This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] New and completely clueless

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok I'm new to the forum thing in general. I was pointed this direction by a friend.

I tried looking through the self helps and am still lost. I know there is something wrong, but do not know what the problem is. When I use google, I chick on one of the results from my search and it seems to load another identical result list and then forwards me to some completely random website… yellow pages, video website, etc. I've tried to download and run numerous programs in hopes that it will help, but none seem to work… at all. Not sure if its because I'm running Vista or not. Anyway I'll post my hijackthis log and pray that someone can help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:44:04 AM, on 3/9/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Users\Capn Ron\Program Files\DNA\btdna.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Capn Ron\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8174 bytes

I thank you for your time in advance.
Hi,

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
Ok I keep running into this problem. When I go to the page to download Malwarebyte's Anti-Malware it blocks the page. Then when I transfered it from my other computer it installed but then when I go to run it nothing happens. Not sure if you wanted me to do the DDS step without running the Malwarebyte's. I did notice one other thing. Something called DecodingHQ has appeared on my computer. Not sure if that means anything.
DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 16:35:29.58 on Thu 03/12/2009 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2046.1192 [GMT -4:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\system32\taskeng.exe C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files\Steam\steam.exe C:\Users\Capn Ron\Program Files\DNA\btdna.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Common Files\Steam\SteamService.exe C:\Program Files\AIM6\aim6.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\BitTorrent\bittorrent.exe C:\Windows\system32\taskeng.exe C:\Program Files\AIM6\aolsoftware.exe C:\Windows\system32\taskeng.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Ron\virus\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=c:\windows\system32\userinit.exe BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: NoExplorer - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File uRun: [Aim6] uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [BitTorrent DNA] "c:\users\capn ron\program files\dna\btdna.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe mRun: [Apoint] c:\program files\apoint2k\Apoint.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-3-8 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-3-8 20560] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-3-8 51792] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-10-12 24652] S3 suknvrx;suknvrx;c:\users\capn ron\suknvrx.sys [2008-12-13 31232] =============== Created Last 30 ================ 2009-03-12 12:38 –d—– c:\program files\common files\Steam 2009-03-12 12:38 –d—– c:\program files\Steam 2009-03-12 12:37 –d—– c:\program files\Microsoft Games for Windows - LIVE 2009-03-12 12:35 509,448 a——- c:\windows\system32\XAudio2_2.dll 2009-03-12 12:35 68,616 a——- c:\windows\system32\XAPOFX1_1.dll 2009-03-12 12:35 238,088 a——- c:\windows\system32\xactengine3_2.dll 2009-03-12 12:35 1,493,528 a——- c:\windows\system32\D3DCompiler_39.dll 2009-03-12 12:35 467,984 a——- c:\windows\system32\d3dx10_39.dll 2009-03-12 12:35 3,851,784 a——- c:\windows\system32\D3DX9_39.dll 2009-03-10 17:37 –d—– c:\users\capnro~1\appdata\roaming\Red Alert 3 2009-03-10 16:55 –d—– C:\RA3 2009-03-10 05:52 –d—– c:\program files\TimeGate Studios 2009-03-09 04:31 –d—– C:\fixwareout 2009-03-08 21:14 a-d—– c:\programdata\TEMP 2009-03-08 20:01 51,792 a——- c:\windows\system32\drivers\aswMonFlt.sys 2009-03-07 16:38 –d—– c:\program files\CCleaner 2009-03-07 16:01 –d—– c:\program files\WOT 2009-03-07 15:48 –d—– c:\programdata\Lavasoft 2009-03-07 15:14 –d—– c:\program files\Trend Micro 2009-03-07 15:00 –d—– c:\users\capn ron\.housecall6.6 2009-03-07 14:29 331 —shr– C:\autorun.inf 2009-03-07 03:16 –d—– c:\program files\livetvbar 2009-03-07 03:16 –d—– c:\program files\Conduit 2009-03-06 19:40 –d—– c:\users\capnro~1\appdata\roaming\LucasArts 2009-03-04 19:43 –d—– C:\MM2 2009-03-04 18:18 –d—– C:\MM 2009-03-02 06:54 –d-h— c:\programdata\{F71301CF-0E9E-468F-B1CE-FEC9F977CAAF} 2009-03-02 06:54 –d-h— c:\progra~2\{F71301CF-0E9E-468F-B1CE-FEC9F977CAAF} 2009-03-02 06:54 –d—– c:\program files\RiffTrax DVD Player 2009-03-02 06:50 –d—– c:\users\capn ron\EurekaLog 2009-03-02 06:26 –d—– c:\users\capnro~1\appdata\roaming\EurekaLog 2009-02-28 02:40 –d—– c:\users\capnro~1\appdata\roaming\DAEMON Tools Pro 2009-02-28 02:39 –d—– c:\programdata\DAEMON Tools Lite 2009-02-28 02:39 –d—– c:\progra~2\DAEMON Tools Lite 2009-02-28 02:35 717,296 a——- c:\windows\system32\drivers\sptd.sys 2009-02-28 02:35 –d—– c:\users\capnro~1\appdata\roaming\DAEMON Tools Lite 2009-02-21 23:54 –d—– C:\FEAR 2009-02-18 17:02 98,304 a——- c:\windows\system32\CmdLineExt.dll 2009-02-18 16:42 –d—– c:\program files\V 2009-02-18 02:40 –d—– C:\Marvel Vs 2009-02-17 21:25 –d—– C:\FREEDOM FIGHTERS 2009-02-17 16:03 –d—– C:\Xeen 2009-02-15 18:19 533 a——- c:\windows\eReg.dat 2009-02-15 00:41 7,552 a——- c:\windows\system32\drivers\enodpl.sys 2009-02-15 00:41 4,736 a——- c:\windows\system32\drivers\tandpl.sys 2009-02-14 19:29 428,544 a——- c:\windows\system32\EncDec.dll 2009-02-14 19:29 217,088 a——- c:\windows\system32\psisrndr.ax 2009-02-14 19:29 293,376 a——- c:\windows\system32\psisdecd.dll 2009-02-14 19:29 177,664 a——- c:\windows\system32\mpg2splt.ax 2009-02-14 19:29 80,896 a——- c:\windows\system32\MSNP.ax 2009-02-11 19:26 827,392 a——- c:\windows\system32\wininet.dll 2009-02-11 19:26 1,383,424 a——- c:\windows\system32\mshtml.tlb ==================== Find3M ==================== 2009-03-12 14:23 27,620 a——- c:\users\capnro~1\appdata\roaming\nvModes.dat 2009-03-07 16:20 410,984 a——- c:\windows\system32\deploytk.dll 2009-01-12 23:50 86,016 a——- c:\windows\inf\infstrng.dat 2009-01-12 23:50 86,016 a——- c:\windows\inf\infstor.dat 2009-01-12 23:50 51,200 a——- c:\windows\inf\infpub.dat 2008-12-23 19:46 201,816 a——- c:\windows\system32\PnkBstrB.exe 2008-12-13 12:32 31,232 a——- c:\users\capn ron\suknvrx.sys 2008-12-13 12:27 1,081,344 a——- c:\users\capn ron\hmqemrfmfm.exe 2008-12-13 12:27 294,912 a——- c:\users\capn ron\GRefs.dat 2008-12-13 12:27 31,232 a——- c:\users\capn ron\Shadow.sys 2008-12-13 12:27 40,960 a——- c:\users\capn ron\GliderTell.exe 2008-12-01 00:32 22,328 a——- c:\users\capnro~1\appdata\roaming\PnkBstrK.sys 2008-09-27 06:59 665,600 a——- c:\windows\inf\drvindex.dat 2008-01-20 22:43 174 a–sh— c:\program files\desktop.ini 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 16:36:09.13 ===============

Attachments:

Hi,

Do you recognize these?
c:\users\capn ron\Shadow.sys
c:\users\capn ron\GliderTell.exe

From what I can see, they appear to be some sort of WorldOfWarcraft hacks. They almost certainly came with Malware, if they haven't got it embedded in them anyway.


1. Go to Start->Run and type in notepad and hit OK.

2. Then copy and paste the content of the following codebox into Notepad:

@echo off
sc stop suknvrx
sc delete suknvrx
del /Q "c:\users\capn ron\suknvrx.sys"
del /Q "c:\users\capn ron\hmqemrfmfm.exe"
del /Q %0

3. Save the file to your DESKTOP as "fix.bat". Make sure to save it with the quotes. Once saved, the icon to click should look like this on your desktop: [external image: Posted Image]

4. Double click fix.bat.


After that has run, please try running MalwareBytes' again. Please also post a new DDS log (DDS.txt).

Thanks.
Tried running Malwarebytes again, but to no avail. I'm sorry if i'm doing something wrong. DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 8:00:19.93 on Fri 03/13/2009 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2046.1233 [GMT -4:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\BitTorrent\bittorrent.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Capn Ron\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=c:\windows\system32\userinit.exe BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: NoExplorer - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File uRun: [Aim6] mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-3-8 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-3-8 20560] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-3-8 51792] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-10-12 24652] =============== Created Last 30 ================ 2009-03-13 07:44 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-03-13 07:44 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-03-13 07:44 –d—– c:\programdata\Malwarebytes 2009-03-13 07:44 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-03-13 07:44 –d—– c:\progra~2\Malwarebytes 2009-03-12 12:38 –d—– c:\program files\common files\Steam 2009-03-12 12:38 –d—– c:\program files\Steam 2009-03-12 12:37 –d—– c:\program files\Microsoft Games for Windows - LIVE 2009-03-12 12:35 509,448 a——- c:\windows\system32\XAudio2_2.dll 2009-03-12 12:35 68,616 a——- c:\windows\system32\XAPOFX1_1.dll 2009-03-12 12:35 238,088 a——- c:\windows\system32\xactengine3_2.dll 2009-03-12 12:35 1,493,528 a——- c:\windows\system32\D3DCompiler_39.dll 2009-03-12 12:35 467,984 a——- c:\windows\system32\d3dx10_39.dll 2009-03-12 12:35 3,851,784 a——- c:\windows\system32\D3DX9_39.dll 2009-03-10 17:37 –d—– c:\users\capnro~1\appdata\roaming\Red Alert 3 2009-03-10 16:55 –d—– C:\RA3 2009-03-10 05:52 –d—– c:\program files\TimeGate Studios 2009-03-09 04:31 –d—– C:\fixwareout 2009-03-08 21:14 a-d—– c:\programdata\TEMP 2009-03-08 20:01 51,792 a——- c:\windows\system32\drivers\aswMonFlt.sys 2009-03-07 16:38 –d—– c:\program files\CCleaner 2009-03-07 16:01 –d—– c:\program files\WOT 2009-03-07 15:48 –d—– c:\programdata\Lavasoft 2009-03-07 15:14 –d—– c:\program files\Trend Micro 2009-03-07 15:00 –d—– c:\users\capn ron\.housecall6.6 2009-03-07 14:29 331 —shr– C:\autorun.inf 2009-03-07 03:16 –d—– c:\program files\livetvbar 2009-03-07 03:16 –d—– c:\program files\Conduit 2009-03-06 19:40 –d—– c:\users\capnro~1\appdata\roaming\LucasArts 2009-03-04 19:43 –d—– C:\MM2 2009-03-04 18:18 –d—– C:\MM 2009-03-02 06:54 –d-h— c:\programdata\{F71301CF-0E9E-468F-B1CE-FEC9F977CAAF} 2009-03-02 06:54 –d-h— c:\progra~2\{F71301CF-0E9E-468F-B1CE-FEC9F977CAAF} 2009-03-02 06:54 –d—– c:\program files\RiffTrax DVD Player 2009-03-02 06:50 –d—– c:\users\capn ron\EurekaLog 2009-03-02 06:26 –d—– c:\users\capnro~1\appdata\roaming\EurekaLog 2009-02-28 02:40 –d—– c:\users\capnro~1\appdata\roaming\DAEMON Tools Pro 2009-02-28 02:39 –d—– c:\programdata\DAEMON Tools Lite 2009-02-28 02:39 –d—– c:\progra~2\DAEMON Tools Lite 2009-02-28 02:35 717,296 a——- c:\windows\system32\drivers\sptd.sys 2009-02-28 02:35 –d—– c:\users\capnro~1\appdata\roaming\DAEMON Tools Lite 2009-02-21 23:54 –d—– C:\FEAR 2009-02-18 17:02 98,304 a——- c:\windows\system32\CmdLineExt.dll 2009-02-18 16:42 –d—– c:\program files\V 2009-02-18 02:40 –d—– C:\Marvel Vs 2009-02-17 21:25 –d—– C:\FREEDOM FIGHTERS 2009-02-17 16:03 –d—– C:\Xeen 2009-02-15 18:19 533 a——- c:\windows\eReg.dat 2009-02-15 00:41 7,552 a——- c:\windows\system32\drivers\enodpl.sys 2009-02-15 00:41 4,736 a——- c:\windows\system32\drivers\tandpl.sys 2009-02-14 19:29 428,544 a——- c:\windows\system32\EncDec.dll 2009-02-14 19:29 217,088 a——- c:\windows\system32\psisrndr.ax 2009-02-14 19:29 293,376 a——- c:\windows\system32\psisdecd.dll 2009-02-14 19:29 177,664 a——- c:\windows\system32\mpg2splt.ax 2009-02-14 19:29 80,896 a——- c:\windows\system32\MSNP.ax 2009-02-11 19:26 827,392 a——- c:\windows\system32\wininet.dll 2009-02-11 19:26 1,383,424 a——- c:\windows\system32\mshtml.tlb ==================== Find3M ==================== 2009-03-12 14:23 27,620 a——- c:\users\capnro~1\appdata\roaming\nvModes.dat 2009-03-07 16:20 410,984 a——- c:\windows\system32\deploytk.dll 2009-01-12 23:50 86,016 a——- c:\windows\inf\infstrng.dat 2009-01-12 23:50 86,016 a——- c:\windows\inf\infstor.dat 2009-01-12 23:50 51,200 a——- c:\windows\inf\infpub.dat 2008-12-23 19:46 201,816 a——- c:\windows\system32\PnkBstrB.exe 2008-12-13 12:27 294,912 a——- c:\users\capn ron\GRefs.dat 2008-12-13 12:27 40,960 a——- c:\users\capn ron\GliderTell.exe 2008-12-01 00:32 22,328 a——- c:\users\capnro~1\appdata\roaming\PnkBstrK.sys 2008-09-27 06:59 665,600 a——- c:\windows\inf\drvindex.dat 2008-01-20 22:43 174 a–sh— c:\program files\desktop.ini 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 8:00:49.83 ===============

Attachments:

Hi,

We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

c:\users\capn ron\GliderTell.exe

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.


Just curious, please right-click MalwareBytes' AntiMalware and select Run As Administrator…. I am not expecting it to be any different, but just wondered.


Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Right click on the avast! icon in system tray (looks like this: [external image: Posted Image]) and choose (Stop On-Access Protection)

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks.
Ok I uploaded that file and it came back clean. I'm not really sure what it even does, I had WoW removed from this system a few months ago.

I ran MalwareBytes' AntiMalware as administrator. Instead of it doing nothing, it came back that there was an error and the program had to be ended.

I ran ComboFix… my problem with internet explorer seems to be cleared up now. Here is the log, I really appreciate all your help.

ComboFix 09-03-12.01 - Capn Ron 2009-03-13 10:45:49.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2046.1124 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
c:\users\Capn Ron\AppData\Roaming\EurekaLog
c:\users\Capn Ron\AppData\Roaming\EurekaLog\RiffTrax\RiffTrax_CAPNRON-PC.elf
c:\users\Capn Ron\Documents\My Documents.url
c:\windows\system32\drivers\gaopdxxgpeeiyrbkocqvpubtqjurvehqeisojc.sys
c:\windows\system32\gaopdxbtfdfepirwtqigqfdmnunrgrgvccpiry.dll
c:\windows\system32\KBL.LOG
D:\Autorun.inf
d:\recycler\S-4-4-52-100007912-100030067-100004076-6594.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_gaopdxserv.sys


((((((((((((((((((((((((( Files Created from 2009-02-13 to 2009-03-13 )))))))))))))))))))))))))))))))
.

2009-03-13 07:44 . 2009-03-13 07:44 d——– c:\users\All Users\Malwarebytes
2009-03-13 07:44 . 2009-03-13 07:44 d——– c:\programdata\Malwarebytes
2009-03-13 07:44 . 2009-03-13 07:44 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-13 07:44 . 2009-01-14 16:11 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-03-13 07:44 . 2009-01-14 16:11 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-03-12 12:38 . 2009-03-13 08:55 d——– c:\program files\Steam
2009-03-12 12:38 . 2009-03-12 15:04 d——– c:\program files\Common Files\Steam
2009-03-12 12:37 . 2009-03-12 12:37 d——– c:\program files\Microsoft Games for Windows - LIVE
2009-03-12 12:35 . 2008-07-12 08:18 3,851,784 –a—— c:\windows\System32\D3DX9_39.dll
2009-03-12 12:35 . 2008-07-12 08:18 1,493,528 –a—— c:\windows\System32\D3DCompiler_39.dll
2009-03-12 12:35 . 2008-07-31 10:40 509,448 –a—— c:\windows\System32\XAudio2_2.dll
2009-03-12 12:35 . 2008-07-12 08:18 467,984 –a—— c:\windows\System32\d3dx10_39.dll
2009-03-12 12:35 . 2008-07-31 10:41 238,088 –a—— c:\windows\System32\xactengine3_2.dll
2009-03-12 12:35 . 2008-07-31 10:41 68,616 –a—— c:\windows\System32\XAPOFX1_1.dll
2009-03-10 17:37 . 2009-03-11 11:48 d——– c:\users\Capn Ron\AppData\Roaming\Red Alert 3
2009-03-10 16:55 . 2009-03-11 19:49 d——– C:\RA3
2009-03-10 05:52 . 2009-03-10 05:52 d——– c:\program files\TimeGate Studios
2009-03-09 04:31 . 2009-03-09 04:32 d——– C:\fixwareout
2009-03-08 21:14 . 2009-03-08 21:17 d-a—— c:\users\All Users\TEMP
2009-03-08 21:14 . 2009-03-08 21:17 d-a—— c:\programdata\TEMP
2009-03-08 20:01 . 2009-03-08 20:01 d——– c:\program files\Alwil Software
2009-03-08 20:01 . 2009-02-05 16:06 51,792 –a—— c:\windows\System32\drivers\aswMonFlt.sys
2009-03-07 16:38 . 2009-03-07 16:39 d——– c:\program files\CCleaner
2009-03-07 16:01 . 2009-03-07 16:01 d——– c:\program files\WOT
2009-03-07 15:48 . 2009-03-08 22:10 d——– c:\users\All Users\Lavasoft
2009-03-07 15:48 . 2009-03-08 22:10 d——– c:\programdata\Lavasoft
2009-03-07 15:14 . 2009-03-07 15:14 d——– c:\program files\Trend Micro
2009-03-07 15:00 . 2009-03-07 16:35 d——– c:\users\Capn Ron\.housecall6.6
2009-03-07 03:16 . 2009-03-07 15:51 d——– c:\program files\livetvbar
2009-03-07 03:16 . 2009-03-07 15:51 d——– c:\program files\Conduit
2009-03-06 19:40 . 2009-03-06 19:40 d——– c:\users\Capn Ron\AppData\Roaming\LucasArts
2009-03-04 19:43 . 2009-03-05 02:20 d——– C:\MM2
2009-03-04 18:18 . 2009-03-05 08:29 d——– C:\MM
2009-03-02 06:54 . 2009-03-02 06:54 d–h—– c:\users\All Users\{F71301CF-0E9E-468F-B1CE-FEC9F977CAAF}
2009-03-02 06:54 . 2009-03-02 06:54 d–h—– c:\programdata\{F71301CF-0E9E-468F-B1CE-FEC9F977CAAF}
2009-03-02 06:54 . 2009-03-02 06:54 d——– c:\program files\RiffTrax DVD Player
2009-03-02 06:50 . 2009-03-02 06:50 d——– c:\users\Capn Ron\EurekaLog
2009-02-28 02:40 . 2009-02-28 02:40 d——– c:\users\Capn Ron\AppData\Roaming\DAEMON Tools Pro
2009-02-28 02:40 . 2009-02-28 02:40 d——– c:\users\Capn Ron\AppData\Roaming\DAEMON Tools
2009-02-28 02:39 . 2009-02-28 02:39 d——– c:\users\All Users\DAEMON Tools Lite
2009-02-28 02:39 . 2009-02-28 02:39 d——– c:\programdata\DAEMON Tools Lite
2009-02-28 02:35 . 2009-02-28 02:41 d——– c:\users\Capn Ron\AppData\Roaming\DAEMON Tools Lite
2009-02-28 02:35 . 2009-02-28 02:35 717,296 –a—— c:\windows\System32\drivers\sptd.sys
2009-02-21 23:54 . 2009-02-22 00:08 d——– C:\FEAR
2009-02-18 17:02 . 2009-02-18 17:02 98,304 –a—— c:\windows\System32\CmdLineExt.dll
2009-02-18 16:42 . 2009-02-18 16:42 d——– c:\program files\V
2009-02-18 02:40 . 2009-02-18 18:45 d——– C:\Marvel Vs
2009-02-17 21:25 . 2009-02-17 21:25 d——– C:\FREEDOM FIGHTERS
2009-02-17 16:03 . 2009-02-17 17:07 d——– C:\Xeen
2009-02-15 18:19 . 2009-02-15 18:28 533 –a—— c:\windows\eReg.dat
2009-02-15 00:41 . 2003-03-02 18:44 7,552 –a—— c:\windows\System32\drivers\enodpl.sys
2009-02-15 00:41 . 2003-04-19 01:32 4,736 –a—— c:\windows\System32\drivers\tandpl.sys
2009-02-14 19:29 . 2008-12-05 00:32 428,544 –a—— c:\windows\System32\EncDec.dll
2009-02-14 19:29 . 2008-12-05 00:32 293,376 –a—— c:\windows\System32\psisdecd.dll
2009-02-14 19:29 . 2008-12-05 00:31 217,088 –a—— c:\windows\System32\psisrndr.ax
2009-02-14 19:29 . 2008-12-05 00:31 177,664 –a—— c:\windows\System32\mpg2splt.ax
2009-02-14 19:29 . 2008-12-05 00:31 80,896 –a—— c:\windows\System32\MSNP.ax

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-13 14:43 ——— d—–w c:\users\Capn Ron\AppData\Roaming\BitTorrent
2009-03-13 12:47 ——— d—–w c:\program files\tuitalker
2009-03-12 21:14 ——— d—–w c:\users\Capn Ron\AppData\Roaming\DNA
2009-03-12 18:23 27,620 —-a-w c:\users\Capn Ron\AppData\Roaming\nvModes.dat
2009-03-11 23:09 ——— d—–w c:\programdata\Electronic Arts
2009-03-11 18:25 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-11 18:25 ——— d—–w c:\program files\LucasArts
2009-03-07 20:39 ——— d—–w c:\program files\Yahoo!
2009-03-07 20:20 410,984 —-a-w c:\windows\System32\deploytk.dll
2009-03-07 20:20 ——— d—–w c:\program files\Java
2009-03-03 10:34 ——— d—–w c:\users\Capn Ron\AppData\Roaming\RiffTrax
2009-03-02 08:41 ——— d—–w c:\program files\MySpace
2009-02-22 07:14 ——— d—–w c:\program files\Electronic Arts
2009-02-22 07:11 ——— d—–w c:\users\Capn Ron\AppData\Roaming\Microsoft Games
2009-02-22 07:11 ——— d—–w c:\program files\Microsoft Games
2009-02-16 07:17 ——— d—–w c:\program files\Konami
2009-02-12 08:01 ——— d—–w c:\program files\Windows Mail
2009-01-17 15:07 ——— d—–w c:\program files\SP41959
2009-01-17 15:03 ——— d—–w c:\users\Capn Ron\AppData\Roaming\Hewlett-Packard
2009-01-17 15:03 ——— d—–w c:\program files\Hewlett-Packard
2009-01-17 15:02 ——— d—–w c:\program files\HP
2009-01-16 04:51 ——— d—–w c:\program files\MagicISO
2009-01-16 04:22 ——— d—–w c:\programdata\DriverCure
2009-01-16 04:20 ——— d—–w c:\users\Capn Ron\AppData\Roaming\DriverCure
2009-01-16 04:18 ——— d—–w c:\programdata\Downloaded Installations
2009-01-15 06:11 827,392 —-a-w c:\windows\System32\wininet.dll
2009-01-13 15:24 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-13 03:51 ——— d—–w c:\programdata\Symantec
2008-12-23 23:46 201,816 —-a-w c:\windows\System32\PnkBstrB.exe
2008-12-13 16:27 40,960 —-a-w c:\users\Capn Ron\GliderTell.exe
2008-12-13 16:27 294,912 —-a-w c:\users\Capn Ron\GRefs.dat
2008-12-01 04:32 22,328 —-a-w c:\users\Capn Ron\AppData\Roaming\PnkBstrK.sys
2008-01-21 02:43 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2007-05-11 07:06 40048 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
–a—— 2007-03-11 07:21 159744 c:\program files\Apoint2K\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
–a—— 2008-12-16 09:40 342848 c:\users\Capn Ron\Program Files\DNA\btdna.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2007-05-08 17:24 54840 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
–a—— 2008-06-02 03:55 80896 c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
–a—— 2007-09-13 12:47 480560 c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
–a—— 2007-07-25 03:02 174616 c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-10-01 18:57 289576 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-09-19 01:05 8497696 c:\windows\System32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-09-19 01:05 81920 c:\windows\System32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
–a—— 2007-09-19 01:05 86016 c:\windows\System32\nvsvc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OnScreenDisplay]
–a—— 2007-09-04 16:54 554320 c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
–a—— 2007-09-19 17:31 202032 c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
–a—— 2007-12-19 22:27 468264 c:\program files\HP\QuickPlay\QPService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2009-03-12 12:38 1410296 c:\program files\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2009-03-07 16:20 148888 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
–a—— 2007-08-17 02:13 218408 c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
–a—— 2007-01-08 19:53 311296 c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
–a—— 2008-01-20 22:23 1008184 c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
–a—— 2008-01-20 22:25 202240 c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{46406647-2382-4C5C-87AB-5BC87D3A28CF}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{6DA9DFEA-0AB2-459C-A646-158182C75152}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{DAF86E4B-0735-47DC-A5DB-637A88C45C74}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A2100764-A630-4771-8CE4-157B32414391}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8D404B90-DBB6-4C47-A835-44EFD4C04957}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{AC7D0598-8C3D-4E24-813A-E058A514B547}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{B9BD04B8-8A4E-479F-9B66-3E6E74904126}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{CF346E64-6138-4C33-8090-6208B5A38FD8}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{04820B17-7658-4344-A5B7-C41D45EF2E66}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{B4BE955E-960C-4B09-90A5-C11E55463523}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3233706A-074C-4F28-8665-1BC990A4551C}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{90B2B186-BA0E-49FF-B874-7538F980A451}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{2D77D23E-D77B-4BE7-9B56-8FDF5009666F}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{5FDFE69A-63E8-4186-BA75-B23644FC605C}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{7B709B26-B343-4E9F-A2DB-C977C78A4552}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{5BF7ABBB-93E9-48B5-B982-38DFCA933E61}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{CF9689E3-A104-40D3-A3A3-16ABB4DB6AEC}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{64BE52E9-CA25-449A-B157-0FC2A1543784}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{503708DF-BB2C-42BA-A827-9DAAF47B0EDA}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{4E987F88-15A9-4DC0-ADBD-1ABA234D6985}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{BEDAF252-1812-4889-A5B4-0EB69BC8679D}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{C59F924F-DBD7-4542-BADE-C2251848C831}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{A78BD61C-AFAD-47C8-80A1-10E8C851C41E}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{3BC4E7FB-4F1D-40B1-A925-9F66090FA2BB}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{A36BC59A-D609-4953-AEC4-A8F64DA3AD1C}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{E533C5B1-9681-46C1-893C-BCD364CE4FA0}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{87A72711-0544-44C6-BE04-8D0985F92EC6}c:\\users\\capn ron\\program files\\dna\\btdna.exe"= UDP:c:\users\capn ron\program files\dna\btdna.exe:btdna.exe
"UDP Query User{52EE481C-2023-41D7-ADF2-0DD5914CFA2F}c:\\users\\capn ron\\program files\\dna\\btdna.exe"= TCP:c:\users\capn ron\program files\dna\btdna.exe:btdna.exe
"TCP Query User{CB585176-5BA4-41D7-9F73-588141DC8DC2}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"UDP Query User{ED71F22A-FAAE-46CD-A5ED-1D2E5249D9A1}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"TCP Query User{FDAE1E7A-73C9-4407-B02E-1DDC88842259}c:\\program files\\starwarsgalaxies\\swgclient_r.exe"= UDP:c:\program files\starwarsgalaxies\swgclient_r.exe:SwgClient_r
"UDP Query User{01F66CF4-8E3B-4B1E-9F03-BA0E0DDBB9F8}c:\\program files\\starwarsgalaxies\\swgclient_r.exe"= TCP:c:\program files\starwarsgalaxies\swgclient_r.exe:SwgClient_r
"{FA26F17F-BA7B-4311-9E79-4A680A197C63}"= UDP:c:\fear\FEAR.exe:FEAR
"{12CEC692-4E69-4864-B6B2-4920F5F9FE0B}"= TCP:c:\fear\FEAR.exe:FEAR
"TCP Query User{16E1D0C7-84F4-4D9A-A38C-C349AD332F50}c:\\program files\\steam\\steamapps\\common\\dawn of war 2\\dow2.exe"= UDP:c:\program files\steam\steamapps\common\dawn of war 2\dow2.exe:DOW2
"UDP Query User{47CC1BCA-DEC6-4D35-9127-3A5EC69DCCA6}c:\\program files\\steam\\steamapps\\common\\dawn of war 2\\dow2.exe"= TCP:c:\program files\steam\steamapps\common\dawn of war 2\dow2.exe:DOW2

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-03-08 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-03-08 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-03-08 51792]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-10-12 24652]

— Other Services/Drivers In Memory —

*Deregistered* - sptd

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9045fd9d-8b85-11dd-96aa-806e6f6e6963}]
\shell\AutoRun\command - E:\install.EXE id= ver=1.0.0.0
.
Contents of the 'Scheduled Tasks' folder

2009-03-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - (no file)
HKCU-Run-Aim6 - (no file)
MSConfigStartUp-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=81&bd;=Pavilion&pf;=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\WOT\WOT.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-13 10:51:02
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
Completion time: 2009-03-13 10:53:04
ComboFix-quarantined-files.txt 2009-03-13 14:53:01

Pre-Run: 8,895,430,656 bytes free
Post-Run: 8,792,076,288 bytes free

262 — E O F — 2009-03-05 16:30:25
Hi, There we go, that was the problem. Give MBAM a go now, it *should* be fine now that the rootkit stopping it is gone. Other than that, how is the computer running? Thanks.
Hi,

Glad to hear things are running better :thumbup:


Click Start >> Run, and then type ComboFix /u and hit enter.
You can now delete any other tools I had you download and use, unless you wish to keep them.


Now that your system appears to be clean, there's just a few steps I'd like you to take to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • You don't appear to be running any third party Firewall software.

    Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
    1) Comodo
    2) Agnitum
    3) Sunbelt/Kerio

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Oh this problem couldn't be anymore resolved. If I wasn't so dead tired at the moment I would download everything and get it installed, but I'm so worn out i'm seeing double. Thank you very much, I couldn't have asked for any better help.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI