This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Everything going haywire

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was out of town for a couple of weeks I ran the program you told me to and I can not get my printer to work now or several other programs. This was before combofix. It took 3 times to conect to net. Can we get this stuff off my machine and back to normal. I have attached the list. My first post was 530580. Thanks

ComboFix 09-03-04.01 - carol 2009-03-06 9:05:37.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1918.1015 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-02-06 to 2009-03-06 )))))))))))))))))))))))))))))))
.

2009-03-05 20:03 . 2009-03-05 20:03 d——– c:\program files\Escape Rosecliff Island
2009-03-02 12:14 . 2009-03-02 12:14 d——– c:\users\All Users\Enkord
2009-03-02 12:14 . 2009-03-02 12:14 d——– c:\programdata\Enkord
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\users\carol\AppData\Roaming\Malwarebytes
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\users\All Users\Malwarebytes
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\programdata\Malwarebytes
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-26 23:00 . 2009-02-11 10:19 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-26 23:00 . 2009-02-11 10:19 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-02-22 19:54 . 2008-12-04 23:32 428,544 –a—— c:\windows\System32\EncDec.dll
2009-02-22 19:54 . 2008-12-04 23:32 293,376 –a—— c:\windows\System32\psisdecd.dll
2009-02-22 19:54 . 2008-12-04 23:31 217,088 –a—— c:\windows\System32\psisrndr.ax
2009-02-22 19:54 . 2008-12-04 23:31 177,664 –a—— c:\windows\System32\mpg2splt.ax
2009-02-22 19:54 . 2008-12-04 23:31 80,896 –a—— c:\windows\System32\MSNP.ax
2009-02-20 20:41 . 2009-02-20 20:41 d——– c:\users\All Users\GameHouse
2009-02-20 20:41 . 2009-02-20 20:41 d——– c:\programdata\GameHouse
2009-02-20 19:26 . 2009-02-20 19:27 d——– c:\program files\Little Shop - Memories
2009-02-20 19:25 . 2009-02-20 19:25 d——– c:\program files\Tahiti Hidden Pearls
2009-02-19 19:30 . 2009-02-24 18:35 d——– C:\BigFishGamesCache
2009-02-18 17:34 . 2009-02-18 17:34 d——– c:\users\carol\AppData\Roaming\V-Games
2009-02-13 17:54 . 2009-02-13 18:20 d——– c:\users\carol\AppData\Roaming\gemsweeperextractedgfx
2009-02-13 17:54 . 2009-02-13 17:54 d——– c:\users\All Users\My Games
2009-02-13 17:54 . 2009-02-13 17:54 d——– c:\programdata\My Games
2009-02-11 18:06 . 2009-01-14 22:36 1,383,424 –a—— c:\windows\System32\mshtml.tlb
2009-02-11 18:06 . 2009-01-15 01:11 827,392 –a—— c:\windows\System32\wininet.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-06 14:02 ——— d—a-w c:\programdata\TEMP
2009-03-06 12:36 410,984 —-a-w c:\windows\System32\deploytk.dll
2009-03-06 01:15 ——— d—–w c:\users\carol\AppData\Roaming\SpinTop Games
2009-03-02 22:06 ——— d—–w c:\programdata\WildTangent
2009-03-02 17:10 ——— d—–w c:\program files\eMachines Games
2009-03-01 19:10 ——— d—–w c:\program files\DAP
2009-02-27 23:11 ——— d—–w c:\program files\Liong - The Lost Amulets
2009-02-27 02:32 ——— d—–w c:\users\carol\AppData\Roaming\PlayFirst
2009-02-26 23:35 ——— d—–w c:\program files\PlayFirst
2009-02-19 01:50 ——— d—–w c:\program files\Coupons
2009-02-19 01:27 ——— d—–w c:\program files\Trend Micro
2009-02-15 21:44 ——— d—–w c:\program files\sounds
2009-02-12 08:01 ——— d—–w c:\program files\Windows Mail
2009-02-07 00:32 ——— d—–w c:\program files\Google
2009-02-07 00:19 ——— d—–w c:\programdata\iWin Games
2009-02-04 22:37 ——— d—–w c:\programdata\AdventureChronicles1
2009-02-04 17:24 ——— d—–w c:\program files\Disney Micro
2009-02-04 17:23 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-04 17:23 ——— d—–w c:\program files\DB CIF Cam
2009-02-04 17:21 ——— d—–w c:\program files\Disney Pix Micro Downloader
2009-02-04 17:20 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-04 16:38 ——— d—–w c:\users\carol\AppData\Roaming\HSA
2009-02-04 16:23 ——— d—–w c:\programdata\GameXzone
2009-02-04 15:15 ——— d—–w c:\program files\Tibet Quest
2009-02-04 15:14 ——— d—–w c:\program files\The Broken Clues
2009-02-04 15:08 ——— d—–w c:\program files\Adventures of Robinson Crusoe
2009-01-24 19:01 ——— d—–w c:\program files\Java
2009-01-23 17:52 ——— d—–w c:\programdata\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2009-01-23 17:52 ——— d—–w c:\program files\The Secret of Margrave Manor
2009-01-23 17:52 ——— d—–w c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2009-01-21 01:39 ——— d—–w c:\programdata\NeptunesAdve
2009-01-20 21:10 ——— d—–w c:\programdata\PlayFirst
2009-01-20 01:09 ——— d—–w c:\programdata\Meridian93
2009-01-20 01:08 ——— d—–w c:\users\carol\AppData\Roaming\Meridian93
2009-01-17 01:01 ——— d—–w c:\users\carol\AppData\Roaming\Boomzap
2009-01-16 01:06 ——— d—–w c:\users\carol\AppData\Roaming\Mushroom Age
2009-01-14 01:28 ——— d—–w c:\programdata\PlayPond
2009-01-11 22:01 ——— d—–w c:\program files\RealArcade
2009-01-09 15:27 ——— d—–w c:\users\carol\AppData\Roaming\Fabulous Finds
2009-01-08 22:54 ——— d—–w c:\program files\Common Files\Knowledge Adventure
2009-01-08 22:54 ——— d—–w c:\program files\Common Files\JumpStart
2009-01-08 22:33 ——— d—–w c:\program files\JumpStart
2009-01-08 02:23 ——— d—–w c:\program files\GameHouse
2009-01-08 01:22 ——— d—–w c:\users\carol\AppData\Roaming\iWin
2009-01-07 01:41 ——— d—–w c:\programdata\BC Soft Games
2009-01-07 01:12 ——— d—–w c:\users\carol\AppData\Roaming\iWinArcade
2009-01-07 01:09 ——— d—–w c:\program files\pages
2009-01-07 01:09 ——— d—–w c:\program files\firefox
2009-01-06 01:02 ——— d—–w c:\programdata\Trymedia
2008-10-30 02:23 92 —-a-w c:\users\carol\AppData\Roaming\wklnhst.dat
2008-05-13 11:58 537 —-a-w c:\program files\MemTurbo.lnk
2008-01-21 02:43 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-11-01 497008]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-20 125952]
"RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2008-07-03 812952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-06 39408]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-12-11 3114496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-19 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-19 92704]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-11-01 970808]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-09-27 162304]
"eligmini"="c:\program files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe" [2008-09-03 487424]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-06 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 c:\windows\RtHDVCpl.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2008-01-18 40072]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]
Nielsen NetRatings.lnk - c:\program files\NielsenNetratings\bin\insight.exe [2008-09-06 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BigFix.lnk]
backup=c:\windows\pss\BigFix.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
–a—— 2008-12-11 18:41 3114496 c:\program files\DAP\DAP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eligmini]
–a—— 2008-09-03 17:01 487424 c:\program files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Clean-Up Pro]
–a—— 2003-06-24 01:53 2525991 c:\program files\3B Software\Windows Clean-Up Pro\Windows Clean-Up Pro.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Registry Repair Pro]
–a—— 2005-02-04 00:00 1285632 c:\program files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{AE98BC2F-AF10-4E66-86DF-7C13644C878A}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9C2B44EC-06FF-40B9-8E67-BFC024D0BC55}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9B1FFE53-0D4F-404B-B7BB-EA3A614A86A1}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{BDC3EB72-12CE-4E74-88AC-98460BE3EFF0}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{749136FD-AE67-4182-A40F-C005910DA5E9}"= UDP:56682:PandoRest Listening Port
"{83B4BE75-F155-4360-B916-BFF7349696CB}"= UDP:c:\program files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:PandoRest Application Name
"{E36BDB5E-478F-4D82-B469-DC3135B89D7C}"= TCP:c:\program files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:PandoRest Application Name
"TCP Query User{7D914CA4-9193-4CDA-A348-9C77949E9316}c:\\program files\\nielsennetratings\\bin\\insight.exe"= UDP:c:\program files\nielsennetratings\bin\insight.exe:insight
"UDP Query User{EF3EC00C-E137-49A7-AB64-02E6881AFA46}c:\\program files\\nielsennetratings\\bin\\insight.exe"= TCP:c:\program files\nielsennetratings\bin\insight.exe:insight
"TCP Query User{3D3C3BE5-27C3-4E70-B35D-F3E1BD698C88}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3BF7EAB7-04E9-4CE8-8BF5-39618B623B11}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{92EF45CF-94D9-44C9-86DD-89894330DE12}"= UDP:c:\windows\System32\lxbacoms.exe:Lexmark Communications System
"{05DBEF90-88EF-4CFA-AAC4-2B3D2722B363}"= TCP:c:\windows\System32\lxbacoms.exe:Lexmark Communications System
"{5F73362F-F260-4B69-8069-D522B50D9BA2}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxbapswx.exe:Printer Status Window
"{1A2190E8-684C-48AB-A8EE-D907CBEB1EB0}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxbapswx.exe:Printer Status Window

R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\System32\drivers\tmlwf.sys [2008-11-01 145424]
R2 lxba_device;lxba_device;c:\windows\system32\lxbacoms.exe -service –> c:\windows\system32\lxbacoms.exe -service [?]
R2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-29 835208]
R2 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [2008-11-01 36368]
R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\System32\drivers\tmwfp.sys [2008-11-01 256528]
S2 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [2008-11-01 49680]
S2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [2008-11-01 492888]
S2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-11-01 677128]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-15 33752]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\System32\drivers\motccgp.sys [2007-11-02 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\System32\drivers\motccgpfl.sys [2007-01-23 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\System32\drivers\motport.sys [2007-06-18 23680]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [2006-11-02 2589184]
S3 SQTECH9052;Disney Micro;c:\windows\System32\drivers\Capt9052.sys [2009-02-04 41216]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01b2b1ce-ccdb-11dd-8544-001e9027d7f7}]
\shell\AutoRun\command - L:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26ce3c03-5f4b-11dd-bb03-001e9027d7f7}]
\shell\AutoRun\command - WD_Windows_Tools\Setup.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-28 c:\windows\Tasks\EasyShare Registration Task.job
- c:\progra~2\Kodak\EasyShareSetup\$REGIS~1\Registration_7.9.20.1.sxt _RegistrationOffer@16 []
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH;=nofound&Br;=EM&Loc;=ENG_US&Sys;=DTP&M;=T5254
uInternet Settings,ProxyOverride = setup.msn.com;memberservices.msn.com
uInternet Settings,ProxyServer = http=127.0.0.1:8010
IE: &Clean; Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download; with &DAP; - c:\program files\DAP\dapextie.htm
IE: Create BigJig puzzle - c:\program files\JigMake\jm.htm
IE: Download &all; with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-06 09:10:58
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-06 9:13:38
ComboFix-quarantined-files.txt 2009-03-06 14:13:35

Pre-Run: 202,227,736,576 bytes free
Post-Run: 202,186,375,168 bytes free

222 — E O F — 2009-03-05 20:45:35

Attachments:

rainbue,

I see you are using Wild Tangent. It is not malware, but is sometimes thought to bring malware along. Wild Tangent is a video game software company specializing in online games. It has even made a partnership with AOL to include itself as part of the AOL Instant Messenger for their AIM games section. The WildTangent Web Driver is their technology that allows you to play 3D games over the Internet. Although it’s not technically considered spyware, it does have built in components to update itself and gather information about the computer system including
  • Operating System Version
  • CPU Type and Speed
  • Memory Amount
    Video Card type and Driver Version
  • Sound Card type and Driver Version
  • DirectX Version
    Location that the Web Driver was installed from
  • It is also a MAJOR resource hog.
For more information, see WildTangent Removal Instructions and Help and Inside Wild Tangent-Delivering High-End 3-D Content To A Web Site Near You.
Unless you are an extremely avid games player, I recommend you uninstall Wild Tangent: To uninstall Wild Tangent:
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Wild Tangent, click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Folder::
    c:\program files\Coupons
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01b2b1ce-ccdb-11dd-8544-001e9027d7f7}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26ce3c03-5f4b-11dd-bb03-001e9027d7f7}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
I am a avid game junkie and wild tanget was on the machine when it was purchased. I am having trouble with the bigfish downloader and that is one I sucribe to and have for 2 years and until recently can not download anything with there manager. I tried to run Rooter and it just flashes a line on the screen and goes away. I tried to search for Rooter.txt in both a general search and with the directory you gave me. Neither are showing up.
I went ahead and delete wild tangent off my machine. Here is the other report you asked me for. KASPERSKY ONLINE SCANNER 7 REPORT Friday, March 6, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Friday, March 06, 2009 19:23:43 Records in database: 1874971 Scan settings Scan using the following database extended Scan archives yes Scan mail databases yes Scan area My Computer C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ Scan statistics Files scanned 189793 Threat name 4 Infected objects 7 Suspicious objects 0 Duration of the scan 03:08:02 File name Threat name Threats count C:\Program Files\Trend Micro\Internet Security\Quarantine\5E9B.tmp Infected: not-a-virus:AdWare.Win32.AdMedia.g 1 C:\Program Files\Trend Micro\Internet Security\Quarantine\5FE4.tmp Infected: not-a-virus:AdWare.Win32.AdMedia.g 1 C:\Program Files\Trend Micro\Internet Security\Quarantine\A9installer_77043301.exe Infected: Trojan-Downloader.Win32.FraudLoad.vdgh 1 C:\Program Files\Trend Micro\Internet Security\Quarantine\liong2.exe Infected: Backdoor.Win32.Mex.aa 1 C:\Users\carol\Documents\My Completed Downloads\can-you-see-what-i-see-setup.exe Infected: not-a-virus:AdWare.Win32.AdMedia.g 1 C:\Users\carol\Documents\My Completed Downloads\magic-academy-setup.exe Infected: not-a-virus:AdWare.Win32.AdMedia.g 1 C:\Users\carol\Documents\My Documents\My Completed Downloads\Super-Text-Twist-setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bu 1 The selected area was scanned.
rainbue,

Where's the ComboFix.txt?

If you didn't save it, it can be found as follows:

Please:
  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

When file opens, Copy/Paste text here
Here is the cmbofix report sorry

ComboFix 09-03-04.01 - carol 2009-03-06 13:51:52.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1918.1148 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\carol\Desktop\CFScript.txt
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-02-06 to 2009-03-06 )))))))))))))))))))))))))))))))
.

2009-03-06 11:31 . 2009-03-06 11:31 d——– C:\Rooter$
2009-03-05 20:03 . 2009-03-05 20:03 d——– c:\program files\Escape Rosecliff Island
2009-03-02 12:14 . 2009-03-02 12:14 d——– c:\users\All Users\Enkord
2009-03-02 12:14 . 2009-03-02 12:14 d——– c:\programdata\Enkord
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\users\carol\AppData\Roaming\Malwarebytes
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\users\All Users\Malwarebytes
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\programdata\Malwarebytes
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-26 23:00 . 2009-02-11 10:19 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-26 23:00 . 2009-02-11 10:19 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-02-22 19:54 . 2008-12-04 23:32 428,544 –a—— c:\windows\System32\EncDec.dll
2009-02-22 19:54 . 2008-12-04 23:32 293,376 –a—— c:\windows\System32\psisdecd.dll
2009-02-22 19:54 . 2008-12-04 23:31 217,088 –a—— c:\windows\System32\psisrndr.ax
2009-02-22 19:54 . 2008-12-04 23:31 177,664 –a—— c:\windows\System32\mpg2splt.ax
2009-02-22 19:54 . 2008-12-04 23:31 80,896 –a—— c:\windows\System32\MSNP.ax
2009-02-20 20:41 . 2009-02-20 20:41 d——– c:\users\All Users\GameHouse
2009-02-20 20:41 . 2009-02-20 20:41 d——– c:\programdata\GameHouse
2009-02-20 19:26 . 2009-02-20 19:27 d——– c:\program files\Little Shop - Memories
2009-02-20 19:25 . 2009-02-20 19:25 d——– c:\program files\Tahiti Hidden Pearls
2009-02-19 19:30 . 2009-02-24 18:35 d——– C:\BigFishGamesCache
2009-02-18 17:34 . 2009-02-18 17:34 d——– c:\users\carol\AppData\Roaming\V-Games
2009-02-13 17:54 . 2009-02-13 18:20 d——– c:\users\carol\AppData\Roaming\gemsweeperextractedgfx
2009-02-13 17:54 . 2009-02-13 17:54 d——– c:\users\All Users\My Games
2009-02-13 17:54 . 2009-02-13 17:54 d——– c:\programdata\My Games
2009-02-11 18:06 . 2009-01-14 22:36 1,383,424 –a—— c:\windows\System32\mshtml.tlb
2009-02-11 18:06 . 2009-01-15 01:11 827,392 –a—— c:\windows\System32\wininet.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-06 18:49 ——— d—a-w c:\programdata\TEMP
2009-03-06 18:20 ——— d—–w c:\program files\eMachines Games
2009-03-06 17:06 ——— d—–w c:\program files\Alawar
2009-03-06 16:58 ——— d—–w c:\programdata\WildTangent
2009-03-06 12:36 410,984 —-a-w c:\windows\System32\deploytk.dll
2009-03-06 01:15 ——— d—–w c:\users\carol\AppData\Roaming\SpinTop Games
2009-03-01 19:10 ——— d—–w c:\program files\DAP
2009-02-27 23:11 ——— d—–w c:\program files\Liong - The Lost Amulets
2009-02-27 02:32 ——— d—–w c:\users\carol\AppData\Roaming\PlayFirst
2009-02-26 23:35 ——— d—–w c:\program files\PlayFirst
2009-02-23 00:24 ——— d—–w c:\users\carol\AppData\Roaming\SpinTop
2009-02-23 00:24 ——— d—–w c:\program files\Suspects and Clues
2009-02-23 00:24 ——— d—–w c:\program files\Paranormal Agency
2009-02-23 00:24 ——— d—–w c:\program files\NielsenNetratings
2009-02-23 00:24 ——— d—–w c:\program files\Mystery of Unicorn Castle
2009-02-23 00:24 ——— d—–w c:\program files\Jewel Quest Mysteries - Curse of the Emerald Tear
2009-02-23 00:24 ——— d—–w c:\program files\James Patterson's Women's Murder Club - Death in Scarlet
2009-02-23 00:24 ——— d—–w c:\program files\Hawaiian Explorer 2 - Lost Island
2009-02-23 00:24 ——— d—–w c:\program files\Fabulous Finds
2009-02-23 00:24 ——— d—–w c:\program files\Cate West The Vanishing Files
2009-02-23 00:24 ——— d—–w c:\program files\bfgclient
2009-02-23 00:24 ——— d—–w c:\program files\Adventure Chronicles - The Search for Lost Treasure
2009-02-19 01:50 ——— d—–w c:\program files\Coupons
2009-02-19 01:27 ——— d—–w c:\program files\Trend Micro
2009-02-15 21:44 ——— d—–w c:\program files\sounds
2009-02-12 08:01 ——— d—–w c:\program files\Windows Mail
2009-02-07 00:32 ——— d—–w c:\program files\Google
2009-02-07 00:19 ——— d—–w c:\programdata\iWin Games
2009-02-04 22:37 ——— d—–w c:\programdata\AdventureChronicles1
2009-02-04 17:24 ——— d—–w c:\program files\Disney Micro
2009-02-04 17:23 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-04 17:23 ——— d—–w c:\program files\DB CIF Cam
2009-02-04 17:21 ——— d—–w c:\program files\Disney Pix Micro Downloader
2009-02-04 17:20 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-04 16:38 ——— d—–w c:\users\carol\AppData\Roaming\HSA
2009-02-04 16:23 ——— d—–w c:\programdata\GameXzone
2009-02-04 15:15 ——— d—–w c:\program files\Tibet Quest
2009-02-04 15:14 ——— d—–w c:\program files\The Broken Clues
2009-02-04 15:08 ——— d—–w c:\program files\Adventures of Robinson Crusoe
2009-01-24 19:01 ——— d—–w c:\program files\Java
2009-01-23 17:52 ——— d—–w c:\programdata\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2009-01-23 17:52 ——— d—–w c:\program files\The Secret of Margrave Manor
2009-01-23 17:52 ——— d—–w c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2009-01-21 01:39 ——— d—–w c:\programdata\NeptunesAdve
2009-01-20 21:10 ——— d—–w c:\programdata\PlayFirst
2009-01-20 01:09 ——— d—–w c:\programdata\Meridian93
2009-01-20 01:08 ——— d—–w c:\users\carol\AppData\Roaming\Meridian93
2009-01-17 01:01 ——— d—–w c:\users\carol\AppData\Roaming\Boomzap
2009-01-16 01:06 ——— d—–w c:\users\carol\AppData\Roaming\Mushroom Age
2009-01-14 01:28 ——— d—–w c:\programdata\PlayPond
2009-01-11 22:01 ——— d—–w c:\program files\RealArcade
2009-01-09 15:27 ——— d—–w c:\users\carol\AppData\Roaming\Fabulous Finds
2009-01-08 22:54 ——— d—–w c:\program files\Common Files\Knowledge Adventure
2009-01-08 22:54 ——— d—–w c:\program files\Common Files\JumpStart
2009-01-08 22:33 ——— d—–w c:\program files\JumpStart
2009-01-08 02:23 ——— d—–w c:\program files\GameHouse
2009-01-08 01:22 ——— d—–w c:\users\carol\AppData\Roaming\iWin
2009-01-07 01:41 ——— d—–w c:\programdata\BC Soft Games
2009-01-07 01:12 ——— d—–w c:\users\carol\AppData\Roaming\iWinArcade
2009-01-07 01:09 ——— d—–w c:\program files\pages
2009-01-07 01:09 ——— d—–w c:\program files\firefox
2009-01-06 01:02 ——— d—–w c:\programdata\Trymedia
2008-10-30 02:23 92 —-a-w c:\users\carol\AppData\Roaming\wklnhst.dat
2008-05-13 11:58 537 —-a-w c:\program files\MemTurbo.lnk
2008-01-21 02:43 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((( SnapShot@2009-03-06_ 9.11.50.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-06 14:10:59 212,992 —-a-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-06 18:46:46 212,992 —-a-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
- 2009-03-06 14:10:54 217,088 —-a-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-06 18:46:41 217,088 —-a-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
- 2009-03-06 13:56:30 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-06 14:54:07 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-06 13:56:30 147,456 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-06 14:54:07 147,456 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-06 13:56:30 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-06 14:54:07 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-06 00:51:20 101,144 —-a-w c:\windows\System32\perfc009.dat
+ 2009-03-06 14:39:26 101,144 —-a-w c:\windows\System32\perfc009.dat
- 2009-02-06 00:51:20 595,446 —-a-w c:\windows\System32\perfh009.dat
+ 2009-03-06 14:39:26 595,446 —-a-w c:\windows\System32\perfh009.dat
- 2009-03-06 11:35:50 7,894 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3666986699-1126495756-2325892406-1000_UserData.bin
+ 2009-03-06 18:47:04 7,894 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3666986699-1126495756-2325892406-1000_UserData.bin
- 2009-03-06 11:35:50 90,680 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-06 18:47:03 90,778 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-06 11:35:46 46,914 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-06 18:46:54 47,048 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-11-01 497008]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-20 125952]
"RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2008-07-03 812952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-06 39408]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-12-11 3114496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-19 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-19 92704]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-11-01 970808]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-09-27 162304]
"eligmini"="c:\program files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe" [2008-09-03 487424]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-06 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 c:\windows\RtHDVCpl.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2008-01-18 40072]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]
Nielsen NetRatings.lnk - c:\program files\NielsenNetratings\bin\insight.exe [2008-09-06 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BigFix.lnk]
backup=c:\windows\pss\BigFix.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
–a—— 2008-12-11 18:41 3114496 c:\program files\DAP\DAP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eligmini]
–a—— 2008-09-03 17:01 487424 c:\program files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Clean-Up Pro]
–a—— 2003-06-24 01:53 2525991 c:\program files\3B Software\Windows Clean-Up Pro\Windows Clean-Up Pro.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Registry Repair Pro]
–a—— 2005-02-04 00:00 1285632 c:\program files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{AE98BC2F-AF10-4E66-86DF-7C13644C878A}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9C2B44EC-06FF-40B9-8E67-BFC024D0BC55}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9B1FFE53-0D4F-404B-B7BB-EA3A614A86A1}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{BDC3EB72-12CE-4E74-88AC-98460BE3EFF0}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{749136FD-AE67-4182-A40F-C005910DA5E9}"= UDP:56682:PandoRest Listening Port
"{83B4BE75-F155-4360-B916-BFF7349696CB}"= UDP:c:\program files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:PandoRest Application Name
"{E36BDB5E-478F-4D82-B469-DC3135B89D7C}"= TCP:c:\program files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:PandoRest Application Name
"TCP Query User{7D914CA4-9193-4CDA-A348-9C77949E9316}c:\\program files\\nielsennetratings\\bin\\insight.exe"= UDP:c:\program files\nielsennetratings\bin\insight.exe:insight
"UDP Query User{EF3EC00C-E137-49A7-AB64-02E6881AFA46}c:\\program files\\nielsennetratings\\bin\\insight.exe"= TCP:c:\program files\nielsennetratings\bin\insight.exe:insight
"TCP Query User{3D3C3BE5-27C3-4E70-B35D-F3E1BD698C88}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3BF7EAB7-04E9-4CE8-8BF5-39618B623B11}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{92EF45CF-94D9-44C9-86DD-89894330DE12}"= UDP:c:\windows\System32\lxbacoms.exe:Lexmark Communications System
"{05DBEF90-88EF-4CFA-AAC4-2B3D2722B363}"= TCP:c:\windows\System32\lxbacoms.exe:Lexmark Communications System
"{5F73362F-F260-4B69-8069-D522B50D9BA2}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxbapswx.exe:Printer Status Window
"{1A2190E8-684C-48AB-A8EE-D907CBEB1EB0}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxbapswx.exe:Printer Status Window

R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\System32\drivers\tmlwf.sys [2008-11-01 145424]
R2 lxba_device;lxba_device;c:\windows\system32\lxbacoms.exe -service –> c:\windows\system32\lxbacoms.exe -service [?]
R2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-29 835208]
R2 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [2008-11-01 36368]
R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\System32\drivers\tmwfp.sys [2008-11-01 256528]
S2 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [2008-11-01 49680]
S2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [2008-11-01 492888]
S2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-11-01 677128]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-15 33752]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\System32\drivers\motccgp.sys [2007-11-02 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\System32\drivers\motccgpfl.sys [2007-01-23 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\System32\drivers\motport.sys [2007-06-18 23680]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [2006-11-02 2589184]
S3 SQTECH9052;Disney Micro;c:\windows\System32\drivers\Capt9052.sys [2009-02-04 41216]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01b2b1ce-ccdb-11dd-8544-001e9027d7f7}]
\shell\AutoRun\command - L:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26ce3c03-5f4b-11dd-bb03-001e9027d7f7}]
\shell\AutoRun\command - WD_Windows_Tools\Setup.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-28 c:\windows\Tasks\EasyShare Registration Task.job
- c:\progra~2\Kodak\EasyShareSetup\$REGIS~1\Registration_7.9.20.1.sxt _RegistrationOffer@16 []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH;=nofound&Br;=EM&Loc;=ENG_US&Sys;=DTP&M;=T5254
uInternet Settings,ProxyOverride = setup.msn.com;memberservices.msn.com
uInternet Settings,ProxyServer = http=127.0.0.1:8010
IE: &Clean; Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download; with &DAP; - c:\program files\DAP\dapextie.htm
IE: Create BigJig puzzle - c:\program files\JigMake\jm.htm
IE: Download &all; with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-06 13:55:57
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\users\carol\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(3200)
c:\program files\NielsenNetratings\bin\dlltrack.dll
c:\program files\NielsenNetratings\bin\keymouse.dll
c:\program files\NielsenNetratings\bin\iehook.dll
.
Completion time: 2009-03-06 13:58:40
ComboFix-quarantined-files.txt 2009-03-06 18:58:34
ComboFix2.txt 2009-03-06 18:38:10
ComboFix3.txt 2009-03-06 14:13:40

Pre-Run: 207,806,742,528 bytes free
Post-Run: 207,749,828,608 bytes free

262 — E O F — 2009-03-05 20:45:35
rainbue,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Users\carol\Documents\My Completed Downloads\can-you-see-what-i-see-setup.exe
    C:\Users\carol\Documents\My Completed Downloads\magic-academy-setup.exe
    C:\Users\carol\Documents\My Documents\My Completed Downloads\Super-Text-Twist-setup.exe
    
    Folder::
    c:\program files\Coupons
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01b2b1ce-ccdb-11dd-8544-001e9027d7f7}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26ce3c03-5f4b-11dd-bb03-001e9027d7f7}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then please give me a new HijackThis log also.
I sent you the combofix list but forgot the hijack file. I also ran Kaz again after opening 1 e-mail. Here are those reports.

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, March 6, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, March 06, 2009 22:55:07
Records in database: 1875477
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Files scanned: 99931
Threat name: 3
Infected objects: 6
Suspicious objects: 0
Duration of the scan: 01:45:24


File name / Threat name / Threats count
C:\Program Files\Trend Micro\Internet Security\Quarantine\5E9B.tmp Infected: not-a-virus:AdWare.Win32.AdMedia.g 1
C:\Program Files\Trend Micro\Internet Security\Quarantine\5FE4.tmp Infected: not-a-virus:AdWare.Win32.AdMedia.g 1
C:\Program Files\Trend Micro\Internet Security\Quarantine\A9installer_77043301.exe Infected: Trojan-Downloader.Win32.FraudLoad.vdgh 1
C:\Program Files\Trend Micro\Internet Security\Quarantine\liong2.exe Infected: Backdoor.Win32.Mex.aa 1
C:\Users\carol\Documents\My Completed Downloads\can-you-see-what-i-see-setup.exe Infected: not-a-virus:AdWare.Win32.AdMedia.g 1
C:\Users\carol\Documents\My Completed Downloads\magic-academy-setup.exe Infected: not-a-virus:AdWare.Win32.AdMedia.g 1

The scan was stopped by the user.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:23 PM, on 3/6/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\System32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DAP\DAP.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\NielsenNetratings\bin\insight.exe
C:\Windows\Explorer.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M=T5254
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8010
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = setup.msn.com;memberservices.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SBCONVERT - {A1056498-D09A-41E4-864B-505EDD640D9E} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: SpeedBit Video Converter - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - (no file)
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [eligmini] C:\Program Files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe 0
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /H
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Nielsen NetRatings.lnk = C:\Program Files\NielsenNetratings\bin\insight.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Create BigJig puzzle - C:\Program Files\JigMake\jm.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O13 - Gopher Prefix:
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Escape%20Rosecliff%20Island/Images/stg_drm.ocx
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: lxba_device - - C:\Windows\system32\lxbacoms.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7640 bytes
Sorry about that. Here is the report
ComboFix 09-03-04.01 - carol 2009-03-06 20:58:37.5 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1918.1146 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\carol\Desktop\CFScript.txt
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\users\carol\Documents\My Completed Downloads\can-you-see-what-i-see-setup.exe
c:\users\carol\Documents\My Completed Downloads\magic-academy-setup.exe
c:\users\carol\Documents\My Documents\My Completed Downloads\Super-Text-Twist-setup.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Coupons
c:\program files\Coupons\uninstall.exe
c:\users\carol\Documents\My Completed Downloads\can-you-see-what-i-see-setup.exe
c:\users\carol\Documents\My Completed Downloads\magic-academy-setup.exe
c:\users\carol\Documents\My Documents\My Completed Downloads\Super-Text-Twist-setup.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-07 to 2009-03-07 )))))))))))))))))))))))))))))))
.

2009-03-06 11:31 . 2009-03-06 11:31 d——– C:\Rooter$
2009-03-05 20:03 . 2009-03-05 20:03 d——– c:\program files\Escape Rosecliff Island
2009-03-02 12:14 . 2009-03-02 12:14 d——– c:\users\All Users\Enkord
2009-03-02 12:14 . 2009-03-02 12:14 d——– c:\programdata\Enkord
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\users\carol\AppData\Roaming\Malwarebytes
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\users\All Users\Malwarebytes
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\programdata\Malwarebytes
2009-02-26 23:00 . 2009-02-26 23:00 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-26 23:00 . 2009-02-11 10:19 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-26 23:00 . 2009-02-11 10:19 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-02-22 19:54 . 2008-12-04 23:32 428,544 –a—— c:\windows\System32\EncDec.dll
2009-02-22 19:54 . 2008-12-04 23:32 293,376 –a—— c:\windows\System32\psisdecd.dll
2009-02-22 19:54 . 2008-12-04 23:31 217,088 –a—— c:\windows\System32\psisrndr.ax
2009-02-22 19:54 . 2008-12-04 23:31 177,664 –a—— c:\windows\System32\mpg2splt.ax
2009-02-22 19:54 . 2008-12-04 23:31 80,896 –a—— c:\windows\System32\MSNP.ax
2009-02-20 20:41 . 2009-02-20 20:41 d——– c:\users\All Users\GameHouse
2009-02-20 20:41 . 2009-02-20 20:41 d——– c:\programdata\GameHouse
2009-02-20 19:26 . 2009-02-20 19:27 d——– c:\program files\Little Shop - Memories
2009-02-20 19:25 . 2009-02-20 19:25 d——– c:\program files\Tahiti Hidden Pearls
2009-02-19 19:30 . 2009-02-24 18:35 d——– C:\BigFishGamesCache
2009-02-18 17:34 . 2009-02-18 17:34 d——– c:\users\carol\AppData\Roaming\V-Games
2009-02-13 17:54 . 2009-02-13 18:20 d——– c:\users\carol\AppData\Roaming\gemsweeperextractedgfx
2009-02-13 17:54 . 2009-02-13 17:54 d——– c:\users\All Users\My Games
2009-02-13 17:54 . 2009-02-13 17:54 d——– c:\programdata\My Games
2009-02-11 18:06 . 2009-01-14 22:36 1,383,424 –a—— c:\windows\System32\mshtml.tlb
2009-02-11 18:06 . 2009-01-15 01:11 827,392 –a—— c:\windows\System32\wininet.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-07 01:53 ——— d—a-w c:\programdata\TEMP
2009-03-06 18:20 ——— d—–w c:\program files\eMachines Games
2009-03-06 17:06 ——— d—–w c:\program files\Alawar
2009-03-06 16:58 ——— d—–w c:\programdata\WildTangent
2009-03-06 12:36 410,984 —-a-w c:\windows\System32\deploytk.dll
2009-03-06 01:15 ——— d—–w c:\users\carol\AppData\Roaming\SpinTop Games
2009-03-01 19:10 ——— d—–w c:\program files\DAP
2009-02-27 23:11 ——— d—–w c:\program files\Liong - The Lost Amulets
2009-02-27 02:32 ——— d—–w c:\users\carol\AppData\Roaming\PlayFirst
2009-02-26 23:35 ——— d—–w c:\program files\PlayFirst
2009-02-23 00:24 ——— d—–w c:\users\carol\AppData\Roaming\SpinTop
2009-02-23 00:24 ——— d—–w c:\program files\Suspects and Clues
2009-02-23 00:24 ——— d—–w c:\program files\Paranormal Agency
2009-02-23 00:24 ——— d—–w c:\program files\NielsenNetratings
2009-02-23 00:24 ——— d—–w c:\program files\Mystery of Unicorn Castle
2009-02-23 00:24 ——— d—–w c:\program files\Jewel Quest Mysteries - Curse of the Emerald Tear
2009-02-23 00:24 ——— d—–w c:\program files\James Patterson's Women's Murder Club - Death in Scarlet
2009-02-23 00:24 ——— d—–w c:\program files\Hawaiian Explorer 2 - Lost Island
2009-02-23 00:24 ——— d—–w c:\program files\Fabulous Finds
2009-02-23 00:24 ——— d—–w c:\program files\Cate West The Vanishing Files
2009-02-23 00:24 ——— d—–w c:\program files\bfgclient
2009-02-23 00:24 ——— d—–w c:\program files\Adventure Chronicles - The Search for Lost Treasure
2009-02-19 01:27 ——— d—–w c:\program files\Trend Micro
2009-02-15 21:44 ——— d—–w c:\program files\sounds
2009-02-12 08:01 ——— d—–w c:\program files\Windows Mail
2009-02-07 00:32 ——— d—–w c:\program files\Google
2009-02-07 00:19 ——— d—–w c:\programdata\iWin Games
2009-02-04 22:37 ——— d—–w c:\programdata\AdventureChronicles1
2009-02-04 17:24 ——— d—–w c:\program files\Disney Micro
2009-02-04 17:23 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-04 17:23 ——— d—–w c:\program files\DB CIF Cam
2009-02-04 17:21 ——— d—–w c:\program files\Disney Pix Micro Downloader
2009-02-04 17:20 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-04 16:38 ——— d—–w c:\users\carol\AppData\Roaming\HSA
2009-02-04 16:23 ——— d—–w c:\programdata\GameXzone
2009-02-04 15:15 ——— d—–w c:\program files\Tibet Quest
2009-02-04 15:14 ——— d—–w c:\program files\The Broken Clues
2009-02-04 15:08 ——— d—–w c:\program files\Adventures of Robinson Crusoe
2009-01-24 19:01 ——— d—–w c:\program files\Java
2009-01-23 17:52 ——— d—–w c:\programdata\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2009-01-23 17:52 ——— d—–w c:\program files\The Secret of Margrave Manor
2009-01-23 17:52 ——— d—–w c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2009-01-21 01:39 ——— d—–w c:\programdata\NeptunesAdve
2009-01-20 21:10 ——— d—–w c:\programdata\PlayFirst
2009-01-20 01:09 ——— d—–w c:\programdata\Meridian93
2009-01-20 01:08 ——— d—–w c:\users\carol\AppData\Roaming\Meridian93
2009-01-17 01:01 ——— d—–w c:\users\carol\AppData\Roaming\Boomzap
2009-01-16 01:06 ——— d—–w c:\users\carol\AppData\Roaming\Mushroom Age
2009-01-14 01:28 ——— d—–w c:\programdata\PlayPond
2009-01-11 22:01 ——— d—–w c:\program files\RealArcade
2009-01-09 15:27 ——— d—–w c:\users\carol\AppData\Roaming\Fabulous Finds
2009-01-08 22:54 ——— d—–w c:\program files\Common Files\Knowledge Adventure
2009-01-08 22:54 ——— d—–w c:\program files\Common Files\JumpStart
2009-01-08 22:33 ——— d—–w c:\program files\JumpStart
2009-01-08 02:23 ——— d—–w c:\program files\GameHouse
2009-01-08 01:22 ——— d—–w c:\users\carol\AppData\Roaming\iWin
2009-01-07 01:41 ——— d—–w c:\programdata\BC Soft Games
2009-01-07 01:12 ——— d—–w c:\users\carol\AppData\Roaming\iWinArcade
2009-01-07 01:09 ——— d—–w c:\program files\pages
2009-01-07 01:09 ——— d—–w c:\program files\firefox
2008-10-30 02:23 92 —-a-w c:\users\carol\AppData\Roaming\wklnhst.dat
2008-05-13 11:58 537 —-a-w c:\program files\MemTurbo.lnk
2008-01-21 02:43 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((( SnapShot@2009-03-06_ 9.11.50.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-06 14:10:59 212,992 —-a-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-07 01:42:40 212,992 —-a-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
- 2009-03-06 14:10:54 217,088 —-a-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-07 01:42:35 217,088 —-a-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
- 2009-03-06 13:56:30 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-06 23:31:23 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-06 13:56:30 147,456 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-06 23:31:23 147,456 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-06 13:56:30 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-06 23:31:23 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-06 00:51:20 101,144 —-a-w c:\windows\System32\perfc009.dat
+ 2009-03-06 14:39:26 101,144 —-a-w c:\windows\System32\perfc009.dat
- 2009-02-06 00:51:20 595,446 —-a-w c:\windows\System32\perfh009.dat
+ 2009-03-06 14:39:26 595,446 —-a-w c:\windows\System32\perfh009.dat
- 2009-03-06 11:35:50 7,894 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3666986699-1126495756-2325892406-1000_UserData.bin
+ 2009-03-07 01:42:51 7,894 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3666986699-1126495756-2325892406-1000_UserData.bin
- 2009-03-06 11:35:50 90,680 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-07 01:42:50 90,794 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-06 11:35:46 46,914 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-07 01:42:48 47,064 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-11-01 497008]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-20 125952]
"RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2008-07-03 812952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-06 39408]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-12-11 3114496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-19 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-19 92704]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-11-01 970808]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-09-27 162304]
"eligmini"="c:\program files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe" [2008-09-03 487424]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-06 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 c:\windows\RtHDVCpl.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2008-01-18 40072]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]
Nielsen NetRatings.lnk - c:\program files\NielsenNetratings\bin\insight.exe [2008-09-06 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BigFix.lnk]
backup=c:\windows\pss\BigFix.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
–a—— 2008-12-11 18:41 3114496 c:\program files\DAP\DAP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eligmini]
–a—— 2008-09-03 17:01 487424 c:\program files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Clean-Up Pro]
–a—— 2003-06-24 01:53 2525991 c:\program files\3B Software\Windows Clean-Up Pro\Windows Clean-Up Pro.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Registry Repair Pro]
–a—— 2005-02-04 00:00 1285632 c:\program files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{AE98BC2F-AF10-4E66-86DF-7C13644C878A}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9C2B44EC-06FF-40B9-8E67-BFC024D0BC55}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9B1FFE53-0D4F-404B-B7BB-EA3A614A86A1}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{BDC3EB72-12CE-4E74-88AC-98460BE3EFF0}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{749136FD-AE67-4182-A40F-C005910DA5E9}"= UDP:56682:PandoRest Listening Port
"{83B4BE75-F155-4360-B916-BFF7349696CB}"= UDP:c:\program files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:PandoRest Application Name
"{E36BDB5E-478F-4D82-B469-DC3135B89D7C}"= TCP:c:\program files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:PandoRest Application Name
"TCP Query User{7D914CA4-9193-4CDA-A348-9C77949E9316}c:\\program files\\nielsennetratings\\bin\\insight.exe"= UDP:c:\program files\nielsennetratings\bin\insight.exe:insight
"UDP Query User{EF3EC00C-E137-49A7-AB64-02E6881AFA46}c:\\program files\\nielsennetratings\\bin\\insight.exe"= TCP:c:\program files\nielsennetratings\bin\insight.exe:insight
"TCP Query User{3D3C3BE5-27C3-4E70-B35D-F3E1BD698C88}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3BF7EAB7-04E9-4CE8-8BF5-39618B623B11}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{92EF45CF-94D9-44C9-86DD-89894330DE12}"= UDP:c:\windows\System32\lxbacoms.exe:Lexmark Communications System
"{05DBEF90-88EF-4CFA-AAC4-2B3D2722B363}"= TCP:c:\windows\System32\lxbacoms.exe:Lexmark Communications System
"{5F73362F-F260-4B69-8069-D522B50D9BA2}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxbapswx.exe:Printer Status Window
"{1A2190E8-684C-48AB-A8EE-D907CBEB1EB0}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxbapswx.exe:Printer Status Window

R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\System32\drivers\tmlwf.sys [2008-11-01 145424]
R2 lxba_device;lxba_device;c:\windows\system32\lxbacoms.exe -service –> c:\windows\system32\lxbacoms.exe -service [?]
R2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-29 835208]
R2 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [2008-11-01 36368]
R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\System32\drivers\tmwfp.sys [2008-11-01 256528]
S2 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [2008-11-01 49680]
S2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [2008-11-01 492888]
S2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-11-01 677128]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-15 33752]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\System32\drivers\motccgp.sys [2007-11-02 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\System32\drivers\motccgpfl.sys [2007-01-23 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\System32\drivers\motport.sys [2007-06-18 23680]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [2006-11-02 2589184]
S3 SQTECH9052;Disney Micro;c:\windows\System32\drivers\Capt9052.sys [2009-02-04 41216]
.
Contents of the 'Scheduled Tasks' folder

2009-02-28 c:\windows\Tasks\EasyShare Registration Task.job
- c:\progra~2\Kodak\EasyShareSetup\$REGIS~1\Registration_7.9.20.1.sxt _RegistrationOffer@16 []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH;=nofound&Br;=EM&Loc;=ENG_US&Sys;=DTP&M;=T5254
uInternet Settings,ProxyOverride = setup.msn.com;memberservices.msn.com
uInternet Settings,ProxyServer = http=127.0.0.1:8010
IE: &Clean; Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download; with &DAP; - c:\program files\DAP\dapextie.htm
IE: Create BigJig puzzle - c:\program files\JigMake\jm.htm
IE: Download &all; with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-06 21:01:53
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-06 21:04:26
ComboFix-quarantined-files.txt 2009-03-07 02:04:22
ComboFix2.txt 2009-03-07 01:37:39
ComboFix3.txt 2009-03-06 18:58:42
ComboFix4.txt 2009-03-06 18:38:10
ComboFix5.txt 2009-03-07 01:57:17

Pre-Run: 208,196,526,080 bytes free
Post-Run: 208,160,010,240 bytes free

263 — E O F — 2009-03-05 20:45:35
Here is the hijack report after running this combofix3
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:23 PM, on 3/6/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\System32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DAP\DAP.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\NielsenNetratings\bin\insight.exe
C:\Windows\Explorer.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M=T5254
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8010
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = setup.msn.com;memberservices.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SBCONVERT - {A1056498-D09A-41E4-864B-505EDD640D9E} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: SpeedBit Video Converter - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - (no file)
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [eligmini] C:\Program Files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe 0
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /H
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Nielsen NetRatings.lnk = C:\Program Files\NielsenNetratings\bin\insight.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Create BigJig puzzle - C:\Program Files\JigMake\jm.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O13 - Gopher Prefix:
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Escape%20Rosecliff%20Island/Images/stg_drm.ocx
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: lxba_device - - C:\Windows\system32\lxbacoms.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7640 bytes
I haven't done anything but restart the machine, but it does seem to be loading faster. Still having problems with printer but will delete and re-install. I'll work on machine tonight and send report tomorrow. :thumbup: Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI