This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] How do I update HJT without internet access?

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello oldman960,

While trying to run haxfix, a window kept popping up called "ping.exe - Bad Image". This notice contained the following text: "The application or DLL C:\WINNT\system32\CSLSP.DLL is not a valid windows image. Please check this against your installation diskette." An "OK" button was displayed.

Haxfix would continually pause it's next task until I closed this "Bad Image" window. I probably closed it 25 times. Is this a problem? Anyway, the log did finish.

I searched for C:\combofix.txt file, but could not find it. How do you search for it or find it?

I unchecked the "Use a proxy server…" and still no internet. In fact, the "IE cannot display…" comes up even faster since I ran Combofix or Haxfix. Up till the running of Haxfix or Combofix, the page seemed to load but was seemed to be blocked after it loaded.??

My email is no longer receiving or sending, so I had to download the haxfix and hjt logs to disk so I could post them.

Here are my logs you asked for except for the combofix I couldn't find:

Rooter Log:

Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:76316 Mo/Free:2002 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Tue 03/10/2009|13:14
———————-\\ Processes..
–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINNT\system32\csrss.exe
———- \??\C:\WINNT\system32\winlogon.exe
———- C:\WINNT\system32\services.exe
———- C:\WINNT\system32\lsass.exe
———- C:\WINNT\system32\svchost.exe
———- C:\WINNT\system32\svchost.exe
———- C:\WINNT\System32\svchost.exe
———- C:\WINNT\System32\svchost.exe
———- C:\WINNT\System32\svchost.exe
———- C:\WINNT\Explorer.EXE
———- C:\WINNT\system32\spoolsv.exe
———- C:\WINNT\system32\svchost.exe
———- C:\WINNT\System32\hkcmd.exe
———- C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
———- C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
———- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
———- C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
———- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
———- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
———- C:\Program Files\Messenger\msmsgs.exe
———- C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
———- C:\WINNT\system32\ctfmon.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
———- C:\Program Files\ewido\security suite\ewidoctrl.exe
———- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
———- C:\WINNT\System32\svchost.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
———- C:\WINNT\System32\alg.exe
———- C:\WINNT\system32\cmd.exe
———- C:\Rooter$\RK.exe
———————-\\ Search..
———————-\\ ROOTKIT !!


1 - "C:\Rooter$\Rooter_1.txt" - Tue 03/10/2009|13:16
———————-\\ Scan completed at 13:16




HAXFIX logfile - by Marckie

version 5.066
2009-03-10 20:04:11.84
running from C:\HaxFix

— Checking for Haxdoor —

checking for a3d files
a3d files found
fltr.a3d

checking for matching notify keys
no matching notify keys found

checking for matching services
no matching services found

checking for matching safeboot services
no matching safeboot services found


— Checking for Goldun - Spybanker —

checking for SSODL keys
no ssodl keys found

checking for notify keys
no notify keys found

checking for services
no services found

checking for random used files and services
– these files are not necessarily malicious
– scanning all folders
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Movie Maker\MEDIATAB0.DAT
C:\Documents and Settings\Owner\My Documents\My Music\Led Zeppelin\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\The Beatles\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\Various Artists\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\Thin Lizzy\Dedication- The Very Best of Thin Lizzy\AlbumArt_{01110B79-A40D-458E-8643-3234EF5AB3B8}_Large.jpg
C:\Documents and Settings\Owner\My Documents\My Music\Thin Lizzy\Dedication- The Very Best of Thin Lizzy\Folder.jpg
C:\Program Files\Windows Media Connect 2\wmccds.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\Program Files\HP\Digital Imaging\Data\projectstemplates\flowers1_2F_A4.{B439E359-B2DF-4336-AD0E-E567C24D365C}.creativetempl
C:\Program Files\HP\Digital Imaging\Data\projectstemplates\pt-summerC4x6H1template.png
C:\Program Files\Intel\ANS\ianswxp.cat
C:\Program Files\McAfee\McAfee Firewall\fwnetcfg.dll
C:\Program Files\Microsoft Works\1033\Wizards\inspuus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\notrnus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\nottsus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\schbrus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\schesus.wwp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Html\Help\MusicMatch_Radio.htm
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonadd.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttondelete.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonexplorer.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonjewelcase.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonsmartsplit.bmp
C:\Program Files\PC-Doctor for Windows\Java\Native Help\en\ftsform.htm
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP2\change.log.1
C:\WINNT\$NtServicePackUninstall$\fxsperf.dll
C:\WINNT\$NtServicePackUninstall$\snmptrap.exe
C:\WINNT\$NtServicePackUninstall$\tty.dll
C:\WINNT\$NtUninstallKB840374$\hscupd.exe
C:\WINNT\Fonts\ega40857.fon
C:\WINNT\Fonts\modern.fon
C:\WINNT\inf\netel90a.inf
C:\WINNT\inf\netel980.inf
C:\WINNT\inf\netdf650.PNF
C:\WINNT\inf\mtxvideo.PNF
C:\WINNT\inf\netbcm4u.PNF
C:\WINNT\system32\c_10tman.dll
C:\WINNT\system32\eventvwr.exe
C:\WINNT\system32\npwmsdrm.dll
C:\WINNT\system32\uwdf.exe
C:\WINNT\system32\wdfmgr.exe
C:\WINNT\$hf_mig$\KB902400\SP2QFE\migregdb.exe
C:\WINNT\ServicePackFiles\i386\fxsperf.dll
C:\WINNT\ServicePackFiles\i386\snmptrap.exe
C:\WINNT\ServicePackFiles\i386\tty.dll
C:\WINNT\system32\dllcache\eventvwr.exe
C:\WINNT\system32\dllcache\modern.fon
C:\WINNT\system32\en-US\icardie.dll.mui
C:\WINNT\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem21.CAT
C:\WINNT\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem22.CAT
no matching random used services found

checking for browser helper objects
no known browser helper objects found

checking for appinit files
no files found

checking for possible infected files
please submit these file here: http://www.bleepingcomputer.com/submit-mal….php?channel=11
no files found

checking for Active Setup Installed Components
no known Active Setup Installed Components found

checking iexplore.exe
iexplore.exe is not infected


— Checking for other Goldun, Spybanker and Haxdoor files —
C:\WINNT\system32\P2.INI


— Catchme logfile - thank you Gmer —

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-10 20:15:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"AppInit_DLLs"="\\?\C:\WINNT\System32\lpt3.bsp"

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


— Analysing Catchme logfile —

no matching regkeys found


Finished!



HJT Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:42, on 2009-03-10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: XBTB05988 - {5C43B8A2-24E8-4336-B86E-A94558E10C60} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Blue Dot Toolbar - {2751F3AD-5600-44cc-A653-8A24CAE5AF6D} - C:\Program Files\Blue Dot Toolbar\bdtool.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Office Quick Launcher] iau1.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [HP Component Manager] "c:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [4156015816] "C:\WINNT\system32\manporeg.exe"
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: searchle it! - {0376FDB9-A132-4929-8336-8CB3B2CAFCC0} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles2.js (HKCU)
O9 - Extra button: my!searchles - {3B72BA76-67BE-11DB-8373-B622A1EF5492} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles.js (HKCU)
O16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.com/download.yahoo.com/…_1/yregucfg.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165704139859
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

–
End of file - 8013 bytes




Thanks.
Hi Katsrock,

Re-enable the "Use a proxy Server" if you haven't all ready done so.

Let's see if the combofix log exists.

click the start button, click search
  • click all file and folders
  • enter combofix.txt
  • scroll down and make sure the search in is set to Local Hard Drive ©
  • click search
Please post it if you find it.

Thanks
Hi Katsrock,

Before you had connection problems did you use a Mcafee firewall? Can you recall the events that lead up to the connection problem?


Start with this

  • Open this folder program files > haxfix and double click on fix.bat (or double click on fix.bat desktop icon)
  • Close all other open windows since this step requires a reboot
  • Select option 2. Run auto fix by typing 2 and then pressing Enter
If an infection is found, you'll get a message to close all other open windows.

  • Close all open windows except the red dos window from haxfix and then press Enter
  • The computer will reboot
  • After reboot a logfile will open
  • Post the contents of that logfile along with a new HijackThis log.



Next
Double click LSPfix to run it
  • Check the box beside I know what I'm doing
  • Click on CSLSP.DLL to highlight it
  • Click the >> button
  • The file should now be in the right hand box
  • Click the Finish
You should recieve a Repairs summary window, click ok to close it.

Try connecting now.



This program should give us a view I had hoped the combofix log would have given us.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Please post back with haxfix log, both DDS logs and a new HJT log.

Thanks
Hello oldman960,

No, I did not use Mcafee firewall. The events that led up to the connection problem are:

I did a google search and as I clicked on different search results, I was redirected to an unrelated page. I then updated my Ad-Aware SE, then performed an entire system scan. It uncovered 7 critical objects, so I clicked the button to remove them. I don't remember exactly, but it seems to me my computer rebooted. My connection was lost immediately after that. I unquarantined the items Ad-Aware removed in an attempt to get back my IE connection. That did not work.

I also realized my "System Restore" was not enabled after trying to go that route to get back connectivity. I do not believe the infection caused that. I believe my System Restore was disabled by me several years ago. I ran another Ad-Aware scan to re-remove the viruses it found earlier. This time it found 5 critical objects, so I removed them. I think that is all I did before posting here. I'll post the Ad-Aware log if you like.

Bottom line is I became aware of the infection by clicking on google results and getting redirected. I lost connectivity after I removed objects found in an Ad-Aware SE scan.

To your most recent instructions:

I ran the Haxfix autofix and a new HJT log. I removed the CSLSP.DLL through LSPFix. Still no connection, but it now seems again as though the page loads then is blocked at the last second.

I didn't know exactly how to "Disable any script blocking protection", so after an internet search, I went to Internet Properties>Advanced>Security and clicked to enable "Allow active content to run in files on my computer". I then ran the DDS, but never received a prompt for an Optional Scan, so I don't have that log to post.

Here are the other logs per your request:

HAXFIX logfile - by Marckie

version 5.066
2009-03-11 22:34:49.95

— Auto Haxdoorfix —


Haxdoorfix Part 1

no infections found


Haxdoorfix Part 2

searching for notifykeys
no notifykeys found

searching for services
no services found

searching for safeboot services
no safeboot services found


— Goldun- and SpyBankerfix —


searching for other goldun- spybanker- and haxdoorfiles:
C:\WINNT\system32\P2.INI

checking iexplore.exe
iexplore.exe is not infected

searching for SSODLkeys
no SSODLkeys found

searching for browser helper objects
no known browser helper objects found

searching for appinit files

checking for Active Setup Installed Components
no known Active Setup Installed Components found

searching for notifykeys
no notify keys found

searching for services
no services found


— Registrysettings —

not necessary


…..rebooting the computer…..


— searching for ssodlkeys —

not necessary


— searching for notifykeys —

not necessary


— searching for services —

not necessary


— searching for safeboot services —

not necessary


— searching for browser helper objects —



— searching for active setup installed components —

no known Active Setup Installed Components found


— searching for files —

C:\WINNT\system32\P2.INI found
deleting C:\WINNT\system32\P2.INI
C:\WINNT\system32\P2.INI has been deleted


— searching for other files in the system32 folder —


— searching for other files in windows folder —

no other files found in the windows folder


— searching for a3d files —

fltr.a3d
deleting a3d files
a3d files are deleted


— checking registry settings —

not necessary


— Catchme logfile —

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-11 22:36:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Lsa]
"LsaPid"=dword:000003f8
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Session Manager\Memory Management]
"EnforceWriteProtection"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Watchdog\Display]
"ShutdownCount"=dword:000003cc
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Epoch]
"Epoch"=dword:00002cd8
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{6BDC7BEC-F7D7-4BD5-BCC6-37A03DDC6205}]
"LeaseObtainedTime"=dword:49b6babd
"T1"=dword:49b7637d
"T2"=dword:49b7e20d
"LeaseTerminatesTime"=dword:49b80c3d
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\{6BDC7BEC-F7D7-4BD5-BCC6-37A03DDC6205}\Parameters\Tcpip]
"LeaseObtainedTime"=dword:49b6babd
"T1"=dword:49b7637d
"T2"=dword:49b7e20d
"LeaseTerminatesTime"=dword:49b80c3d
[HKEY_LOCAL_MACHINE\SYSTEM\LastKnownGoodRecovery\LastGood.Tmp]
"INF/oem55.inf"=dword:00000001
"INF/oem55.PNF"=dword:00000001

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3CA95A43C5C690A47A5F63A97371C6A8\Usage]
"AiO_Device"=dword:3a6b0c72
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\532CCD1ACCADF1E4D8116D0336B4A4FE\Usage]
"GalleryFramework"=dword:3a6a013c
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EC868762FFD67F04C9850C11917B1B71\Usage]
"Fax"=dword:3a6a0061
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"AppInit_DLLs"="\\?\C:\WINNT\System32\lpt3.bsp"

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


— checking for random used files and services —
- these files and service are not necessarily malicious
- these files and services will not be deleted by HaxFix
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Movie Maker\MEDIATAB0.DAT
C:\Documents and Settings\Owner\My Documents\My Music\Led Zeppelin\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\The Beatles\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\Various Artists\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\Thin Lizzy\Dedication- The Very Best of Thin Lizzy\AlbumArt_{01110B79-A40D-458E-8643-3234EF5AB3B8}_Large.jpg
C:\Documents and Settings\Owner\My Documents\My Music\Thin Lizzy\Dedication- The Very Best of Thin Lizzy\Folder.jpg
C:\Program Files\Windows Media Connect 2\wmccds.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\Program Files\HP\Digital Imaging\Data\projectstemplates\flowers1_2F_A4.{B439E359-B2DF-4336-AD0E-E567C24D365C}.creativetempl
C:\Program Files\HP\Digital Imaging\Data\projectstemplates\pt-summerC4x6H1template.png
C:\Program Files\Intel\ANS\ianswxp.cat
C:\Program Files\McAfee\McAfee Firewall\fwnetcfg.dll
C:\Program Files\Microsoft Works\1033\Wizards\inspuus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\notrnus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\nottsus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\schbrus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\schesus.wwp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonadd.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttondelete.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonexplorer.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonjewelcase.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonsmartsplit.bmp
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP2\change.log.1
C:\WINNT\$NtServicePackUninstall$\fxsperf.dll
C:\WINNT\$NtServicePackUninstall$\snmptrap.exe
C:\WINNT\$NtServicePackUninstall$\tty.dll
C:\WINNT\$NtUninstallKB840374$\hscupd.exe
C:\WINNT\Fonts\ega40857.fon
C:\WINNT\Fonts\modern.fon
C:\WINNT\inf\netdf650.PNF
C:\WINNT\inf\mtxvideo.PNF
C:\WINNT\system32\c_10tman.dll
C:\WINNT\system32\eventvwr.exe
C:\WINNT\system32\npwmsdrm.dll
C:\WINNT\system32\uwdf.exe
C:\WINNT\system32\wdfmgr.exe
C:\WINNT\$hf_mig$\KB902400\SP2QFE\migregdb.exe
C:\WINNT\ServicePackFiles\i386\fxsperf.dll
C:\WINNT\ServicePackFiles\i386\snmptrap.exe
C:\WINNT\ServicePackFiles\i386\tty.dll
C:\WINNT\system32\dllcache\eventvwr.exe
C:\WINNT\system32\dllcache\modern.fon
C:\WINNT\system32\en-US\icardie.dll.mui
C:\WINNT\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem21.CAT
C:\WINNT\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem22.CAT
no matching services found


Finished


HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:00, on 2009-03-11
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: XBTB05988 - {5C43B8A2-24E8-4336-B86E-A94558E10C60} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Blue Dot Toolbar - {2751F3AD-5600-44cc-A653-8A24CAE5AF6D} - C:\Program Files\Blue Dot Toolbar\bdtool.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Office Quick Launcher] iau1.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [HP Component Manager] "c:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [4156015816] "C:\WINNT\system32\manporeg.exe"
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: searchle it! - {0376FDB9-A132-4929-8336-8CB3B2CAFCC0} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles2.js (HKCU)
O9 - Extra button: my!searchles - {3B72BA76-67BE-11DB-8373-B622A1EF5492} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles.js (HKCU)
O16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.com/download.yahoo.com/…_1/yregucfg.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165704139859
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

–
End of file - 8044 bytes



DDS Log:


DDS (Ver_09-02-01.01) - NTFSx86
Run by [removed] at 23:24:56.00 on 2009-03-11
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.203 [GMT -5:00]

AV: AVG 7.5.557 *On-access scanning disabled* (Updated)

============== Running Processes ===============

C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
C:\WINNT\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\System32\svchost.exe -k imgsvc
C:\WINNT\system32\wscntfy.exe
C:\Documents and Settings\Owner\My Documents\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://new.kentuckysportsradio.com
mStart Page = hxxp://new.kentuckysportsradio.com
uInternet Settings,ProxyServer = http=127.0.0.1:80
uInternet Settings,ProxyOverride =
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: KTBho Class: {25edc164-41a6-47c3-80bd-5e4fbe1ba7ab} - c:\progra~1\kaboodle\kabood~1\KTBar.dll
BHO: {5C43B8A2-24E8-4336-B86E-A94558E10C60} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
TB: Kaboodle Toolbar: {92857633-2441-4a14-8236-dfcb97ad3e87} - c:\progra~1\kaboodle\kabood~1\KTBar.dll
TB: Blue Dot Toolbar: {2751f3ad-5600-44cc-a653-8a24cae5af6d} - c:\program files\blue dot toolbar\bdtool.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {981FE6A8-260C-4930-960F-C3BC82746CB0} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [PopUpStopperFreeEdition] "c:\progra~1\panicw~1\pop-up~1\PSFree.exe"
uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe
mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe
mRun: [mmtask] c:\program files\musicmatch\musicmatch jukebox\mmtask.exe
mRun: [NeroCheck] c:\winnt\system32\NeroCheck.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [MMTray] c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe
mRun: [AVG7_CC] c:\progra~1\grisoft\avgfre~1\avgcc.exe /STARTUP
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [Microsoft Office Quick Launcher] iau1.exe
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRun: [AVG7_Run] c:\progra~1\grisoft\avgfre~1\avgw.exe /RUNONCE
mExplorerRun: [4156015816] "c:\winnt\system32\manporeg.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/controls/yregucfg/2005_6_10_1/yregucfg.cab
DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxps://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
DPF: {49232000-16E4-426C-A231-62846947304B} - hxxp://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxp://www.linkedin.com/cab/LinkedInContactFinderControl.cab
DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165704139859
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - hxxp://mediaplayer.walmart.com/installer/install.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxps://www-secure.symantec.com/techsupp/asa/SymAData.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winnt\system32\WPDShServiceObj.dll
SEH: CShellExecuteHookImpl Object: {54d9498b-cf93-414f-8984-8ce7fde0d391} - c:\program files\ewido\security suite\shellhook.dll

============= SERVICES / DRIVERS ===============

R1 Avg7Core;AVG7 Kernel;c:\winnt\system32\drivers\avg7core.sys [2006-5-24 821856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\winnt\system32\drivers\avg7rsw.sys [2005-10-24 4224]
R1 Avg7RsXP;AVG7 Rezident Driver;c:\winnt\system32\drivers\avg7rsxp.sys [2006-3-15 27776]
R1 AvgClean;AVG7 Clean Driver;c:\winnt\system32\drivers\avgclean.sys [2006-12-13 10760]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avgfre~1\avgamsvr.exe [2005-12-6 418816]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avgfre~1\avgupsvc.exe [2005-10-24 49664]
R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avgfre~1\avgemc.exe [2005-12-6 406528]
R2 AvgTdi;AVG Network Redirector;c:\winnt\system32\drivers\avgtdi.sys [2005-10-24 4960]
R2 ewido security suite control;ewido security suite control;c:\program files\ewido\security suite\ewidoctrl.exe [2004-11-11 16448]
R3 McAfeePF;McAfee Firewall Network Filter Miniport;c:\winnt\system32\drivers\fw220.sys [2002-8-5 33280]
S3 LCcfltr;Logitech USB Filter Driver;c:\winnt\system32\drivers\LCcFltr.Sys [2004-2-26 13724]

=============== Created Last 30 ================

2009-03-10 20:01 512,614 a——- C:\HaxFix.exe
2009-03-10 14:10 389,120 a——- c:\winnt\system32\CF24165.exe
2009-03-10 14:10 –d—– C:\ComboFix
2009-03-10 13:53 a-dshr– C:\cmdcons
2009-03-10 13:51 161,792 a——- c:\winnt\SWREG.exe
2009-03-10 13:51 98,816 a——- c:\winnt\sed.exe
2009-03-10 13:50 389,120 a——- c:\winnt\system32\CF20233.exe
2009-03-10 13:13 –d—– C:\Rooter$
2009-03-10 01:41 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-03-09 23:38 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2009-03-09 23:38 15,504 a——- c:\winnt\system32\drivers\mbam.sys
2009-03-09 23:38 38,496 a——- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-03-09 23:38 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-03-09 23:38 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-03-09 19:31 –d—– c:\program files\Trend Micro

==================== Find3M ====================

2009-01-16 22:35 3,594,752 a——- c:\winnt\system32\dllcache\mshtml.dll
2008-12-19 04:10 70,656 ——– c:\winnt\system32\dllcache\ie4uinit.exe
2008-12-19 04:10 13,824 ——– c:\winnt\system32\dllcache\ieudinit.exe
2008-12-19 00:25 634,024 ——– c:\winnt\system32\dllcache\iexplore.exe
2008-12-19 00:23 161,792 a——- c:\winnt\system32\dllcache\ieakui.dll
2005-10-26 10:31 123,662 a——- c:\program files\smitRem.exe
2004-07-03 15:25 66,048 a——- c:\program files\notepad.exe
2008-08-30 00:50 32,768 a–sh— c:\winnt\system32\config\systemprofile\local settings\history\history.ie5\mshist012008083020080831\index.dat

============= FINISH: 23:25:11.51 ===============


📎Attach.txt



Thanks.
Hi

Mcafee firewall shows in the add/remove programs.

Please post the AdAware logs. Knowing what was removed before the connection went down will be helpful.

Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKLM\..\Run: [Microsoft Office Quick Launcher] iau1.exe
O4 - HKLM\..\Policies\Explorer\Run: [4156015816] "C:\WINNT\system32\manporeg.exe"


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.




We're going to use combofix again, but we will run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

KillAll::

File::
C:\WINNT\system32\manporeg.exe
C:\WINNT\iau1.exe

Registry::

Driver::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Please post back with
  • combofix log
  • new HJT log
  • AdAware logs
Thanks
Hello,

I forgot I even had McAfee. No, it was not running and I just uninstalled it.

Re-ran combofix per your instructions. Worked fine this time, but it prompted me to update to a newer version. So, I did. My email works again and so did the update for combofix. This indicates to me I have internet connection, but the page is somehow blocked in IE.

Here are the logs, but remember the AdAware log was run a second time after I un-quarantined the initial fix that took away my IE. The initial log disappeared after I un-quarantined it :

ADAware Log:

ArchiveData(auto-quarantine- 2009-03-06 14-34-31.bckp)
Referencefile : SE1R340 02.03.2009
======================================================
MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU FileReference : C:\Documents and Settings\Owner\recent\18028DisposableWeddingCameras.jpg.lnk
obj[1]=MRU FileReference : C:\Documents and Settings\Owner\recent\20079carriagecandlecinderella.jpg.lnk
obj[2]=MRU FileReference : C:\Documents and Settings\Owner\recent\20088ChampagneGelCandleFavors.jpg.lnk
obj[3]=MRU FileReference : C:\Documents and Settings\Owner\recent\20089PerfectWeddingDressCandleFavors.jpg.lnk
obj[4]=MRU FileReference : C:\Documents and Settings\Owner\recent\25056GolfBallTealightplacecardholders.jpg.lnk
obj[5]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\search assistant\acmru\5603
obj[6]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\search assistant\acmru\5604
obj[7]=MRU FileReference : C:\Documents and Settings\Owner\recent\KA31001NA-L.jpg.lnk
obj[8]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[9]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\windows\currentversion\explorer\recentdocs\.bmp
obj[10]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\windows\currentversion\explorer\recentdocs\.jpg
obj[11]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\windows\currentversion\explorer\recentdocs\.wps
obj[13]=MRU RegReference : software\microsoft\direct3d\mostrecentapplication name
obj[14]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\windows\currentversion\explorer\runmru
obj[15]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\windows media\wmsdk\general computername
obj[16]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\internet explorer\typedurls
obj[12]=MRU RegReference : S-1-5-21-2468393796-743131199-3449879890-1003\software\microsoft\windows\currentversion\explorer\recentdocs\Folder
WIN32.TROJAN.AGENT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[12]=Regkey : system\controlset001\enum\root\legacy__11f*00df*00e4*0006#*00b7*00ba*00c4*00d6`i
obj[13]=Regkey : system\currentcontrolset\enum\root\legacy__11f*00df*00e4*0006#*00b7*00ba*00c4*00d6`i
obj[14]=File : C:\Documents and Settings\Owner\Local Settings\Temp\csrss7.dll
obj[15]=File : C:\WINNT\system32\csrss7.dll
obj[16]=File : C:\WINNT\system32\svchost.exe


ComboFix Log:

ComboFix 09-03-10.03 - Owner 2009-03-12 18:50:22.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.218 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AVG 7.5.557 *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\winnt\iau1.exe
c:\winnt\system32\manporeg.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\winnt\genjc1.dll
c:\winnt\system32\manporeg.exe
.
—- Previous Run ——-
.
c:\documents and settings\Owner\My Documents\notepad.exe
c:\winnt\system32\lpt3.bsp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NTIO256
——-\Legacy_VDMT16
——-\Legacy_WINLOW


((((((((((((((((((((((((( Files Created from 2009-02-12 to 2009-03-12 )))))))))))))))))))))))))))))))
.

2009-03-10 20:01 . 2009-03-10 19:52 512,614 –a—— C:\HaxFix.exe
2009-03-10 13:13 . 2009-03-10 13:16 d——– C:\Rooter$
2009-03-10 01:41 . 2009-03-10 01:41 d——– c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-09 23:38 . 2009-03-09 23:38 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-09 23:38 . 2009-03-09 23:38 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2009-03-09 23:38 . 2009-03-09 23:38 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-09 23:38 . 2009-02-11 10:19 38,496 –a—— c:\winnt\system32\drivers\mbamswissarmy.sys
2009-03-09 23:38 . 2009-02-11 10:19 15,504 –a—— c:\winnt\system32\drivers\mbam.sys
2009-03-09 23:31 . 2009-03-09 23:32 d——– c:\program files\ERUNT
2009-03-09 19:31 . 2009-03-09 19:31 d——– c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-12 17:04 ——— d—–w c:\program files\McAfee
2009-03-10 06:55 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-03-10 06:54 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-10 04:56 ——— d—–w c:\documents and settings\Owner\Application Data\AVG7
2009-02-20 14:00 ——— d—–w c:\documents and settings\LocalService\Application Data\AVG7
2005-10-26 15:31 123,662 —-a-w c:\program files\smitRem.exe
2004-07-03 20:25 66,048 —-a-w c:\program files\notepad.exe
2008-08-30 05:50 32,768 –sha-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008083020080831\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-03-10_14.07.19.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-09 11:08:53 1,847,552 —-a-w c:\winnt\$hf_mig$\KB958690\SP3QFE\win32k.sys
+ 2008-07-09 07:38:24 17,272 —-a-w c:\winnt\$hf_mig$\KB958690\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w c:\winnt\$hf_mig$\KB958690\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w c:\winnt\$hf_mig$\KB958690\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w c:\winnt\$hf_mig$\KB958690\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w c:\winnt\$hf_mig$\KB958690\update\updspapi.dll
+ 2008-12-05 06:58:08 144,896 —-a-w c:\winnt\$hf_mig$\KB960225\SP3QFE\schannel.dll
+ 2007-11-30 11:18:51 17,272 —-a-w c:\winnt\$hf_mig$\KB960225\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\winnt\$hf_mig$\KB960225\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\winnt\$hf_mig$\KB960225\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\winnt\$hf_mig$\KB960225\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\winnt\$hf_mig$\KB960225\update\updspapi.dll
+ 2008-12-05 06:54:55 144,896 ——w c:\winnt\system32\dllcache\schannel.dll
- 2008-09-15 12:12:56 1,846,400 ——w c:\winnt\system32\dllcache\win32k.sys
+ 2009-02-09 11:13:27 1,846,784 ——w c:\winnt\system32\dllcache\win32k.sys
- 2008-10-15 20:25:40 754,952 —-a-w c:\winnt\system32\FNTCACHE.DAT
+ 2009-03-12 17:15:39 754,952 —-a-w c:\winnt\system32\FNTCACHE.DAT
- 2008-04-14 00:12:05 144,384 —-a-w c:\winnt\system32\schannel.dll
+ 2008-12-05 06:54:55 144,896 —-a-w c:\winnt\system32\schannel.dll
- 2008-07-09 07:38:24 17,272 ——w c:\winnt\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ——w c:\winnt\system32\spmsg.dll
- 2007-08-11 01:46:18 26,488 —-a-w c:\winnt\system32\spupdsvc.exe
+ 2007-07-27 14:41:38 26,488 —-a-w c:\winnt\system32\spupdsvc.exe
- 2008-09-15 12:12:56 1,846,400 —-a-w c:\winnt\system32\win32k.sys
+ 2009-02-09 11:13:27 1,846,784 —-a-w c:\winnt\system32\win32k.sys
- 2007-06-12 04:51:12 10,834,944 —-a-w c:\winnt\system32\wmp.dll
+ 2008-11-11 23:34:42 10,838,016 —-a-w c:\winnt\system32\wmp.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~1\PSFree.exe" [2003-10-29 524288]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2003-11-18 155648]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2003-11-18 118784]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-06-26 53248]
"NeroCheck"="c:\winnt\System32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2002-05-20 90112]
"AVG7_CC"="c:\progra~1\Grisoft\AVGFRE~1\avgcc.exe" [2009-02-24 590848]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-24 28672]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [BU]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-23 219136]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-29 53248]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 282624]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware SE Personal\\Ad-Aware.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgw.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgvv.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4340:TCP"= 4340:TCP:WWW
"110:TCP"= 110:TCP:svchost

S3 LCcfltr;Logitech USB Filter Driver;c:\winnt\system32\drivers\LCcFltr.Sys [2004-02-26 13724]
.
Contents of the 'Scheduled Tasks' folder

2004-02-27 c:\winnt\Tasks\ISP signup reminder 1.job
- c:\winnt\System32\OOBE\oobebaln.exe [2008-04-13 19:12]

2004-03-07 c:\winnt\Tasks\ISP signup reminder 2.job
- c:\winnt\System32\OOBE\oobebaln.exe [2008-04-13 19:12]

2004-03-12 c:\winnt\Tasks\ISP signup reminder 3.job
- c:\winnt\System32\OOBE\oobebaln.exe [2008-04-13 19:12]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Explorer_Run-4156015816 - c:\winnt\system32\manporeg.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://new.kentuckysportsradio.com
mStart Page = hxxp://new.kentuckysportsradio.com
uInternet Settings,ProxyServer = http=127.0.0.1:80
uInternet Settings,ProxyOverride =
DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/controls/yregucfg/2005_6_10_1/yregucfg.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-12 18:54:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MMTray = c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe?w???g????V??g????SOFTWARE\MusicMatch\MusicMatch Jukebox\4.0\TrayApp???%X??????????????????>?w0 ?w????3??w???g8!?????????g?RY??QY????????g????2??????? ???8???? @??%X??%X???????????????????Y?????n?Q?????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\progra~1\Grisoft\AVGFRE~1\avgamsvr.exe
c:\progra~1\Grisoft\AVGFRE~1\avgupsvc.exe
c:\progra~1\Grisoft\AVGFRE~1\avgemc.exe
c:\program files\ewido\security suite\ewidoctrl.exe
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\winnt\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-12 18:59:49 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2009-03-12 23:59:27

Pre-Run: 43,299,643,392 bytes free
Post-Run: 43,296,256,000 bytes free

174 — E O F — 2009-03-12 16:44:57


HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:07:34 PM, on 3/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: XBTB05988 - {5C43B8A2-24E8-4336-B86E-A94558E10C60} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Blue Dot Toolbar - {2751F3AD-5600-44cc-A653-8A24CAE5AF6D} - C:\Program Files\Blue Dot Toolbar\bdtool.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [HP Component Manager] "c:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: searchle it! - {0376FDB9-A132-4929-8336-8CB3B2CAFCC0} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles2.js (HKCU)
O9 - Extra button: my!searchles - {3B72BA76-67BE-11DB-8373-B622A1EF5492} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles.js (HKCU)
O16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.com/download.yahoo.com/…_1/yregucfg.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165704139859
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

–
End of file - 7799 bytes



Thanks.
Hi Katsrock,

Ok, we can safely say you have an internet connection.

Do you recall the version/year of the Mcafee firewall?

Let's see if you didn't pick an addon that shouldn't be there.

Make sure all IE browsers are closed
  • click the start button,
  • highlight all programs,
  • highlight accessories,
  • highlight System Tools,
  • click Internet Explorer (no add ons)
This will lauuch IE without any add ones. You will get a popup notifing you that add ons are disabled

See if you can now get online.



And we'll have a look with another tool.

Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: [external image: Posted Image]
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again
  • After the update, from the "File" menu, choose "Standard Scripts"
  • Put a check next to item 2: Advanced System Investigation
  • Click Execute selected scripts
  • At the next prompt, click the OK button
  • Let the scan run and click "OK" when the completion prompt pops up
  • Now Close out of the Standard Scripts window, and exit AVZ
  • Navigate to the avz4 folder and locate the folder LOG
  • Inside the LOG folder you will find virusinfo_syscheck.htm and virusinfo_syscheck.zip
  • Attach virusinfo_syscheck.zip to your next reply, along with a fresh HijackThis log

Thanks
Hello oldman960,

The McAfee firewall version/year was 2004 I think. Before I uninstalled it, it said it was not active and the subscription had run out. I believe it came with my computer when I bought it.

As instructed, I opened IE with no add-ons. My home page was still blocked. On a lark, I decided to try to click to another site (Yahoo login) and a "Security Alert" popup appears that says "You are about to view pages over a secure connection. Any information you exchange with this site cannot be viewed by anyone else on the web." So, I clicked OK and the login page was displayed. I then closed the "No add-ons" window to see if I could open it in regular mode. It worked! However, no other sites I went to were displayed in "No add-ons" mode, or regular mode. Only the secure Yahoo Login page would dispplay. I did not attempt to login.

I tried both scources available, but the update to AVZ4 did not function.

Here is the attached log of the non-updated version of AVZ4:

📎virusinfo_syscheck.zip


Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:22 AM, on 3/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\explorer.exe
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: XBTB05988 - {5C43B8A2-24E8-4336-B86E-A94558E10C60} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Blue Dot Toolbar - {2751F3AD-5600-44cc-A653-8A24CAE5AF6D} - C:\Program Files\Blue Dot Toolbar\bdtool.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [HP Component Manager] "c:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: searchle it! - {0376FDB9-A132-4929-8336-8CB3B2CAFCC0} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles2.js (HKCU)
O9 - Extra button: my!searchles - {3B72BA76-67BE-11DB-8373-B622A1EF5492} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles.js (HKCU)
O16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.com/download.yahoo.com/…_1/yregucfg.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165704139859
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

–
End of file - 7822 bytes




Thanks.
Hi katsrock,

Thanks for the new info. With our experimenting, it would appear you are using a proxy as when you unchecked "Use a proxy server…". your mail stopped working and started working again after rechecking it.

Let's make sure one other setting is correct.

In IE, click Tools, click Internet Options
  • Click the Advanced tab
  • Scroll down to Http 1.1 Settings
  • Make sure both boxes are checked.
  • click apply, click OK
  • Close IE, open it again
Any luck?

Thanks
Hi Katsrock,

The way I read it, the connection started working again while you where using combpfix. Now I could be wrong. :)

Let's try a different browser. If we can get Firefox to access the internet, then the problem lies within IE. If we can get online, will also be able to finish cleaning your computer then dig deeper into the no HTTP with IE.

You can get FireFox3 from HERE

Let me know how you make out.

Thanks
Hello, Downloaded Firefox. Got a popup that says: "Proxy Server Refused Connection" I checked to see if the Yahoo Login page would load and it did. Then I did a google search on proxy servers and how to fix connections. After reading up on that, I went to Firefox tools>options>advanced>network>settings> then clicked "No Proxy" This solved the internet connection problem. Firefox now loads both secure and unsecure pages. Hurraaah!! How now?
Hi Katsrock, For firefox try this Check the connection settings: Click Tools > Options > Advanced Tab Click the Network Tab In the Connection box, click settings check "Direct connection to the internet"
Hello, There is no "Direct connection to the internet" option. There are only 4 options: 1 No proxy (which I checked and now have internet access) 2 Auto detect proxy settings… 3 Manual proxy config…. 4 Auto Proxy config… So, when you say, "For firefox try this", are you trying to get me an internet connection? I already have that now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI