Hey Noviciate,
Back after much hard work for an old man.
Took the trip to bleepingcomputer; download was much different tan they said it would be. I think that was the result of using FireFox. Figured out how to disable Avast, but forgot to disable ZoneAlarm, and was afraid to stop the ComboFix. Saved log as log1.txt, disabled ZoneAlarm, ran comboFix again, and saved log as log2.txt. Went back for log1 and found it was gone; I obviosly don't understand Notepad. Got a fresh HJT log and an uninstall list.
My PC seem to be behaving well. the popup screens are gone, for now, the big blue screen has stopped showing up, and the two icons on my system tray are gone.
Hopefully the logs and lists are below.
A big thanks for the help, and I will let you know if all continues well.
Thanks,
Billed
ComboFix log:
ComboFix 09-03-15.01 - Judy Dengler 2009-03-18 11:44:32.2 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.262 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090317-0] *On-access scanning disabled* (Updated)
FW: ZoneAlarm Pro Firewall *disabled*
.
((((((((((((((((((((((((( Files Created from 2009-02-18 to 2009-03-18 )))))))))))))))))))))))))))))))
.
2009-03-18 06:21 . 2009-03-18 06:21 d——– c:\documents and settings\Judy Dengler\Application Data\U3
2009-03-17 13:44 . 2009-03-17 13:44 d——– c:\program files\Trend Micro
2009-03-16 22:24 . 2009-03-16 22:24 d–hs—- C:\FOUND.016
2009-03-16 18:08 . 2009-03-16 18:08 301,056 –a—— c:\windows\SYSTEM32\winconfig.dll
2009-02-28 19:22 . 2009-02-15 23:10 1,221,512 –a—— c:\windows\SYSTEM32\zpeng25.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-18 11:29 1,610 —-a-w c:\windows\SYSTEM32\PerfStringBackup.TMP
2009-03-06 11:17 410,984 —-a-w c:\windows\SYSTEM32\deploytk.dll
2009-02-09 11:13 1,846,784 —-a-w c:\windows\SYSTEM32\win32k.sys
2009-02-09 11:13 1,846,784 ——w c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2009-01-26 12:10 22,614,727 ——w c:\windows\Internet Logs\tvDebug.zip
2009-01-17 02:35 3,594,752 —-a-w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2008-12-19 08:10 70,656 ——w c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-12-19 08:10 13,824 ——w c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
2008-12-19 04:25 634,024 ——w c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
2008-12-19 04:23 161,792 —-a-w c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
2006-04-21 10:55 0 —-a-w c:\documents and settings\Judy Dengler\dl.exe
2008-08-28 00:00 32,768 –sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008082720080828\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS Probe"="d:\program files\ASUS\Probe\AsusProb.exe" [2006-04-26 625152]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2006-04-26 151552]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2006-04-26 90112]
"zBrowser Launcher"="d:\program files\Logitech\iTouch\iTouch.exe" [2006-04-26 524288]
"EM_EXEC"="d:\progra~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2006-04-26 32256]
"Pop-Up Stopper"="c:\progra~1\PANICW~1\POP-UP~1\dpps2.exe" [2006-04-26 712704]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-06 148888]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"C-Media Mixer"="Mixer.exe" [2001-10-22 c:\windows\mixer.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Office Startup.lnk - d:\program files\Microsoft Office\Office\OSA.EXE [1997-08-01 55808]
Microsoft Find Fast.lnk - d:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-08-01 114688]
Logitech Desktop Messenger.lnk - d:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2003-01-01 173056]
Monitor.lnk - c:\program files\ArcSoft\Media Card Companion\MCC Monitor.exe [2008-08-03 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"msacm.divxa32"= divxa32.acm
"vidc.xvid"= xvid.dll
"VIDC.DIV4"= divxc32f.dll
"VIDC.DIV3"= divxc32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 Fasttrak;Fasttrak;c:\windows\SYSTEM32\DRIVERS\Fasttrak.sys [2004-05-13 70528]
R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [2008-03-30 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [2008-03-30 20560]
S2 ousbehci;%OWC_USBEHCD.DeviceDesc%;c:\windows\SYSTEM32\DRIVERS\ousbehci.sys [2006-10-06 29568]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb9bb602-13ae-11de-9d46-000c41214de7}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
Trusted Zone: bleepingcomputer.com
Trusted Zone: mediafire.com
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: nutnworks.com
Trusted Zone: windowsupdate.com
Trusted Zone: windowsupdate.com\download
Trusted Zone: zonealarm.com
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Judy Dengler\Application Data\Mozilla\Firefox\Profiles\d7r4uq94.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-18 11:46:19
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
Completion time: 2009-03-18 11:47:42
ComboFix-quarantined-files.txt 2009-03-18 16:47:40
ComboFix2.txt 2009-03-18 16:14:40
Pre-Run: 26,553,286,656 bytes free
Post-Run: 26,533,330,944 bytes free
120 — E O F — 2009-03-17 03:15:44

HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:19 PM, on 03/18/09
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
D:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
D:\Program Files\Logitech\iTouch\iTouch.exe
D:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Microsoft Office\Office\OSA.EXE
D:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ASUS Probe] D:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [zBrowser Launcher] D:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] D:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Office Startup.lnk = D:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = D:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.bleepingcomputer.com
O15 - Trusted Zone: *.mediafire.com
O15 - Trusted Zone: *.nutnworks.com
O15 - Trusted Zone:
http://download.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.com
O15 - Trusted Zone:
http://*.zonealarm.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1146187722687
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1177595026046
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
–
End of file - 6261 bytes

UNINSTALL list:
Acrobat.com
Acrobat.com
Active Disk
Adobe AIR
Adobe AIR
Adobe Download Manager 1.2 (Remove Only)
Adobe Flash Player 10 Plugin
Adobe Reader 9
Adobe Shockwave Player
ArcSoft Media Card Companion
ASUS Probe V2.17.00
avast! Antivirus
Canon Camera Support Core Library
Canon Camera Window DS for ZoomBrowser EX
Canon Camera Window DVC for ZoomBrowser EX
Canon Camera Window for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX
Critical Update for Windows Media Player 11 (KB959772)
ffdshow (remove only)
Garmin Communicator Plugin
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
IomegaWare 4.0.2
J2SE Runtime Environment 5.0 Update 9
Java™ 6 Update 12
Java™ 6 Update 5
Java™ 6 Update 7
Logitech Desktop Messenger
Logitech iTouch Software
Logitech MouseWare 9.61
Logitech Resource Center
Macromedia Flash Player 8
MadOnion.com/3DMark2001 SE
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft DirectX Transform optional components
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 97, Professional Edition
Microsoft User-Mode Driver Framework Feature Pack 1.0
Mozilla Firefox (3.0.7)
Nero - Burning Rom
Nimo Codecs Pack v5.0 (Remove Only)
OpenOffice.org Installer 1.0
PCI Audio Applications
PCI Audio Driver
Pdf995 (installed by TaxCut)
PdfEdit995 (installed by TaxCut)
Pop-Up Stopper
QuickTime
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
SiSoftware Sandra Standard 2004.SP1 (StarSoft Edition)
Spelling Dictionaries Support For Adobe Reader 9
TaxCut 2002
TaxCut 2003
TaxCut 2004
TaxCut Premium 2006
TaxCut Premium 2007
Tsunami-Filter-Pack Mini
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VC 9.0 Runtime
VC 9.0 Runtime
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WinZip
XviD Video Codec 04102002-1 (Koepi's build with EPSZ ME)
ZoneAlarm Pro
ZoneAlarm Spy Blocker
That's all folks,
Billed