
          C [java.dll+0x1061]
          j sun.plugin2.applet.Plugin2ClassLoader.f indClassHelper(Ljava/lang/String;)Ljava/lang/Class;+33
          j sun.plugin2.applet.Applet2ClassLoader.f indClass(Ljava/lang/String;)Ljava/lang/Class;+34
          j java.lang.ClassLoader.loadClass(Ljava/lang/String;Z)Ljava/lang/Class;+43
          j java.lang.ClassLoader.loadClass(Ljava/lang/String;)Ljava/lang/Class;+3
          j sun.plugin2.applet.Plugin2ClassLoader.l oadCode(Ljava/lang/String;)Ljava/lang/Class;+123
          j sun.plugin2.applet.Plugin2Manager.creat eApplet()Ljava/applet/Applet;+127
          j sun.plugin2.applet.Plugin2Manager$AppletExecutionRunnable.run()V+183
          j java.lang.Thread.run()V+11
          v ~StubRoutines::call_stub
          V [jvm.dll+0xecf9c]
          V [jvm.dll+0x1741d1]
          V [jvm.dll+0xed167]
          V [jvm.dll+0xed1dd]
          V [jvm.dll+0x116290]
          V [jvm.dll+0x1d0414]
          V [jvm.dll+0x173e4c]
          C [msvcr71.dll+0x9565]
          C [kernel32.dll+0xb729]

          Java frames: (J=compiled Java code, j=interpreted, Vv=VM code)
          j java.net.SocketOutputStream.socketWrite 0(Ljava/io/FileDescriptor;[BII)V+0
          j java.net.SocketOutputStream.socketWrite([BII)V+44
          j java.net.SocketOutputStream.write([BII)V+4
          j java.io.BufferedOutputStream.flushBuffe r()V+20
          j java.io.BufferedOutputStream.flush()V+1
          j java.io.PrintStream.flush()V+12
          j sun.net.www.MessageHeader.print(Ljava/io/PrintStream;)V+101
          j sun.net.www.http.HttpClient.writeReques ts(Lsun/net/www/MessageHeader;Lsun/net/www/http/PosterOutputStream;)V+13
          j sun.net.www.protocol.http.HttpURLConnec tion.writeRequests()V+647
          j sun.net.www.protocol.http.HttpURLConnec tion.getInputStream()Ljava/io/InputStream;+278
          j com.sun.deploy.net.HttpUtils.followRedi rects(Ljava/net/URLConnection;)Ljava/net/HttpURLConnection;+20
          j com.sun.deploy.net.BasicHttpRequest.doR equest(Ljava/net/URL;Z[Ljava/lang/String;[Ljava/lang/String;ZJ)Lcom/sun/deploy/net/HttpResponse;+193
          j com.sun.deploy.net.BasicHttpRequest.doG etRequestEX(Ljava/net/URL;[Ljava/lang/String;[Ljava/lang/String;J)Lcom/sun/deploy/net/HttpResponse;+8
          j com.sun.deploy.net.DownloadEngine.isUpd ateAvailable(Ljava/net/URL;Ljava/lang/String;ZLjava/util/Map;)Z+329
          j com.sun.deploy.cache.DeployCacheHandler .get(Ljava/net/URI;Ljava/lang/String;Ljava/util/Map;)Ljava/net/CacheResponse;+134
          j sun.net.www.protocol.http.HttpURLConnec tion.plainConnect()V+54
          j sun.net.www.protocol.http.HttpURLConnec tion.connect()V+1
          j sun.net.www.protocol.http.HttpURLConnec tion.getInputStream()Ljava/io/InputStream;+187
          j sun.plugin.PluginURLJarFileCallBack.dow nloadJAR(Ljava/net/URLConnection;Z)V+34
          j sun.plugin.PluginURLJarFileCallBack.acc ess$000(Lsun/plugin/PluginURLJarFileCallBack;Ljava/net/URLConnection;Z)V+3
          j sun.plugin.PluginURLJarFileCallBack$2.run()Ljava/lang/Object;+103
          v ~StubRoutines::call_stub
          j java.security.AccessController.doPrivil eged(Ljava/security/PrivilegedExceptionAction;)Ljava/lang/Object;+0
          j sun.plugin.PluginURLJarFileCallBack.ret rieve(Ljava/net/URL;)Ljava/util/jar/JarFile;+73
          j sun.net.www.protocol.jar.URLJarFile.ret rieve(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+10
          j sun.net.www.protocol.jar.URLJarFile.get JarFile(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+19
          j sun.net.www.protocol.jar.JarFileFactory .get(Ljava/net/URL;Z)Ljava/util/jar/JarFile;+192
          j sun.net.www.protocol.jar.JarURLConnecti on.connect()V+19
          j sun.plugin.net.protocol.jar.CachedJarUR LConnection.connect()V+116
          j sun.plugin.net.protocol.jar.CachedJarUR LConnection.getJarFileInternal()Ljava/util/jar/JarFile;+213
          j sun.plugin.net.protocol.jar.CachedJarUR LConnection.getJarFile()Ljava/util/jar/JarFile;+2
          j sun.misc.URLClassPath$JarLoader.getJarFile(Ljava/net/URL;)Ljava/util/jar/JarFile;+69
          j sun.misc.URLClassPath$JarLoader.access$600(Lsun/misc/URLClassPath$JarLoader;Ljava/net/URL;)Ljava/util/jar/JarFile;+2
          j sun.misc.URLClassPath$JarLoader$1.run()Ljava/lang/Object;+55
          v ~StubRoutines::call_stub
          j java.security.AccessController.doPrivil eged(Ljava/security/PrivilegedExceptionAction;)Ljava/lang/Object;+0
          j sun.misc.URLClassPath$JarLoader.ensureOpen()V+15
          j sun.misc.URLClassPath$JarLoader.(Ljava/net/URL;Ljava/net/URLStreamHandler;Ljava/util/HashMap;)V+60
          j sun.misc.URLClassPath$3.run()Ljava/lang/Object;+82
          v ~StubRoutines::call_stub
          j java.security.AccessController.doPrivil eged(Ljava/security/PrivilegedExceptionAction;)Ljava/lang/Object;+0
          j sun.misc.URLClassPath.getLoader(Ljava/net/URL;)Lsun/misc/URLClassPath$Loader;+9
          j sun.misc.URLClassPath.getLoader(I)Lsun/misc/URLClassPath$Loader;+73
          j sun.misc.URLClassPath.getResource(Ljava/lang/String;Z)Lsun/misc/Resource;+42
          j sun.plugin2.applet.Plugin2ClassLoader$2.run()Ljava/lang/Object;+51
          v ~StubRoutines::call_stub
          j java.security.AccessController.doPrivil eged(Ljava/security/PrivilegedExceptionAction;Ljava/security/AccessControlContext;)Ljava/lang/Object;+0
          j sun.plugin2.applet.Plugin2ClassLoader.f indClassHelper(Ljava/lang/String;)Ljava/lang/Class;+33
          j sun.plugin2.applet.Applet2ClassLoader.f indClass(Ljava/lang/String;)Ljava/lang/Class;+34
          j java.lang.ClassLoader.loadClass(Ljava/lang/String;Z)Ljava/lang/Class;+43
          j java.lang.ClassLoader.loadClass(Ljava/lang/String;)Ljava/lang/Class;+3
          j sun.plugin2.applet.Plugin2ClassLoader.l oadCode(Ljava/lang/String;)Ljava/lang/Class;+123
          j sun.plugin2.applet.Plugin2Manager.creat eApplet()Ljava/applet/Applet;+127
          j sun.plugin2.applet.Plugin2Manager$AppletExecutionRunnable.run()V+183
          j java.lang.Thread.run()V+11
          v ~StubRoutines::call_stub

          --------------- P R O C E S S ---------------

          Java Threads: ( => current thread )
          0x03123000 JavaThread "Thread-10" [_thread_blocked, id=3216, stack(0x04080000,0x040d0000)]
          =>0x03122800 JavaThread "thread applet-com.diginet.digichat.client.DigiChatApplet-1" [_thread_in_native, id=3696, stack(0x03320000,0x03370000)]
          0x03118400 JavaThread "AWT-EventQueue-2" [_thread_blocked, id=3648, stack(0x040d0000,0x04120000)]
          0x03114400 JavaThread "Applet 2 LiveConnect Worker Thread" [_thread_blocked, id=3392, stack(0x04030000,0x04080000)]
          0x030ec400 JavaThread "Browser Side Object Cleanup Thread" [_thread_blocked, id=3524, stack(0x03600000,0x03650000)]
          0x03107000 JavaThread "Image FETCHER 3" daemon [_thread_blocked, id=3552, stack(0x03740000,0x03790000)]
          0x03100c00 JavaThread "Windows Tray Icon Thread" [_thread_in_native, id=2996, stack(0x036f0000,0x03740000)]
          0x03100800 JavaThread "CacheCleanUpThread" daemon [_thread_blocked, id=3088, stack(0x03650000,0x036a0000)]
          0x030f5c00 JavaThread "CacheMemoryCleanUpThread" daemon [_thread_blocked, id=2976, stack(0x036a0000,0x036f0000)]
          0x030e6000 JavaThread "Java Plug-In Heartbeat Thread" [_thread_blocked, id=1492, stack(0x035b0000,0x03600000)]
          0x030e4c00 JavaThread "AWT-EventQueue-0" [_thread_blocked, id=4040, stack(0x03560000,0x035b0000)]
          0x030e3000 JavaThread "AWT-Windows" daemon [_thread_in_native, id=1896, stack(0x034b0000,0x03500000)]
          0x030e1c00 JavaThread "AWT-Shutdown" [_thread_blocked, id=3568, stack(0x03460000,0x034b0000)]
          0x030dd800 JavaThread "Java2D Disposer" daemon [_thread_blocked, id=2544, stack(0x03410000,0x03460000)]
          0x030dac00 JavaThread "Java Plug-In Pipe Worker Thread (Client-Side)" daemon [_thread_in_native, id=1600, stack(0x03370000,0x033c0000)]
          0x030dc800 JavaThread "traceMsgQueueThread" daemon [_thread_blocked, id=3140, stack(0x032d0000,0x03320000)]
          0x02d6bc00 JavaThread "Timer-0" [_thread_blocked, id=3836, stack(0x03080000,0x030d0000)]
          0x02d49400 JavaThread "Low Memory Detector" daemon [_thread_blocked, id=3164, stack(0x02fc0000,0x03010000)]
          0x02d42c00 JavaThread "CompilerThread0" daemon [_thread_blocked, id=2712, stack(0x02f70000,0x02fc0000)]
          0x02d41400 JavaThread "Attach Listener" daemon [_thread_blocked, id=1176, stack(0x02f20000,0x02f70000)]
          0x02d40000 JavaThread "Signal Dispatcher" daemon [_thread_blocked, id=3252, stack(0x02ed0000,0x02f20000)]
          0x02d01800 JavaThread "Finalizer" daemon [_thread_blocked, id=2572, stack(0x02e80000,0x02ed0000)]
          0x02cfcc00 JavaThread "Reference Handler" daemon [_thread_blocked, id=1368, stack(0x02e30000,0x02e80000)]
          0x00a96800 JavaThread "main" [_thread_blocked, id=3132, stack(0x00b20000,0x00b70000)]

          Other Threads:
          0x02cfb400 VMThread [stack: 0x02de0000,0x02e30000] [id=172]
          0x02d5cc00 WatcherThread [stack: 0x03010000,0x03060000] [id=2732]

          VM state:not at safepoint (normal execution)

          VM Mutex/Monitor currently owned by a thread: None

          Heap
          def new generation total 960K, used 839K [0x22bc0000, 0x22cc0000, 0x230a0000)
          eden space 896K, 86% used [0x22bc0000, 0x22c81f00, 0x22ca0000)
          from space 64K, 100% used [0x22ca0000, 0x22cb0000, 0x22cb0000)
          to space 64K, 0% used [0x22cb0000, 0x22cb0000, 0x22cc0000)
          tenured generation total 4096K, used 491K [0x230a0000, 0x234a0000, 0x26bc0000)
          the space 4096K, 11% used [0x230a0000, 0x2311ac78, 0x2311ae00, 0x234a0000)
          compacting perm gen total 12288K, used 2276K [0x26bc0000, 0x277c0000, 0x2abc0000)
          the space 12288K, 18% used [0x26bc0000, 0x26df9250, 0x26df9400, 0x277c0000)
          ro space 8192K, 63% used [0x2abc0000, 0x2b0d8b20, 0x2b0d8c00, 0x2b3c0000)
          rw space 12288K, 53% used [0x2b3c0000, 0x2ba35138, 0x2ba35200, 0x2bfc0000)

          Dynamic libraries:
          0x00400000 - 0x00424000 C:\Program Files\Java\jre6\bin\java.exe
          0x7c900000 - 0x7c9b2000 C:\WINDOWS\system32\ntdll.dll
          0x7c800000 - 0x7c8f6000 C:\WINDOWS\system32\kernel32.dll
          0x77dd0000 - 0x77e6b000 C:\WINDOWS\system32\ADVAPI32.dll
          0x77e70000 - 0x77f02000 C:\WINDOWS\system32\RPCRT4.dll
          0x77fe0000 - 0x77ff1000 C:\WINDOWS\system32\Secur32.dll
          0x5cb70000 - 0x5cb96000 C:\WINDOWS\system32\ShimEng.dll
          0x71590000 - 0x71609000 C:\WINDOWS\AppPatch\AcLayers.DLL
          0x7e410000 - 0x7e4a1000 C:\WINDOWS\system32\USER32.dll
          0x77f10000 - 0x77f59000 C:\WINDOWS\system32\GDI32.dll
          0x7c9c0000 - 0x7d1d7000 C:\WINDOWS\system32\SHELL32.dll
          0x77c10000 - 0x77c68000 C:\WINDOWS\system32\msvcrt.dll
          0x77f60000 - 0x77fd6000 C:\WINDOWS\system32\SHLWAPI.dll
          0x774e0000 - 0x7761d000 C:\WINDOWS\system32\ole32.dll
          0x769c0000 - 0x76a74000 C:\WINDOWS\system32\USERENV.dll
          0x73000000 - 0x73026000 C:\WINDOWS\system32\WINSPOOL.DRV
          0x76390000 - 0x763ad000 C:\WINDOWS\system32\IMM32.DLL
          0x773d0000 - 0x774d3000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
          0x76bf0000 - 0x76bfb000 C:\WINDOWS\system32\psapi.dll
          0x3d930000 - 0x3da01000 C:\WINDOWS\system32\wininet.dll
          0x003e0000 - 0x003e9000 C:\WINDOWS\system32\Normaliz.dll
          0x3dfd0000 - 0x3e015000 C:\WINDOWS\system32\iertutil.dll
          0x71ab0000 - 0x71ac7000 C:\WINDOWS\system32\ws2_32.dll
          0x71aa0000 - 0x71aa8000 C:\WINDOWS\system32\WS2HELP.dll
          0x71ad0000 - 0x71ad9000 C:\WINDOWS\system32\wsock32.dll
          0x77a80000 - 0x77b15000 C:\WINDOWS\system32\crypt32.dll
          0x77b20000 - 0x77b32000 C:\WINDOWS\system32\MSASN1.dll
          0x77c00000 - 0x77c08000 C:\WINDOWS\system32\VERSION.dll
          0x5b860000 - 0x5b8b5000 C:\WINDOWS\system32\netapi32.dll
          0x68000000 - 0x68036000 C:\WINDOWS\system32\rsaenh.dll
          0x7c340000 - 0x7c396000 C:\Program Files\Java\jre6\bin\msvcr71.dll
          0x6d800000 - 0x6da8b000 C:\Program Files\Java\jre6\bin\client\jvm.dll
          0x76b40000 - 0x76b6d000 C:\WINDOWS\system32\WINMM.dll
          0x6d7b0000 - 0x6d7bc000 C:\Program Files\Java\jre6\bin\verify.dll
          0x6d330000 - 0x6d34f000 C:\Program Files\Java\jre6\bin\java.dll
          0x6d290000 - 0x6d298000 C:\Program Files\Java\jre6\bin\hpi.dll
          0x6d7f0000 - 0x6d7ff000 C:\Program Files\Java\jre6\bin\zip.dll
          0x6d430000 - 0x6d436000 C:\Program Files\Java\jre6\bin\jp2native.dll
          0x6d1d0000 - 0x6d1e3000 C:\Program Files\Java\jre6\bin\deploy.dll
          0x77120000 - 0x771ab000 C:\WINDOWS\system32\OLEAUT32.dll
          0x78130000 - 0x78258000 C:\WINDOWS\system32\urlmon.dll
          0x6d6b0000 - 0x6d6f3000 C:\Program Files\Java\jre6\bin\regutils.dll
          0x7d1e0000 - 0x7d49c000 C:\WINDOWS\system32\msi.dll
          0x6d610000 - 0x6d623000 C:\Program Files\Java\jre6\bin\net.dll
          0x6d630000 - 0x6d639000 C:\Program Files\Java\jre6\bin\nio.dll
          0x6d000000 - 0x6d14a000 C:\Program Files\Java\jre6\bin\awt.dll
          0x5ad70000 - 0x5ada8000 C:\WINDOWS\system32\uxtheme.dll
          0x74720000 - 0x7476c000 C:\WINDOWS\system32\MSCTF.dll
          0x77b40000 - 0x77b62000 C:\WINDOWS\system32\apphelp.dll
          0x755c0000 - 0x755ee000 C:\WINDOWS\system32\msctfime.ime
          0x6d230000 - 0x6d284000 C:\Program Files\Java\jre6\bin\fontmanager.dll
          0x71a50000 - 0x71a8f000 C:\WINDOWS\system32\mswsock.dll
          0x662b0000 - 0x66308000 C:\WINDOWS\system32\hnetcfg.dll
          0x71a90000 - 0x71a98000 C:\WINDOWS\System32\wshtcpip.dll

          VM Arguments:
          jvm_args: -D__jvm_launched=36107607242 -Xbootclasspath/a:C:\PROGRA~1\Java\jre6\lib\deploy.jar;C:\PROGRA~1\Java\jre6\lib\javaws.jar;C:\PROGRA~1\Java\jre6\lib\plugin.jar
          java_command: sun.plugin2.main.client.PluginMain write_pipe_name=jpi2_pid2896_pipe6,read_pipe_name=jpi2_pid2896_pipe5
          Launcher Type: SUN_STANDARD

          Environment Variables:
          PATH=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\adabas\bin;C:\adabas\pgm;C:\Program Files\Common Files\Teleca Shared;C:\Program Files\QuickTime\QTSystem\;C:\adabas\bin;C:\adabas\pgm
          USERNAME=Nathan
          OS=Windows_NT
          PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel



          --------------- S Y S T E M ---------------

          OS: Windows XP Build 2600 Service Pack 3

          CPU:total 1 (1 cores per cpu, 1 threads per core) family 6 model 13 stepping 8, cmov, cx8, fxsr, mmx, sse, sse2

          Memory: 4k page, physical 1039408k(414428k free), swap 2499048k(1873708k free)

          vm_info: Java HotSpot(TM) Client VM (14.3-b01) for windows-x86 JRE (1.6.0_17-b04), built on Oct 11 2009 00:52:06 by "java_re" with MS VC++ 7.1

          time: Mon Apr 05 00:59:23 2010
          elapsed time: 4 seconds



          Please visit this webpage for a tutorial on downloading and running ComboFix:

          http://www.bleepingcomputer.com/combofix/how-to-use-combofix

          See the area: Using ComboFix, and when done, post the log back here.boFix 10-04-05.06 - Nathan 06/04/2010 19:40:58.1.1 - x86
          Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1015.684 [GMT 0:00]
          Running from: c:\documents and settings\Nathan\Desktop\ComboFix.exe
          AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
          * Created a new restore point
          * Resident AV is active


          WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
          .

          ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
          .

          c:\docume~1\Nathan\LOCALS~1\Temp\tmp2.tmp
          c:\recycler\S-1-5-21-2226665520-4189811108-2719964761-1003
          c:\recycler\S-1-5-21-3504028335-655725818-2494886574-1003
          c:\recycler\S-1-5-21-4193448610-1243597163-2470444081-1003
          c:\recycler\S-1-5-21-839522115-1383384898-527237240-1003
          c:\windows\run.log
          c:\windows\system32\lowsec
          c:\windows\system32\lowsec\local.ds
          c:\windows\system32\lowsec\user.ds
          c:\windows\system32\lowsec\user.ds.lll
          c:\windows\system32\sdra64.exe
          c:\windows\system32\Thumbs.db

          .
          ((((((((((((((((((((((((( Files Created from 2010-03-06 to 2010-04-06 )))))))))))))))))))))))))))))))
          .

          2010-04-05 19:19 . 2010-04-05 21:33--------d-----w-c:\documents and settings\All Users\Application Data\RegCure
          2010-04-05 19:19 . 2010-04-05 21:31--------d-----w-c:\program files\RegCure
          2010-04-04 23:48 . 2010-04-05 21:18--------d-----w-c:\documents and settings\All Users\Application Data\NOS
          2010-04-04 23:48 . 2010-04-04 23:48--------d-----w-c:\program files\NOS
          2010-03-13 21:52 . 2010-03-13 21:52152576----a-w-c:\documents and settings\Nathan\Application Data\Sun\Java\jre1.6.0_17\lzma.dll

          .
          (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2010-04-06 19:15 . 2009-02-03 18:22--------d-----w-c:\documents and settings\Nathan\Application Data\StarOffice8
          2010-04-05 22:12 . 2009-03-05 04:52--------d-----w-c:\program files\SeekeenSrch
          2010-04-05 21:42 . 2009-03-05 04:52--------d-----w-c:\documents and settings\All Users\Application Data\SeekeenSrch
          2010-04-04 14:50 . 2009-02-03 18:256952----a-w-c:\documents and settings\Nathan\Application Data\wklnhst.dat
          2010-04-04 14:41 . 2009-02-10 20:33--------d-----w-c:\documents and settings\Nathan\Application Data\Teleca
          2010-04-04 14:40 . 2009-02-10 20:29--------d-----w-c:\program files\Common Files\Teleca Shared
          2010-03-17 00:41 . 2009-02-10 19:29--------d-----w-c:\documents and settings\Nathan\Application Data\LimeWire
          2010-03-13 21:54 . 2008-07-05 02:39--------d-----w-c:\program files\Java
          2010-03-13 21:52 . 2009-11-11 00:3679488----a-w-c:\documents and settings\Nathan\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
          2010-03-11 12:38 . 2008-07-03 04:32832512----a-w-c:\windows\system32\wininet.dll
          2010-03-11 12:38 . 2008-07-03 04:3178336----a-w-c:\windows\system32\ieencode.dll
          2010-03-11 12:38 . 2008-07-03 04:3117408----a-w-c:\windows\system32\corpol.dll
          2010-02-12 10:03 . 2010-02-25 15:00293376------w-c:\windows\system32\browserchoice.exe
          2008-05-07 08:34 . 2008-07-05 02:5515523560----a-w-c:\program files\U1 Setup.exe
          .

          ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* empty entries & legit default entries are not shown
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 104984]
          "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 121368]
          "Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 100888]
          "AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-06-03 98304]
          "AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-06-03 479232]
          "AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
          "RTHDCPL"="RTHDCPL.EXE" [2008-07-16 16806400]
          "ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-07-23 335872]
          "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
          "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
          "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
          "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
          "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-10-07 1461080]

          c:\documents and settings\Nathan\Start Menu\Programs\Startup\
          StarOffice 8.lnk - c:\program files\Sun\StarOffice 8\program\quickstart.exe [2007-8-18 122880]

          c:\documents and settings\All Users\Start Menu\Programs\Startup\
          SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-7-5 303104]

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
          2007-10-11 02:5139792----a-w-c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
          2008-06-19 08:2057344----a-w-c:\windows\Alcmtr.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
          2008-06-19 08:422808832----a-w-c:\windows\alcwzrd.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
          2009-07-26 16:443883856----a-w-c:\program files\Windows Live\Messenger\msnmsgr.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
          2008-06-18 10:0177824----a-w-c:\windows\SoundMan.exe

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "%windir%\\system32\\sessmgr.exe"=
          "c:\\Program Files\\Messenger\\msmsgs.exe"=
          "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
          "c:\\Program Files\\iTunes\\iTunes.exe"=
          "c:\\Program Files\\LimeWire\\LimeWire.exe"=
          "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

          R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [13/03/2008 21:52 35168]
          R2 EKRN;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [07/10/2009 09:16 472280]
          S1 driubrsb;driubrsb;\??\c:\windows\system32\drivers\driubrsb.sys --> c:\windows\system32\drivers\driubrsb.sys [?]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          getPlusHelperREG_MULTI_SZ getPlusHelper
          .
          Contents of the 'Scheduled Tasks' folder

          2010-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job
          - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

          2010-04-05 c:\windows\Tasks\RegCure Program Check.job
          - c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]

          2010-04-06 c:\windows\Tasks\RegCure Startup.job
          - c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]

          2010-04-05 c:\windows\Tasks\RegCure.job
          - c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]
          .
          .
          ------- Supplementary Scan -------
          .
          uStart Page = hxxp://www.facebook.com/
          uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global
          uInternet Settings,ProxyOverride = *.local
          .
          - - - - ORPHANS REMOVED - - - -

          WebBrowser-{D0523BB4-21E7-11DD-9AB7-415B56D89593} - (no file)



          **************************************************************************

          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2010-04-06 19:47
          Windows 5.1.2600 Service Pack 3 NTFS

          scanning hidden processes ...

          scanning hidden autostart entries ...

          scanning hidden files ...

          scan completed successfully
          hidden files: 0

          **************************************************************************
          .
          Completion time: 2010-04-06 19:50:09
          ComboFix-quarantined-files.txt 2010-04-06 19:49

          Pre-Run: 28,739,575,808 bytes free
          Post-Run: 30,070,956,032 bytes free

          - - End Of File - - CA2EDE311A4535339C36392BCBDED7EA





          That was scary :-sThere is a dangerous backdoor trojan on your system. This is a sign of total system compromise.
          Backdoor trojans are very dangerous because they compromise system integrity by making changes that allow it to by used by the attacker for malicious purposes. Remote attackers use backdoors as a means of accessing and taking control of a computer that bypasses security mechanisms. This type of exploit allows them to steal SENSITIVE information like passwords, personal and financial data which is send back to the hacker. To learn more about these types of infections, you can refer to: http://www.viruslist.com/en/viruses/glossary?glossid=189208417
          I would counsel you to immediately disconnect this PC from the Internet and from your network if it is on a network. Disconnect the infected computer until the computer can be cleaned.
          Then, access this information from a non-compromised computer to follow the steps needed.
          If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable. Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information. (If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.) Banking and credit card institutions should be notified to apprise them of your situation (possible security breach). To protect your information that may have been compromised, I recommend reading these references:
          [/color]
          Though the backdoor has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired so you can never be sure that you have completely removed a backdoor trojan. The malware may leave so many remnants behind that security tools cannot find them. Tools that claim to be able to remove backdoor trojans cannot guarantee that all traces of it will be removed. Many experts in the security community believe that once infected with such a piece of malware, the best course of action would be a reformat and clean reinstall of the OS. This is something I don't like to recommend normally, but in most cases it is the best solution for your safety. Making this decision is based on what the computer is used for, and what information can be accessed from it. For more information, please read these references very carefully:
          GUIDES for format and reinstall: http://www.geekpolice.net/tutorials-guides-f13/how-to-reformat-and-reinstall-your-operating-system-t15119.htm#95115

          http://www.helpmyos.com/tutorials-software-alternatives-to-proprietary-f19/how-to-reformat-and-reinstall-your-operating-system-the-easy-way-t1307.htm#3143
          However, if you do not have the resources to reinstall your computer's OS and would like me to attempt to clean it, I will be happy to do so. But please consider carefully before deciding against a reformat.
          If you do make that decision, I will do my best to help you clean the computer of any infections, but you must understand that once a machine has been taken over by this type of malware, I cannot guarantee that it will be 100% secure even after disinfection or that the removal will be successful.

          Please let me KNOW what you have decided to do in your next post. Should you have any questions, please feel free to ask.
          148.

          Solve : Possible malware; unable to enable firewall, system errors, etc. . .?

          Answer»

          Hello! Thank you for all the work you guys do to help us; I really appreciate it!

          I was given a Sony Vaio running Windows Vista secondhand from a family member to clean up. They suspected that it had viruses, and after checking it out for a few days, I also believe that this is the case.

          Some examples of what is wrong:

          -Windows Defender is disabled, and nothing I do changes that. Every time I try to enable/open it, an error message pops up instead. In addition, I seem to be unable to use other firewalls, leaving this computer vulnerable.

          -Programs are slow, and opening things takes ages

          - I got a blue error screen the first time I tried to run the DDS scan that said "win32k.sys shutdown." After I restarted the computer, Microsoft Security Essentials had stopped working, and I had to GO and re-enable that.

          Before requesting help on this FORUM, I did the Hijack This steps--followed the instructions on this website, as well as used the diagnostic tool for the log, and subsequently fixed the errors listed. Log available upon request . . . I also followed the steps required before asking help here.

          Thank you for any help provided!

          Here are the four (4) logs requested:

          SAS:

          SUPERAntiSpyware Scan Log
          http://www.superantispyware.com

          Generated 06/06/2012 at 06:57 PM

          Application VERSION : 5.0.1150

          Core Rules Database Version : 8696
          Trace Rules Database Version: 6508

          Scan type : Complete Scan
          Total Scan Time : 01:14:34

          Operating System Information
          Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
          UAC On - Limited User (Administrator User)

          Memory items scanned : 626
          Memory threats detected : 0
          Registry items scanned : 33675
          Registry threats detected : 78
          File items scanned : 29918
          File threats detected : 5

          PUP.MyWebSearch/FunWebProducts
          HKLM\SOFTWARE\Fun Web Products
          HKLM\SOFTWARE\Fun Web Products#JpegConversionLib
          HKLM\SOFTWARE\Fun Web Products\MSNMessenger
          HKLM\SOFTWARE\Fun Web Products\MSNMessenger#DLLFile
          HKLM\SOFTWARE\Fun Web Products\MSNMessenger#DLLDir
          HKLM\SOFTWARE\Fun Web Products\ScreenSaver
          HKLM\SOFTWARE\Fun Web Products\ScreenSaver#ImagesDir
          HKLM\SOFTWARE\Fun Web Products\Settings
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextNone.numActive
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextNone.0
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyFreqNone
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextUninstalled.numActive
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextUninstalled.0
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyFreqUninstalled
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.numActive
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.1
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.2
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.3
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.4
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.5
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.6
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.7
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.numActive2
          HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.8
          HKU\S-1-5-21-1527495172-1149829277-2661899657-1002\SOFTWARE\MyWebSearch
          HKLM\SOFTWARE\MyWebSearch
          HKLM\SOFTWARE\MyWebSearch\bar
          HKLM\SOFTWARE\MyWebSearch\bar#pid
          HKLM\SOFTWARE\MyWebSearch\bar#fwp
          HKLM\SOFTWARE\MyWebSearch\bar#tiec
          HKLM\SOFTWARE\MyWebSearch\bar#Dir
          HKLM\SOFTWARE\MyWebSearch\bar#UninstallString
          HKLM\SOFTWARE\MyWebSearch\bar#PluginPath
          HKLM\SOFTWARE\MyWebSearch\bar#RegHookPath
          HKLM\SOFTWARE\MyWebSearch\bar#Id
          HKLM\SOFTWARE\MyWebSearch\bar#CurInstall
          HKLM\SOFTWARE\MyWebSearch\bar#SettingsDir
          HKLM\SOFTWARE\MyWebSearch\bar#sr
          HKLM\SOFTWARE\MyWebSearch\bar#pl
          HKLM\SOFTWARE\MyWebSearch\bar#HistoryDir
          HKLM\SOFTWARE\MyWebSearch\bar#t
          HKLM\SOFTWARE\MyWebSearch\SearchAssistant
          HKLM\SOFTWARE\MyWebSearch\SearchAssistant#pid
          HKLM\SOFTWARE\MyWebSearch\SearchAssistant#fwp
          HKLM\SOFTWARE\MyWebSearch\SearchAssistant#esh
          HKLM\SOFTWARE\MyWebSearch\SearchAssistant#lsp
          HKLM\SOFTWARE\MyWebSearch\SkinTools
          HKLM\SOFTWARE\MyWebSearch\SkinTools#PlayerPath
          HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}
          HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}\TreatAs
          HKLM\Software\FocusInteractive
          HKLM\Software\FocusInteractive\bar
          HKLM\Software\FocusInteractive\bar\Switches
          HKLM\Software\FocusInteractive\bar\Switches#ok
          HKLM\Software\FocusInteractive\bar\Switches#od
          HKLM\Software\FocusInteractive\bar\Switches#nk
          HKLM\Software\FocusInteractive\bar\Switches#nd
          HKLM\Software\FocusInteractive\bar\Switches#incmail.exe
          HKLM\Software\FocusInteractive\bar\Switches#msimn.exe
          HKLM\Software\FocusInteractive\bar\Switches#msn.exe
          HKLM\Software\FocusInteractive\bar\Switches#outlook.exe
          HKLM\Software\FocusInteractive\bar\Switches#waol.exe
          HKLM\Software\FocusInteractive\bar\Switches#aim.exe
          HKLM\Software\FocusInteractive\bar\Switches#icq.exe
          HKLM\Software\FocusInteractive\bar\Switches#icqlite.exe
          HKLM\Software\FocusInteractive\bar\Switches#msmsgs.exe
          HKLM\Software\FocusInteractive\bar\Switches#msnmsgr.exe
          HKLM\Software\FocusInteractive\bar\Switches#ypager.exe
          HKLM\Software\FocusInteractive\bar\Switches#mwsSrcAs.dll
          HKLM\Software\FocusInteractive\bar\Switches#ua
          HKLM\Software\FocusInteractive\bar\Switches#au
          HKLM\Software\FocusInteractive\bar\Switches#nodns
          HKLM\Software\FocusInteractive\Email-IM
          HKLM\Software\FocusInteractive\Email-IM\0
          HKLM\Software\FocusInteractive\Email-IM\0#Toolbar
          HKLM\Software\FocusInteractive\Email-IM\0#AppName
          HKLM\Software\FocusInteractive\Outlook
          C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
          C:\Program Files\MyWebSearch\bar\Settings
          C:\Program Files\MyWebSearch\bar
          C:\Program Files\MyWebSearch

          PUP.MyWebSearch-Installer
          C:\USERS\MY VAIO\APPDATA\LOCALLOW\FUNWEBPRODUCTS\INSTALLR\CACHE\0FB503E8.EXE

          MBAM:


          Malwarebytes Anti-Malware 1.61.0.1400
          www.malwarebytes.org

          Database version: v2012.06.07.01

          Windows Vista Service Pack 2 x86 NTFS
          Internet Explorer 9.0.8112.16421
          My Vaio :: MYVAIO-PC [administrator]

          6/6/2012 7:51:59 PM
          mbam-log-2012-06-06 (19-51-59).txt

          Scan type: Quick scan
          Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
          Scan options disabled: P2P
          Objects scanned: 188231
          Time elapsed: 8 minute(s), 13 second(s)

          Memory Processes Detected: 0
          (No malicious items detected)

          Memory Modules Detected: 0
          (No malicious items detected)

          Registry Keys Detected: 13
          HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
          HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
          HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
          HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

          Registry Values Detected: 0
          (No malicious items detected)

          Registry Data Items Detected: 1
          HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.

          Folders Detected: 0
          (No malicious items detected)

          Files Detected: 0
          (No malicious items detected)

          (end)

          DDS - DDS.txt:

          .
          DDS (Ver_2011-08-26.01) - NTFSx86
          Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.4.1
          Run by My Vaio at 20:26:57 on 2012-06-06
          Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1014.230 [GMT -7:00]
          .
          AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
          SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
          .
          ============== Running Processes ===============
          .
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe -k DcomLaunch
          C:\Windows\system32\svchost.exe -k rpcss
          c:\Program Files\Microsoft Security Client\MsMpEng.exe
          C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
          C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
          C:\Windows\system32\svchost.exe -k netsvcs
          C:\Windows\system32\svchost.exe -k GPSvcGroup
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe -k LocalService
          C:\Windows\system32\svchost.exe -k NetworkService
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
          C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
          C:\Program Files\Sony\Network Utility\NSUService.exe
          C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
          C:\Windows\system32\svchost.exe -k imgsvc
          C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
          C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
          C:\Windows\System32\svchost.exe -k WerSvcGroup
          C:\Windows\system32\DRIVERS\xaudio.exe
          C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
          C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
          C:\Windows\system32\igfxext.exe
          C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Windows\system32\WUDFHost.exe
          C:\Windows\system32\igfxext.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\Browny02\Brother\BrStMonW.exe
          C:\Program Files\Sony\ISB Utility\ISBMgr.exe
          C:\Program Files\Apoint\Apoint.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\Microsoft Security Client\msseces.exe
          C:\Program Files\Common Files\Java\Java Update\jusched.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
          C:\Program Files\Windows Media Player\wmpnetwk.exe
          C:\Program Files\Browny02\BrYNSvc.exe
          C:\Program Files\Apoint\ApMsgFwd.exe
          C:\Program Files\Apoint\Apntex.exe
          C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
          C:\Windows\System32\mobsync.exe
          C:\Windows\system32\SearchProtocolHost.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Windows\system32\DllHost.exe
          C:\Windows\system32\DllHost.exe
          .
          ============== Pseudo HJT Report ===============
          .
          uStart Page = hxxp://www.yahoo.com/
          uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie9
          uWindow Title = Windows Internet Explorer provided by Yahoo!
          mDefault_Page_URL = hxxp://www.sony.com/vaiopeople
          uURLSearchHooks: H - No File
          BHO: MRI_DISABLED - No File
          BHO: AOL Toolbar Launcher - No File
          BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
          BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
          BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
          BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
          BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
          BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
          TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
          TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
          EB: MRI_DISABLED - No File
          EB: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - No File
          uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
          uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
          mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
          mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
          mRun: [Persistence] c:\windows\system32\igfxpers.exe
          mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
          mRun: [BrStsMon00] c:\program files\browny02\brother\BrStMonW.exe /AUTORUN
          mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
          mRun: [RtHDVCpl] RtHDVCpl.exe
          mRun: [Skytel] Skytel.exe
          mRun: [ISBMgr.exe] "c:\program files\sony\isb utility\ISBMgr.exe"
          mRun: [Apoint] c:\program files\apoint\Apoint.exe
          mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
          mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
          StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\ADOBEA~1.LNK -
          StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\adobea~2.lnk - c:\program files\adobe\acrobat 8.0\acrobat\AdobeCollabSync.exe
          StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\aolddi~1.lnk - c:\ddi\AOLICON.exe
          StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
          uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
          mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
          mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
          IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
          IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2iexp.dll
          TCP: DhcpNameServer = 192.168.1.254
          TCP: Interfaces\{DE4E9A12-F75D-4D38-8479-C7A118F31CFB} : DhcpNameServer = 192.168.1.254
          TCP: Interfaces\{E2BE8A7A-3EA8-48F8-98EF-4C835DD6505D} : DhcpNameServer = 192.168.1.254
          Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
          Notify: igfxcui - igfxdev.dll
          Notify: VESWinlogon - VESWinlogon.dll
          SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
          mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
          .
          ================= FIREFOX ===================
          .
          FF - ProfilePath - c:\users\my vaio\appdata\roaming\mozilla\firefox\profiles\mv2ijqfw.default\
          FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
          FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
          FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
          FF - plugin: c:\windows\system32\npDeployJava1.dll
          FF - plugin: c:\windows\system32\npmproxy.dll
          .
          ============= SERVICES / DRIVERS ===============
          .
          R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
          R1 MpKsl1c2e434e;MpKsl1c2e434e;c:\programdata\microsoft\microsoft antimalware\definition updates\{b0e1fb93-4b21-48a2-9603-58c6043194a6}\MpKsl1c2e434e.sys [2012-6-6 29904]
          R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
          R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
          R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\drivers\RTL8192su.sys [2010-7-8 541800]
          R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-8-26 812544]
          R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2011-4-15 16896]
          S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 74112]
          .
          =============== Created Last 30 ================
          .
          2012-06-07 03:11:15--------d-----w-c:\program files\Oracle
          2012-06-07 03:10:30772504----a-w-c:\windows\system32\npDeployJava1.dll
          2012-06-07 03:10:30687504----a-w-c:\windows\system32\deployJava1.dll
          2012-06-07 02:37:1056200----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{b0e1fb93-4b21-48a2-9603-58c6043194a6}\offreg.dll
          2012-06-07 02:37:0929904----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{b0e1fb93-4b21-48a2-9603-58c6043194a6}\MpKsl1c2e434e.sys
          2012-06-07 02:29:10713784----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{608411dd-9a92-4505-a97f-f8d9242d4bba}\gapaengine.dll
          2012-06-07 02:28:156737808----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{b0e1fb93-4b21-48a2-9603-58c6043194a6}\mpengine.dll
          2012-06-07 02:00:55--------d-----w-C:\e58248bec90ebb26dd38ac608d45
          2012-06-07 01:35:41--------d-----w-c:\program files\Microsoft Security Client
          2012-06-07 01:33:44221568----a-w-c:\windows\system32\drivers\netio.sys
          2012-06-07 00:39:25--------d-----w-c:\users\my vaio\appdata\roaming\Malwarebytes
          2012-06-07 00:39:05--------d-----w-c:\programdata\Malwarebytes
          2012-06-07 00:39:0422344----a-w-c:\windows\system32\drivers\mbam.sys
          2012-06-07 00:39:04--------d-----w-c:\program files\Malwarebytes' Anti-Malware
          2012-06-07 00:37:53--------d-----w-c:\users\my vaio\appdata\roaming\SUPERAntiSpyware.com
          2012-06-07 00:37:27--------d-----w-c:\programdata\SUPERAntiSpyware.com
          2012-06-07 00:37:27--------d-----w-c:\program files\SUPERAntiSpyware
          2012-06-07 00:18:25--------d-----w-c:\program files\CCleaner
          2012-06-06 23:55:02--------d-----w-c:\windows\Intuit
          2012-06-06 23:25:30--------d-----w-c:\users\my vaio\appdata\local\Seven Zip
          2012-06-06 22:56:146737808----a-w-c:\programdata\microsoft\windows defender\definition updates\{6e392898-1e44-4d99-b73d-ebc292850a86}\mpengine.dll
          2012-05-30 06:39:48--------d-----w-C:\f36b42cdd04982006cf6afa5
          2012-05-14 06:52:4453120----a-w-c:\windows\system32\drivers\partmgr.sys
          2012-05-14 06:51:23914304----a-w-c:\windows\system32\drivers\tcpip.sys
          2012-05-14 06:51:2231232----a-w-c:\windows\system32\drivers\tcpipreg.sys
          2012-05-14 06:51:191218048----a-w-c:\program files\windows journal\NBDoc.DLL
          2012-05-14 06:51:18964608----a-w-c:\program files\windows journal\JNWDRV.dll
          2012-05-14 06:51:181404928----a-w-c:\program files\common files\microsoft shared\ink\InkObj.dll
          2012-05-14 06:51:17983040----a-w-c:\program files\windows journal\JNTFiltr.dll
          2012-05-14 06:51:17936960----a-w-c:\program files\common files\microsoft shared\ink\journal.dll
          2012-05-14 06:51:1647104----a-w-c:\program files\windows journal\PDIALOG.exe
          2012-05-14 06:50:241069056----a-w-c:\windows\system32\DWrite.dll
          2012-05-14 06:50:23683008----a-w-c:\windows\system32\d2d1.dll
          2012-05-14 06:50:23219648----a-w-c:\windows\system32\d3d10_1core.dll
          2012-05-14 06:50:23160768----a-w-c:\windows\system32\d3d10_1.dll
          2012-05-14 06:50:231172480----a-w-c:\windows\system32\d3d10warp.dll
          2012-05-14 05:42:463550080----a-w-c:\windows\system32\ntoskrnl.exe
          2012-05-14 05:42:453602816----a-w-c:\windows\system32\ntkrnlpa.exe
          2012-05-14 05:42:452044928----a-w-c:\windows\system32\win32k.sys
          .
          ==================== Find3M ====================
          .
          2012-05-05 09:18:1170304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
          2012-05-05 09:18:11419488----a-w-c:\windows\system32\FlashPlayerApp.exe
          2012-05-05 09:17:444126880----a-w-c:\windows\system32\FlashPlayerInstaller.exe
          2012-03-26 21:04:16724992----a-w-c:\windows\iun6002.exe
          2012-03-21 03:44:1274112----a-w-c:\windows\system32\drivers\NisDrvWFP.sys
          2012-03-21 03:44:12171064----a-w-c:\windows\system32\drivers\MpFilter.sys
          .
          ============= FINISH: 20:28:52.13 ===============

          DDS - Attach.txt:

          .
          UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
          IF REQUESTED, ZIP IT UP & ATTACH IT
          .
          DDS (Ver_2011-08-26.01)
          .
          Microsoft® Windows Vista™ Home Premium
          Boot Device: \Device\HarddiskVolume2
          Install Date: 4/16/2011 12:18:48 PM
          System Uptime: 6/6/2012 8:18:32 PM (0 hours ago)
          .
          Motherboard: Sony Corporation | | VAIO
          Processor: Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz | N/A | 1467/133mhz
          .
          ==== Disk Partitions =========================
          .
          C: is FIXED (NTFS) - 142 GiB total, 106.557 GiB free.
          D: is Removable
          E: is Removable
          F: is CDROM ()
          G: is Removable
          .
          ==== Disabled Device Manager Items =============
          .
          Class GUID:
          Description: BlackBerry
          Device ID: USB\VID_0FCA&PID_8004&MI_00\6&376D0E18&0&0000
          Manufacturer:
          Name: BlackBerry
          PNP Device ID: USB\VID_0FCA&PID_8004&MI_00\6&376D0E18&0&0000
          Service:
          .
          ==== System Restore Points ===================
          .
          .
          ==== Installed Programs ======================
          .
          .
          ABBYY FineReader 6.0 Sprint
          Adobe AIR
          Adobe Flash Player 10 Plugin
          Adobe Flash Player 11 ActiveX
          Adobe Reader X (10.1.3)
          Alps Pointing-device for VAIO
          Belkin USB Wireless Adaptor
          Brother MFL-Pro Suite MFC-J270W
          CCleaner
          Click to DVD 2.0.05 Menu Data
          Click to DVD 2.6.00
          Corel Paint Shop Pro Photo XI
          Corel Snapfire
          HDAUDIO SoftV92 Data Fax Modem with SmartCP
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
          Intel(R) Graphics Media Accelerator Driver
          Java Auto Updater
          Java(TM) 7 Update 4
          Java(TM) SE Runtime Environment 6
          JavaFX 2.1.0
          LocationFree Player
          Malwarebytes Anti-Malware version 1.61.0.1400
          Microsoft .NET Framework 1.1
          Microsoft .NET Framework 1.1 Security Update (KB2656353)
          Microsoft .NET Framework 3.5 SP1
          Microsoft .NET Framework 4 Client Profile
          Microsoft Office PowerPoint Viewer 2007 (English)
          Microsoft Security Client
          Microsoft Security Essentials
          Microsoft Silverlight
          Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
          Microsoft Visual C++ 2005 Redistributable
          Microsoft Works
          Mozilla Firefox 13.0 (x86 en-US)
          Mozilla Maintenance Service
          MSXML 4.0 SP2 (KB927978)
          MSXML 4.0 SP2 (KB954430)
          MSXML 4.0 SP2 (KB973688)
          MSXML 4.0 SP2 Parser and SDK
          OpenMG Limited Patch 4.7-07-15-19-01
          OpenMG Secure Module 4.7.00
          QuickBooks Product Listing Service
          Realtek High Definition Audio Driver
          Roxio Easy Media Creator Home
          Security Update for CAPICOM (KB931906)
          Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
          Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
          Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
          Setting Utility Series
          SonicStage Mastering Studio
          SonicStage Mastering Studio Audio Filter
          SonicStage Mastering Studio Audio Filter Custom Preset
          SonicStage Mastering Studio Plugins
          Sony Video Shared Library
          SUPERAntiSpyware
          SupportSoft Assisted Service
          Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
          Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
          Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
          Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
          VAIO Azure Float Wallpaper
          VAIO Center Access Bar
          VAIO Content Folder Setting
          VAIO Content Importer VAIO Content Exporter
          VAIO Content Importer / VAIO Content Exporter
          VAIO Content Metadata Intelligent Analyzing Manager
          VAIO Content Metadata Manager Setting
          VAIO Content Metadata XML Interface Library
          VAIO Control Center
          VAIO Entertainment Center
          VAIO Entertainment Platform
          VAIO Event Service
          VAIO Floral Dusk Wallpaper
          VAIO Help And Support
          VAIO Launcher
          VAIO Media
          VAIO Media 6.0
          VAIO Media AC3 Decoder 1.0
          VAIO Media Content Collection 6.0
          VAIO Media Integrated Server 6.1
          VAIO Media Redistribution 6.0
          VAIO Media Registration Tool
          VAIO Media Registration Tool 6.0
          VAIO Movie Story
          VAIO Movie Story Template Data
          VAIO MusicBox
          VAIO OOBE and Welcome Center
          VAIO Original Function Setting
          VAIO PC Wireless LAN Wizard
          VAIO Power Management
          VAIO Productivity Center
          VAIO Security Center
          VAIO Service Utility
          VAIO Smart Network
          VAIO Teal Whisper Wallpaper
          VAIO Update 3
          WinDVD for VAIO
          .
          ==== Event Viewer Messages From Past Week ========
          .
          6/6/2012 8:21:24 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
          6/6/2012 8:21:17 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
          6/6/2012 8:21:15 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
          6/6/2012 8:20:58 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
          6/6/2012 8:20:37 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
          6/6/2012 8:20:37 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
          6/6/2012 8:20:37 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
          6/6/2012 8:19:34 PM, Error: EventLog [6008] - The previous system shutdown at 8:16:53 PM on 6/6/2012 was unexpected.
          6/6/2012 6:52:24 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description: The program can't check for definition updates.
          6/6/2012 6:52:24 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description: The program can't check for definition updates.
          6/6/2012 3:43:16 PM, Error: Service Control Manager [7034] - The NSUService service terminated unexpectedly. It has done this 1 time(s).
          6/6/2012 3:42:59 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the lxddCATSCustConnectService service to connect.
          6/6/2012 3:42:59 PM, Error: Service Control Manager [7000] - The lxddCATSCustConnectService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
          6/6/2012 3:41:36 PM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer QuickBooks PDF Converter with shared resource name QuickBooks PDF Converter. Error 2114. The printer cannot be used by others on the network.
          5/30/2012 10:52:13 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the VzCdbSvc service.
          .
          ==== End Of File ===========================




          Can you run HijackThis and post that log please.I don't know if this is related, but the computer would not turn on at all today, and I was prompted to do a start up repair. I did so, and it failed, although the computer eventually turned on after several tries . . . so I'm really unsure if this is a malware issue or a HARDWARE issue.

          Anyways, here is the HijackThis log:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 8:39:24 PM, on 6/6/2012
          Platform: Windows Vista SP2 (WinNT 6.00.1906)
          MSIE: Internet Explorer v9.00 (9.00.8112.16421)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\Browny02\Brother\BrStMonW.exe
          C:\Program Files\Sony\ISB Utility\ISBMgr.exe
          C:\Program Files\Apoint\Apoint.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\Microsoft Security Client\msseces.exe
          C:\Program Files\Common Files\Java\Java Update\jusched.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
          C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
          C:\Program Files\Apoint\ApMsgFwd.exe
          C:\Program Files\Apoint\Apntex.exe
          C:\Windows\System32\mobsync.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
          O1 - Hosts: ::1 localhost
          O2 - BHO: (no name) - MRI_DISABLED - (no file)
          O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
          O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
          O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
          O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
          O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Skytel] Skytel.exe
          O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
          O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
          O4 - Global Startup: MRI_DISABLED
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll
          O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
          O13 - Gopher Prefix:
          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
          O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
          O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
          O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
          O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files\Browny02\BrYNSvc.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
          O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
          O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
          O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
          O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
          O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
          O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
          O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
          O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
          O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
          O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
          O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
          O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
          O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
          O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
          O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
          O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
          O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

          --
          End of file - 9017 bytes
          Open HijackThis and select Do a system scan only

          Place a check mark next to the following entries: (if there)

          R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
          O2 - BHO: (no name) - MRI_DISABLED - (no file)
          O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)


          Important: Close all open windows except for HijackThis and then click Fix checked.

          Once completed, exit HijackThis.

          ----------

          If you already have ComboFix be sure to delete it and download a new copy.

          Download ComboFix© by sUBs from one of the below links. Be sure to save it to the Desktop.

          Link #1
          Link #2

          **Note: It is important that it is saved directly to your Desktop

          Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

          Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

          Double click combofix.exe & follow the prompts.

          When finished ComboFix will produce a log for you.
          Post the ComboFix log in your next reply.

          Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

          Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

          If you have problems with ComboFix usage, see How to use ComboFixAll right, I disabled real time scanning for MSE while using Combofix, and after the fact have since turned it back on.

          Here's the Combofix log:

          ComboFix 12-06-07.03 - My Vaio 06/07/2012 16:02:15.1.2 - x86
          Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1014.305 [GMT -7:00]
          Running from: c:\users\My Vaio\Desktop\ComboFix.exe
          AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
          SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
          SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          .
          .
          ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          c:\programdata\pswi_preloaded.exe
          c:\programdata\SPL3334.tmp
          c:\programdata\SPL69FB.tmp
          .
          .
          ((((((((((((((((((((((((( Files Created from 2012-05-07 to 2012-06-07 )))))))))))))))))))))))))))))))
          .
          .
          2012-06-07 23:13 . 2012-06-07 23:14--------d-----w-c:\users\My Vaio\AppData\Local\temp
          2012-06-07 23:13 . 2012-06-07 23:13--------d-----w-c:\users\Default\AppData\Local\temp
          2012-06-07 03:37 . 2012-06-07 03:37--------d-----w-c:\program files\Trend Micro
          2012-06-07 03:11 . 2012-06-07 03:11--------d-----w-c:\program files\Oracle
          2012-06-07 03:10 . 2012-04-05 01:47772504----a-w-c:\windows\system32\npDeployJava1.dll
          2012-06-07 03:10 . 2012-04-05 01:47687504----a-w-c:\windows\system32\deployJava1.dll
          2012-06-07 02:37 . 2012-06-07 22:5356200----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B0E1FB93-4B21-48A2-9603-58C6043194A6}\offreg.dll
          2012-06-07 02:29 . 2012-02-09 20:17713784----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{608411DD-9A92-4505-A97F-F8D9242D4BBA}\gapaengine.dll
          2012-06-07 02:28 . 2012-05-15 08:436737808----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B0E1FB93-4B21-48A2-9603-58C6043194A6}\mpengine.dll
          2012-06-07 02:00 . 2012-06-07 02:01--------d-----w-C:\e58248bec90ebb26dd38ac608d45
          2012-06-07 01:35 . 2012-06-07 01:39--------d-----w-c:\program files\Microsoft Security Client
          2012-06-07 01:33 . 2010-04-05 20:00221568----a-w-c:\windows\system32\drivers\netio.sys
          2012-06-07 00:39 . 2012-06-07 00:39--------d-----w-c:\users\My Vaio\AppData\Roaming\Malwarebytes
          2012-06-07 00:39 . 2012-06-07 00:39--------d-----w-c:\programdata\Malwarebytes
          2012-06-07 00:39 . 2012-06-07 00:39--------d-----w-c:\program files\Malwarebytes' Anti-Malware
          2012-06-07 00:39 . 2012-04-04 22:5622344----a-w-c:\windows\system32\drivers\mbam.sys
          2012-06-07 00:37 . 2012-06-07 00:37--------d-----w-c:\users\My Vaio\AppData\Roaming\SUPERAntiSpyware.com
          2012-06-07 00:37 . 2012-06-07 00:37--------d-----w-c:\program files\SUPERAntiSpyware
          2012-06-07 00:37 . 2012-06-07 00:37--------d-----w-c:\programdata\SUPERAntiSpyware.com
          2012-06-07 00:31 . 2012-06-07 00:31--------d-----w-c:\users\My Vaio\AppData\Local\Mozilla
          2012-06-07 00:31 . 2012-06-07 00:31--------d-----w-c:\program files\Mozilla Maintenance Service
          2012-06-07 00:18 . 2012-06-07 00:18--------d-----w-c:\program files\CCleaner
          2012-06-06 23:55 . 2012-06-06 23:55--------d-----w-c:\windows\Intuit
          2012-06-06 23:25 . 2012-06-06 23:25--------d-----w-c:\users\My Vaio\AppData\Local\Seven Zip
          2012-06-06 22:56 . 2012-05-08 16:406737808----a-w-c:\programdata\Microsoft\Windows Defender\Definition Updates\{6E392898-1E44-4D99-B73D-EBC292850A86}\mpengine.dll
          2012-05-30 06:39 . 2012-05-30 06:44--------d-----w-C:\f36b42cdd04982006cf6afa5
          2012-05-14 06:52 . 2012-03-20 23:2853120----a-w-c:\windows\system32\drivers\partmgr.sys
          2012-05-14 06:51 . 2012-03-30 12:39914304----a-w-c:\windows\system32\drivers\tcpip.sys
          2012-05-14 06:51 . 2012-03-29 13:3931232----a-w-c:\windows\system32\drivers\tcpipreg.sys
          2012-05-14 06:51 . 2012-02-01 15:111218048----a-w-c:\program files\Windows Journal\NBDoc.DLL
          2012-05-14 06:51 . 2012-02-01 15:10964608----a-w-c:\program files\Windows Journal\JNWDRV.dll
          2012-05-14 06:51 . 2012-02-01 15:101404928----a-w-c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
          2012-05-14 06:51 . 2012-02-01 15:10983040----a-w-c:\program files\Windows Journal\JNTFiltr.dll
          2012-05-14 06:51 . 2012-02-01 15:10936960----a-w-c:\program files\Common Files\Microsoft Shared\ink\journal.dll
          2012-05-14 06:51 . 2012-02-01 13:5847104----a-w-c:\program files\Windows Journal\PDIALOG.exe
          2012-05-14 06:50 . 2012-02-29 13:411069056----a-w-c:\windows\system32\DWrite.dll
          2012-05-14 06:50 . 2012-03-01 14:46219648----a-w-c:\windows\system32\d3d10_1core.dll
          2012-05-14 06:50 . 2012-03-01 14:46160768----a-w-c:\windows\system32\d3d10_1.dll
          2012-05-14 06:50 . 2012-02-29 14:081172480----a-w-c:\windows\system32\d3d10warp.dll
          2012-05-14 06:50 . 2012-02-29 13:44683008----a-w-c:\windows\system32\d2d1.dll
          2012-05-14 05:42 . 2012-04-03 08:163550080----a-w-c:\windows\system32\ntoskrnl.exe
          2012-05-14 05:42 . 2012-04-03 08:163602816----a-w-c:\windows\system32\ntkrnlpa.exe
          2012-05-14 05:42 . 2012-04-02 13:362044928----a-w-c:\windows\system32\win32k.sys
          .
          .
          .
          (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2012-05-05 09:18 . 2012-04-05 18:16419488----a-w-c:\windows\system32\FlashPlayerApp.exe
          2012-05-05 09:18 . 2011-07-01 17:3070304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
          2012-05-05 09:17 . 2012-05-05 09:174126880----a-w-c:\windows\system32\FlashPlayerInstaller.exe
          2012-03-26 21:04 . 2012-03-26 21:05724992----a-w-c:\windows\iun6002.exe
          2012-03-21 03:44 . 2012-03-21 03:4474112----a-w-c:\windows\system32\drivers\NisDrvWFP.sys
          2012-03-21 03:44 . 2012-03-21 03:44171064----a-w-c:\windows\system32\drivers\MpFilter.sys
          2012-06-01 15:40 . 2012-06-07 00:3185472----a-w-c:\program files\mozilla firefox\components\browsercomps.dll
          .
          .
          ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* empty entries & legit default entries are not shown
          REGEDIT4
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AOLOverlayIcon]
          @="{AB0C8BE3-041C-47d6-8195-E089D32B38DD}"
          [HKEY_CLASSES_ROOT\CLSID\{AB0C8BE3-041C-47d6-8195-E089D32B38DD}]
          2007-08-15 16:42303104------w-c:\ddi\OverIcon.dll
          .
          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
          "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-05-21 3905920]
          .
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-29 137752]
          "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-29 154136]
          "Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-29 133656]
          "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
          "BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440]
          "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
          "RtHDVCpl"="RtHDVCpl.exe" [2007-06-25 4489216]
          "Skytel"="Skytel.exe" [2007-06-25 1826816]
          "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-06-12 317560]
          "Apoint"="c:\program files\Apoint\Apoint.exe" [2007-06-08 118784]
          "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-27 931200]
          "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
          .
          c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED
          Adobe Acrobat Speed Launcher.lnk - [N/A]
          Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [N/A]
          AOL DDI.lnk - c:\ddi\AOLICON.exe [N/A]
          QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [N/A]
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
          "EnableUIADesktopToggle"= 0 (0x0)
          .
          [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
          "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
          2011-05-04 17:54551296----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
          2007-07-25 02:2698304----a-w-c:\windows\System32\VESWinlogon.dll
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
          @=""
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
          @="Service"
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe]
          2007-06-12 01:27317560----a-w-c:\program files\Sony\ISB Utility\ISBMgr.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
          2007-06-25 21:414489216----a-w-c:\windows\RtHDVCpl.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
          2007-06-25 21:411826816----a-w-c:\windows\SkyTel.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
          2007-08-26 21:4377824----a-w-c:\program files\Java\jre1.6.0\bin\jusched.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Center Access Bar]
          2007-06-21 23:5453248----a-w-c:\program files\Sony\VAIO Center Access Bar\VCAB.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VWLASU]
          2007-07-12 18:3145056----a-w-c:\program files\Sony\VAIO PC Wireless LAN Wizard\AutoLaunchWLASU.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
          "DisableMonitoring"=dword:00000001
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
          "DisableMonitoring"=dword:00000001
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
          "DisableMonitoring"=dword:00000001
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
          "AntiVirusOverride"=dword:00000001
          .
          R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 253088]
          S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]
          S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
          .
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
          2011-04-16 15:26114176----a-w-c:\windows\System32\advpack.dll
          .
          Contents of the 'Scheduled Tasks' folder
          .
          2012-06-07 c:\windows\Tasks\Adobe Flash Player Updater.job
          - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 10:02]
          .
          .
          ------- Supplementary Scan -------
          .
          uStart Page = hxxp://www.yahoo.com/
          IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
          TCP: DhcpNameServer = 192.168.1.254
          FF - ProfilePath - c:\users\My Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\mv2ijqfw.default\
          .
          - - - - ORPHANS REMOVED - - - -
          .
          MSConfigStartUp-Acrobat Assistant 8 - c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
          MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
          AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\standard_1.exe
          .
          .
          .
          **************************************************************************
          .
          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2012-06-07 16:14
          Windows 6.0.6002 Service Pack 2 NTFS
          .
          scanning hidden processes ...
          .
          scanning hidden autostart entries ...
          .
          scanning hidden files ...
          .
          scan completed successfully
          hidden files: 0
          .
          **************************************************************************
          .
          --------------------- LOCKED REGISTRY KEYS ---------------------
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
          @Denied: (A) (Users)
          @Denied: (A) (Everyone)
          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
          "BlindDial"=dword:00000000
          .
          Completion time: 2012-06-07 16:17:56
          ComboFix-quarantined-files.txt 2012-06-07 23:17
          .
          Pre-Run: 113,740,283,904 bytes free
          Post-Run: 113,367,640,064 bytes free
          .
          - - End Of File - - 43771D24ADC6D8A5A2E861D48C34E210
          * Click START then RUN - Vista/Windows 7 users press the Windows Key and the R keys for the Run box.
          * Now type (or copy/paste) in the runbox:
          Code: [Select]"%userprofile%\Desktop\combofix" /uninstall* Make sure there's a space between Combofix and /Uninstall
          * Then hit Enter

          * The above procedure will remove ComboFix and its associated files and folders.

          ----------

          Clean out your temporary internet files and temp files.

          Download TFC by OldTimer to your desktop.

          Double-click TFC.exe to run it.

          Note: If you are running on Vista, right-click on the file and choose Run As Administrator

          TFC will close all programs when run, so make sure you have saved all your work before you begin.

          * Click the Start button to begin the cleaning process.
          * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
          * Please let TFC run uninterrupted until it is finished.

          Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

          ----------

          ESET Online Scan

          Scan your computer with the ESET FREE Online Virus Scan

          * Click the ESET Online Scanner button.

          * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
          * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
          * Double click on the esetsmartinstaller_enu.exe icon on your desktop.
          * Place a check mark next to YES, I accept the Terms of Use.

          * Click the Start button.
          * Accept any security warnings from your browser.
          * Leave the check mark next to Remove found threats and place a check next to Scan archives.
          * Click the Start button.
          * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
          * When the scan completes, click List of found threats.
          * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
          * Click the <<Back button then click Finish.

          In your next reply please include the ESET Online Scan Log

          Also let me know how the computer is running now.Hello! Sorry for the delay.

          I ran the ESET Online Scan, but I don't know how to get the log. . .? There was no option for me to see a list of threats found, but it found one thing (more of that MyWebSearch variety) and removed it.

          Aside from that, the computer seems to be doing better, although it is still very slow, and freezes for short periods of time quite often.

          I tried to enable Windows Defender again, and the same error popped up. For your reference, the error is: 0x800106ba

          If you have any other suggestions/ideas, I'd love to hear them! All virus scans are turning up without any threats, so if you believe that it is a hardware issue rather than malware, I'll post in the appropriate place.

          And thank you for you help thus far, I really appreciate it!Quote from: Leon Ever on June 08, 2012, 10:05:37 PM


          I tried to enable Windows Defender again, and the same error popped up. For your reference, the error is: 0x800106ba

          You are using Microsoft Security essentials which has Windows Defender built into it so that's why you can not turn it on.

          You might need to defrag your hard drive. You can use the built in Windows defrag by clicking the Start button and then type in disk defragmenter then click on the Disk Defragmenter shortcut. Or use a faster FREE program. Defraggler is very effective and easy to use.

          Important! Be sure to uncheck Install optional Yahoo! Toolbar or Google Chrome during the install process to avoid installing them.

          Note: Be sure to clean out temp files and restart the computer just before beginning a defrag.


          Other than that I believe the computer is malware free.

          Use the Secunia Software Inspector to check for out of date software.

          * Click Start Scanner
          * Check the box next to Enable thorough system inspection.
          * Click Start
          * Allow the scan to finish and scroll down to see if any updates are NEEDED.
          * Update anything listed.

          You can also download and use the Secunia Personal Software Inspector (PSI) which is
          FREE for Home Users. This will allow Secunia to run in real time and alert you to potential security threats from outdated software installed on your computer.

          ----------

          Go to Microsoft Windows Update and get all critical updates.

          ----------

          If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

          ----------

          I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

          I also suggest keeping CCleaner Slim. It is an excellent and safe disk cleaner. Running CCleaner on a daily basis helps to protect your privacy and make your computer faster and more secure.

          I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

          SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
          * Using SpywareBlaster to protect your computer from Spyware and Malware
          * If you don't know what ActiveX controls are, see here

          Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy.
          * Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

          Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

          Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you so much for all of your help! It's much appreciated.Sorry, I posted in the wrong feed.
          149.

          Solve : HiJack This Problem?

          Answer»

          I am in the process of getting rid of VIRUSES on my BUDDY's computer. He has vista and HiJack this V2.0.3
          When I go to click run a system scan and SAVE a log, it comes up with a message saying that the system is DENIED ACCESS to host files.
          It says to run it as an administrator, but the message comes even if you do.
          We tried reinstalling it, but that didn't work what should we do?Please visit this webpage for a tutorial on downloading and running ComboFix:

          http://www.bleepingcomputer.com/combofix/how-to-use-combofix

          See the area: Using ComboFix, and when done, post the log back here.

          150.

          Solve : HiJackThis logfile, anything wrong??

          Answer»

          Just posting a HiJackThis logfile. Nothing is wrong with my PC at all, however, with Internet Explorer 8, it does take a painfully long time to start up (once going, it's FAST). I've SWITCHED to Chrome anyhow. My system specs are: AMD Turion ML-37 1.99Ghz, 2.00 GB RAM, 80GB HD, ATI Radeon Xpress 200M.


          Logfile of Trend Micro HijackThis v2.0.3 (BETA)
          Scan saved at 4:50:12 PM, on 3/12/2010
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 SP3 (8.00.6001.18702)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Microsoft Security Essentials\msseces.exe
          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
          C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Documents and Settings\Matthew\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\Documents and Settings\Matthew\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\Program Files\uTorrent\uTorrent.exe
          C:\WINDOWS\system32\msiexec.exe
          C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
          O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\RunOnce: [IERESETATTRIB] %SystemRoot%\system32\cmd.exe /d /q /c %SystemRoot%\system32\ieudinit.exe -ResetFileAttributes
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Matthew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1268278295551
          O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
          O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
          O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

          --
          End of file - 6342 bytes
          Sorry for the delay, we are BUSY here on the boards. If you are still having issues, please do the following:


          Please download Malwarebytes Anti-Malware from here.

          Double Click mbam-setup.exe to install the application.

          • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
          • If an update is found, it will download and install the latest version.
          • Once the program has loaded, select "Perform Full Scan", then click Scan.
          • The scan may take some time to finish,so please be patient.
          • When the scan is complete, click OK, then Show Results to view the results.
          • Make sure that everything is checked, and click Remove Selected.
          • When disinfection is completed, a log will OPEN in Notepad and you may be prompted to Restart. (See Extra Note)
          • Please save the log to a location you will remember.
          • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
          • Copy and paste the entire report in your next reply.
          Extra Note:

          If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.Due to lack of feedback, this topic is now closed. If you need the topic re-opened, PM a moderator and they shall unlock it.

          =>CLOSED