This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] I think I'm Infected

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI



I have AVG and it ran a scan. It said it found an infection called windows virut 56 or something close to that. So, being computer illiterate as I am, the only thing I knew to do was to look it up. Everything I read about it said to reformat that there was no way to fix it. Then, I stumbled on this forum site and for the first time found language and explanations that I could understand. Alas, here I am. From reading the other posts I downloaded HiJackThis and ran a system scan and saved a log file. However, I have no clue where to go from here which brings me to post here. I am at my wits end with this and the sad thing about it is that I have NO CLUE how to do this reformat thing either. I truly hope that ya'll can help. Below I've copied and pasted the file from the scan, if its not what you need please let me know what is needed and I will do my best to get it to you to evaluate.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:10:41 PM, on 3/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PSIService.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\WINDOWS\system32\tdctxte.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
C:\Program Files\eAcceleration\Firewall\FWService.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\eAcceleration\OnAccess\onaccess.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pando Networks\Pando\pando.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
C:\Program Files\eAcceleration\Station\station_bk.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Documents and Settings\Angela\Desktop\drweb-cureit.exe
C:\DOCUME~1\Angela\LOCALS~1\Temp\RarSFX3\_start.exe
C:\DOCUME~1\Angela\LOCALS~1\Temp\RarSFX3\setup.exe
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OnAccess] "C:\Program Files\eAcceleration\OnAccess\onaccess.exe" -erk
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\pando.exe" /Minimized
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O9 - Extra 'Tools' menuitem: Block This Page - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: eAcceleration Notification Service (eac_notifysvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
O23 - Service: FWService - eAcceleration Corp - C:\Program Files\eAcceleration\Firewall\FWService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: tdctxte Service (tdctxte) - Unknown owner - C:\WINDOWS\system32\tdctxte.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 8773 bytes

Attachments:

  • [attachment removed: DollyLettingGoAVsd_vi.gif]
Hi Demented Dolly, welcome to the forum.

Please do not post in color, it's very hard on my poor old eyes. ;)


To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

I see you have DrWeb. What did the scan results say?

Before we panic, let's see what going on.


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post




Thanks
Well hello there Oldman960. Thank you so much for trying to help me out. As requested I downloaded the DDS and scanned the computer and I have copy/pasted the first one for you and zipped up and attached the second one for your evaluation. I'm hoping I did this right. DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 17:05:10.23 on Sat 03/21/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_12 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.751.100 [GMT -5:00] AV: AVG Anti-Virus *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\afisicx.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe C:\Program Files\Unlocker\UnlockerAssistant.exe C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\PSIService.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\eAcceleration\OnAccess\onaccess.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Pando Networks\Pando\pando.exe C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe C:\WINDOWS\system32\sopidkc.exe C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe C:\WINDOWS\system32\tdctxte.exe C:\Program Files\eAcceleration\Station\station_bk.exe C:\WINDOWS\System32\TUProgSt.exe C:\Program Files\Webroot\Washer\WasherSvc.exe C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\IncrediMail\bin\IMApp.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe C:\Program Files\eAcceleration\Firewall\FWService.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Documents and Settings\Angela\Desktop\drweb-cureit.exe C:\DOCUME~1\Angela\LOCALS~1\Temp\RarSFX4\_start.exe C:\DOCUME~1\Angela\LOCALS~1\Temp\RarSFX4\setup.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe C:\Documents and Settings\Angela\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html mDefault_Page_URL = hxxp://www.yahoo.com/ mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com mStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyServer = socks= uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll mWinlogon: Userinit=c:\windows\system32\Userinit.exe BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: AcroIEHelperStub: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - Adobe PDF Link Helper BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL BHO: {b753c7c5-0942-4b7f-bc27-942b52bdac66} - c:\progra~1\accele~1\stopsign\webcbrowse.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [IncrediMail] c:\program files\incredimail\bin\IncMail.exe /c uRun: [Pando] "c:\program files\pando networks\pando\pando.exe" /Minimized uRun: [Active Desktop Calendar] c:\program files\xemicomputers\active desktop calendar\ADC.exe uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S uRun: [Window Washer] c:\program files\webroot\washer\wwDisp.exe mRun: [webscan] "c:\program files\acceleration software\anti-virus\stopsignav.exe" -k mRun: [SoftwareStation] "c:\program files\eacceleration\station\station.exe" /b Startup mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe" mRun: [Corel File Shell Monitor] c:\program files\corel\corel paint shop pro photo x2\CorelIOMonitor.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [OnAccess] "c:\program files\eacceleration\onaccess\onaccess.exe" -erk mRun: [TrojanScanner] c:\program files\trojan remover\Trjscan.exe /boot StartupFolder: c:\docume~1\angela\startm~1\programs\startup\erunt autobackup.lnk - c:\program files\erunt\AUTOBACK.EXE IE: E&xport to Microsoft Excel IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - c:\progra~1\accele~1\stopsign\webcbrowse.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll SEH: ExecuteMonitorShellHook Class: {42dd0873-5fa9-465d-90de-0826020416a5} - c:\program files\eacceleration\onaccess\onaccess_hk32.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\angela\applic~1\mozilla\firefox\profiles\ahzywolk.default\ FF - prefs.js: browser.search.selectedEngine - Rocket Division Search FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=CFEMNov08FFAB&search= FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg8\toolbarff\components\vmAVGConnector.dll FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll —- FIREFOX POLICIES —- FF - user.js: network.http.max-connections-per-server - 6 FF - user.js: network.http.max-persistent-connections-per-server - 3 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: content.notify.interval - 750000 FF - user.js: content.max.tokenizing.time - 2250000 ============= SERVICES / DRIVERS =============== R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-1-15 12552] R0 fwcore;Fwcore Filter;c:\windows\system32\drivers\fwcore.sys [2008-11-25 100696] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-15 325128] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-1-15 27656] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-15 107272] R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [2009-2-19 85760] R2 afisicx;afisicx Service;c:\windows\system32\afisicx.exe [2006-2-28 177152] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-1-15 903960] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-15 298264] R2 eac_notifysvc;eAcceleration Notification Service;c:\progra~1\eaccel~1\framew~1\eac_svc.exe [2008-11-25 111952] R2 eac_productsvc;eAcceleration Product Manager Service;c:\progra~1\eaccel~1\framew~1\eac_productsvc.exe [2008-11-25 263504] R2 FWService;FWService;c:\program files\eacceleration\firewall\fwservice.exe -service –> c:\program files\eacceleration\firewall\FWService.exe -Service [?] R2 sopidkc;sopidkc Service;c:\windows\system32\sopidkc.exe [2006-2-28 176128] R2 tdctxte;tdctxte Service;c:\windows\system32\tdctxte.exe [2006-2-28 176640] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-2-19 603904] R2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\drivers\UBSBM.sys [2009-2-6 17408] R2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\drivers\UBUMAPI.sys [2009-2-6 39424] R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2009-3-19 598856] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-2-7 15504] R3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\drivers\ubohci.sys [2009-2-6 114688] S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-2-7 179856] =============== Created Last 30 ================ 2009-03-20 20:48 –d—– c:\program files\Trend Micro 2009-03-20 02:06 –d—– c:\documents and settings\angela\DoctorWeb 2009-03-19 22:17 –d—– c:\docume~1\angela\applic~1\Webroot 2009-03-19 22:17 –d—– c:\program files\Webroot 2009-03-19 22:17 –d—– c:\program files\common files\Webroot Shared 2009-03-19 22:17 –d—– c:\docume~1\alluse~1\applic~1\Webroot 2009-03-19 22:17 194,888 a——- c:\windows\Unwash6.exe 2009-03-19 11:06 5,785,088 a——- c:\windows\system32\QtGui4.dll 2009-03-19 11:06 2,170,368 a——- c:\windows\system32\QtCore4.dll 2009-03-19 11:06 –d-h— c:\program files\InstallJammer Registry 2009-03-19 11:05 –d—– c:\program files\Free Image Manipulator 2009-03-19 00:31 7,168 a–sh— c:\windows\system32\Thumbs.db 2009-03-19 00:10 –d—– c:\docume~1\alluse~1\applic~1\SecTaskMan 2009-03-19 00:10 –d—– c:\program files\Security Task Manager 2009-03-18 20:59 –d—– c:\program files\Trojan Remover 2009-03-18 18:32 162,304 a——- c:\windows\system32\ztvunrar36.dll 2009-03-18 18:32 153,088 a——- c:\windows\system32\unrar3.dll 2009-03-18 18:32 77,312 a——- c:\windows\system32\ztvunace26.dll 2009-03-18 18:32 75,264 a——- c:\windows\system32\unacev2.dll 2009-03-18 18:32 69,632 a——- c:\windows\system32\ztvcabinet.dll 2009-03-18 18:32 –d—– c:\docume~1\angela\applic~1\Simply Super Software 2009-03-18 18:32 –d—– c:\docume~1\alluse~1\applic~1\Simply Super Software 2009-03-18 18:14 -cd-h— c:\docume~1\alluse~1\applic~1\{66E2F539-12B6-4870-A500-7689CDE75C5E} 2009-03-18 01:12 –d—– c:\docume~1\angela\applic~1\Hide IP NG 2009-03-18 00:50 –d—– c:\docume~1\angela\applic~1\HideIP 2009-03-15 01:46 –d—– c:\program files\CleanUp! 2009-03-11 15:52 190,976 a——- c:\program files\Lovely Folders 4_Patch.exe 2009-03-11 15:09 –d—– c:\program files\Lovely Folders 2009-03-11 05:20 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat 2009-03-10 11:38 –d—– c:\windows\system32\XPSViewer 2009-03-10 11:35 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-03-10 11:35 117,760 ——– c:\windows\system32\prntvpt.dll 2009-03-10 11:35 597,504 ac—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-03-10 11:35 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-03-10 11:35 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-03-10 11:35 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-03-10 11:35 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-03-10 10:01 –d—– c:\program files\UseNeXT 2009-02-24 17:26 410,984 a——- c:\windows\system32\deploytk.dll 2009-02-24 17:26 73,728 a——- c:\windows\system32\javacpl.cpl 2009-02-19 23:44 –d-h— c:\windows\PIF 2009-02-19 23:27 716,272 a——- c:\windows\system32\drivers\sptd.sys 2009-02-19 23:26 85,760 a——- c:\windows\system32\drivers\StarPortLite.sys 2009-02-19 23:26 –d—– c:\program files\Rocket Division Software 2009-02-19 23:03 603,904 a——- c:\windows\system32\TUProgSt.exe 2009-02-19 23:03 27,904 a——- c:\windows\system32\uxtuneup.dll 2009-02-19 23:03 360,192 a——- c:\windows\system32\TuneUpDefragService.exe 2009-02-19 23:03 –d—– c:\docume~1\angela\applic~1\TuneUp Software 2009-02-19 23:02 –d—– c:\docume~1\alluse~1\applic~1\TuneUp Software 2009-02-19 23:02 –d—– c:\program files\TuneUp Utilities 2009 2009-02-19 23:01 –dsh— c:\docume~1\alluse~1\applic~1\{55A29068-F2CE-456C-9148-C869879E2357} 2009-02-19 20:14 –d—– c:\program files\Keenfinder 2009-02-19 20:14 –d—– c:\windows\Icons 2009-02-19 20:14 –d—– c:\program files\FileSubmit 2009-02-19 17:11 10 a——- c:\windows\system32\WIN51IP.SP3 2009-02-19 17:11 10 a——- c:\windows\system32\WIN51IP 2009-02-19 17:11 10 a——- c:\windows\system32\WIN51 2009-02-19 17:11 –d—– c:\windows\system32\SOFTWARE 2009-02-19 17:11 203,576 a——- c:\windows\system32\RICHTX32.OCX 2009-02-19 17:11 46,080 a——- c:\windows\system32\MCIWNDX.OCX 2009-02-19 17:11 –d—– c:\windows\system32\I386 2009-02-19 17:11 933,888 a——- c:\windows\system32\FLASH.OCX 2009-02-19 17:11 –d—– c:\windows\system32\DATA 2009-02-19 17:11 47 a——- c:\windows\system32\AUTORUN.INF 2009-02-19 17:11 136,606 a——- c:\windows\system32\AUTORUN.ICO 2009-02-19 17:10 270,848 a——- c:\windows\system32\AUTORUN.EXE 2009-02-19 17:10 –d—– c:\windows\system32\$OEM$ ==================== Find3M ==================== 2009-03-20 04:43 30,720 a——- c:\windows\system32\xcopy.exe 2009-03-20 04:43 32,256 a——- c:\windows\system32\wupdmgr.exe 2009-03-20 04:43 165,888 a——- c:\windows\system32\wuauclt1.exe 2009-03-20 04:43 155,648 a——- c:\windows\system32\wscript.exe 2009-03-20 04:43 13,824 a——- c:\windows\system32\wscntfy.exe 2009-03-20 04:43 11,264 a——- c:\windows\system32\wpnpinst.exe 2009-03-20 04:43 5,632 a——- c:\windows\system32\write.exe 2009-03-20 04:43 32,256 a——- c:\windows\system32\wpabaln.exe 2009-03-20 04:43 5,632 a——- c:\windows\system32\winver.exe 2009-03-20 04:43 11,776 a——- c:\windows\system32\winmsd.exe 2009-03-20 04:43 119,808 a——- c:\windows\system32\winmine.exe 2009-03-20 04:41 31,744 a——- c:\windows\system32\tracert6.exe 2009-03-20 04:40 20,992 a——- c:\windows\system32\spupdwxp.exe 2009-03-20 04:39 77,312 a——- c:\windows\system32\rtcshare.exe 2009-03-20 04:38 9,216 a——- c:\windows\system32\proxycfg.exe 2009-03-20 04:37 86,016 a——- c:\windows\system32\netsh.exe 2009-03-20 04:36 20,992 a——- c:\windows\system32\msg.exe 2009-03-20 04:35 25,088 a——- c:\windows\system32\lnkstub.exe 2009-03-20 04:35 29,696 a——- c:\windows\system32\lights.exe 2009-03-20 04:35 9,728 a——- c:\windows\system32\label.exe 2009-03-20 04:35 23,552 a——- c:\windows\system32\ipxroute.exe 2009-03-20 04:35 53,248 a——- c:\windows\system32\ipv6.exe 2009-03-20 04:35 44,032 a——- c:\windows\system32\ipsec6.exe 2009-03-20 04:35 55,808 a——- c:\windows\system32\ipconfig.exe 2009-03-20 04:35 114,688 a——- c:\windows\system32\igfxzoom.exe 2009-03-20 04:35 159,744 a——- c:\windows\system32\igfxsrvc.exe 2009-03-20 04:35 94,208 a——- c:\windows\system32\igfxext.exe 2009-03-20 04:35 446,464 a——- c:\windows\system32\igfxcfg.exe 2009-03-20 04:35 114,688 a——- c:\windows\system32\iexpress.exe 2009-03-20 04:33 55,296 a——- c:\windows\system32\dvdplay.exe 2009-03-20 04:32 8,192 a——- c:\windows\system32\control.exe 2009-03-20 04:31 14,336 a——- c:\windows\system32\auditusr.exe 2009-03-20 04:31 12,288 a——- c:\windows\system32\attrib.exe 2009-03-20 04:31 11,264 a——- c:\windows\system32\atmadm.exe 2009-03-20 04:31 25,088 a——- c:\windows\system32\at.exe 2009-03-20 04:31 19,456 a——- c:\windows\system32\arp.exe 2009-03-20 04:31 98,304 a——- c:\windows\system32\ahui.exe 2009-03-20 04:31 4,096 a——- c:\windows\system32\actmovie.exe 2009-03-20 04:31 184,320 a——- c:\windows\system32\accwiz.exe 2009-03-20 04:12 150,528 a——- c:\windows\pchealth\uploadlb\binaries\uploadm.exe 2009-03-20 04:12 35,328 a——- c:\windows\pchealth\helpctr\binaries\notiflag.exe 2009-03-20 04:11 169,984 a——- c:\windows\pchealth\helpctr\binaries\msconfig.exe 2009-03-20 04:11 18,944 a——- c:\windows\pchealth\helpctr\binaries\hscupd.exe 2009-03-20 04:11 744,448 a——- c:\windows\pchealth\helpctr\binaries\helpsvc.exe 2009-03-20 04:11 99,840 a——- c:\windows\pchealth\helpctr\binaries\HelpHost.exe 2009-03-20 04:11 769,024 a——- c:\windows\pchealth\helpctr\binaries\helpctr.exe 2009-03-20 03:48 283,648 a——- c:\windows\winhlp32.exe 2009-03-20 03:48 299,520 a——- c:\windows\uninst.exe 2009-03-20 03:48 25,600 a——- c:\windows\twunk_32.exe 2009-03-20 03:48 15,360 a——- c:\windows\TASKMAN.EXE 2009-03-20 03:48 146,432 a——- c:\windows\regedit.exe 2009-03-20 03:48 69,120 a——- c:\windows\notepad.exe 2009-03-20 03:48 10,752 a——- c:\windows\hh.exe 2009-03-20 02:19 57,856 a——- c:\windows\system32\wdfmgr.exe 2009-03-20 02:19 289,792 a——- c:\windows\system32\vssvc.exe 2009-03-20 02:19 26,112 a——- c:\windows\system32\userinit.exe 2009-03-20 02:19 18,432 a——- c:\windows\system32\ups.exe 2009-03-20 02:19 176,640 a——- c:\windows\system32\tdctxte.exe 2009-03-20 02:19 76,288 a——- c:\windows\system32\spoolsv.exe 2009-03-20 02:19 89,600 a——- c:\windows\system32\smlogsvc.exe 2009-03-20 02:19 45,056 a——- c:\windows\system32\shmgrate.exe 2009-03-20 02:17 77,824 a——- c:\windows\system32\hkcmd.exe 2009-03-20 02:17 224,768 a——- c:\windows\system32\dmadmin.exe 2009-03-20 02:17 33,792 a——- c:\windows\system32\ctfmon.exe 2009-03-20 02:17 33,280 a——- c:\windows\system32\clipsrv.exe 2009-03-20 02:17 5,632 a——- c:\windows\system32\cisvc.exe 2009-03-20 02:17 63,488 a——- c:\windows\system32\alg.exe 2009-03-20 02:16 1,052,160 a——- c:\windows\explorer.exe 2009-03-17 00:14 5,852 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-02-11 11:19 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 11:19 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-02-09 06:13 1,846,784 a——- c:\windows\system32\win32k.sys 2009-01-15 18:59 10,520 a——- c:\windows\system32\avgrsstx.dll ============= FINISH: 17:06:56.04 ===============
oh, I almost forgot. You had asked what Dr. Web had to say. Well on the first scan with it, it found numerous infected files but it cured all it found or so it said. So, on the second running of it on my c drive, it doesn't find anything. Is that good? Thanks again for your help.
Hi Demented Dolly, I don't see the Attach.txt attached. You can copy and paste it in your reply if you wish. Also, do you know the name of the infection that DrWeb detected and cleaned? Thanks
ok I copy/pasted it here as you asked, you will find it below. The infections that it found were mostly that virut 56 and since that scan none are showing or at least none as of yet. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-03-16.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 11/21/2008 11:24:17 PM System Uptime: 3/21/2009 4:44:08 PM (1 hours ago) Motherboard: | | Springdale-G Processor: Intel® Celeron® CPU 2.20GHz | Socket 478 | 2194/100mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 37 GiB total, 11.764 GiB free. D: is FIXED (NTFS) - 149 GiB total, 0.003 GiB free. E: is CDROM (CDFS) F: is FIXED (NTFS) - 149 GiB total, 45.752 GiB free. ==== Disabled Device Manager Items ============= Class GUID: Description: Unibrain 1394 PC Device ID: UB1394\UNIBRAIN&1394_PC\0030670000019CC2 Manufacturer: Name: Unibrain 1394 PC PNP Device ID: UB1394\UNIBRAIN&1394_PC\0030670000019CC2 Service: Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Realtek RTL8139/810x Family Fast Ethernet NIC Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_23001565&REV_10\4&1F7DBC9F&0&18F0 Manufacturer: Realtek Semiconductor Corp. Name: Realtek RTL8139/810x Family Fast Ethernet NIC #2 PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_23001565&REV_10\4&1F7DBC9F&0&18F0 Service: RTL8023xp ==== System Restore Points =================== RP174: 3/18/2009 6:14:19 PM - Installed Uniblue DriverScanner v1.0 RP175: 3/18/2009 6:23:20 PM - DriverScanner install: Intel® 82801EB Ultra ATA Storage Controllers RP176: 3/18/2009 6:26:58 PM - Removed Google Earth. RP177: 3/18/2009 8:28:14 PM - Removed Nero 7 Ultra Edition RP178: 3/18/2009 11:53:34 PM - Uniblue RegistryBooster 2009 RP179: 3/19/2009 12:18:10 AM - Move file to quarantine: tdctxte.exe RP180: 3/19/2009 12:33:24 AM - Move file to quarantine: xkfykialwms RP181: 3/19/2009 12:34:05 AM - Move file to quarantine: afisicx.exe RP182: 3/19/2009 12:35:08 AM - Move file to quarantine: xkfykialwms RP183: 3/21/2009 3:03:06 AM - Software Distribution Service 3.0 ==== Installed Programs ====================== Acrobat.com Active Desktop Calendar 7.46 Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9 Alien Skin Eye Candy 5 Impact Alien Skin Eye Candy 5 Nature Alien Skin Eye Candy 5 Textures Alien Skin Splat! 1.0 Demo Alien Skin Xenofex 2.0 AVG 8.0 C-Media WDM Audio Driver CCleaner (remove only) CleanUp! Corel Paint Shop Pro Photo X2 CutePDF Writer 2.7 eAcceleration - StopSign Popup Blocker ERUNT 1.1j Eye Candy 3 Eye Candy 4000 Demo Filters Unlimited 1.0 Filters Unlimited 2.0 Fire 2.0 Free Image Manipulator HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows XP (KB954550-v5) IncrediMail Intel® Extreme Graphics 2 Driver Jasc Animation Shop 3 Java™ 6 Update 12 Lovely Folders Malwarebytes' Anti-Malware Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework Client Profile - PREVIEW Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.0.7) MSXML 4.0 SP2 (KB954430) Pando RegistryFix v7.0 Security Task Manager 1.7h Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows XP (KB923789) StarBurn Version 10.0 (Build 0x20080229) StopSign Internet Security Trojan Remover 6.7.6 TuneUp Utilities 2009 Uniblue DriverScanner 2009 Uniblue RegistryBooster 2009 Uniblue SpeedUpMyPC 2009 Unlocker 1.8.7 WebFldrs XP WinAce Archiver Window Washer Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Live Messenger Windows Media Format Runtime Yahoo! Messenger Yahoo! Toolbar ==== Event Viewer Messages From Past Week ======== 3/18/2009 6:55:46 PM, error: Service Control Manager [7023] - The Service AntiVir service terminated with the following error: Access is denied. 3/18/2009 4:52:56 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000007F' while processing the file 'desktop.ini' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 3/18/2009 7:28:17 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The system cannot find the file specified. 3/18/2009 8:44:03 PM, error: Service Control Manager [7023] - The Service AntiVir service terminated with the following error: The specified module could not be found. 3/18/2009 9:23:41 PM, error: Service Control Manager [7023] - The Service AntiVir service terminated with the following error: The system cannot find the file specified. 3/19/2009 12:18:19 AM, error: Service Control Manager [7034] - The tdctxte Service service terminated unexpectedly. It has done this 1 time(s). 3/19/2009 12:34:06 AM, error: Service Control Manager [7034] - The afisicx Service service terminated unexpectedly. It has done this 1 time(s). 3/19/2009 2:27:08 AM, error: Service Control Manager [7000] - The afisicx Service service failed to start due to the following error: The system cannot find the file specified. 3/19/2009 2:27:08 AM, error: Service Control Manager [7000] - The tdctxte Service service failed to start due to the following error: The system cannot find the file specified. 3/19/2009 4:31:56 AM, error: Service Control Manager [7034] - The sopidkc Service service terminated unexpectedly. It has done this 1 time(s). 3/19/2009 4:32:09 AM, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). 3/19/2009 5:28:32 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the TuneUp.Defrag service. 3/19/2009 5:29:01 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the service. 3/19/2009 7:08:59 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde 3/20/2009 1:30:16 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Window Washer Engine service to connect. 3/20/2009 1:30:16 PM, error: Service Control Manager [7000] - The Window Washer Engine service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. ==== End Of File ===========================
Hi Demented Dolly,

Thanks. Let's do another scan and see if anything turns up.


You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.




Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Desktop is a good place.
  • Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply along with a new HijackThis log.


Thanks
As requested here is the kasper sky report and a new hijack this report. Again, thank you so much for all your help with this.

DD


——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, March 22, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, March 22, 2009 13:53:47
Records in database: 1949734
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
E:\

Scan statistics:
Files scanned: 72258
Threat name: 2
Infected objects: 4
Suspicious objects: 0
Duration of the scan: 02:52:14


File name / Threat name / Threats count
afisicx.exe\afisicx.exe/afisicx.exe\afisicx.exe Infected: Backdoor.Win32.Delf.oht 1
C:\WINDOWS\system32\afisicx.exe/C:\WINDOWS\system32\afisicx.exe Infected: Backdoor.Win32.Delf.oht 1
C:\WINDOWS\system32\afisicx.exe Infected: Backdoor.Win32.Delf.oht 1
C:\WINDOWS\system32\dxonool32.sys Infected: Trojan.Win32.VB.lgf 1

The selected area was scanned.


********************************************************************************
***********************************
********************************************************************************
***********************************

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:01:46 PM, on 3/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\afisicx.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\eAcceleration\OnAccess\onaccess.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pando Networks\Pando\pando.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\WINDOWS\system32\sopidkc.exe
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
C:\WINDOWS\system32\tdctxte.exe
C:\Program Files\eAcceleration\Station\station_bk.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
C:\Program Files\eAcceleration\Firewall\FWService.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\Angela\Desktop\drweb-cureit.exe
C:\DOCUME~1\Angela\LOCALS~1\Temp\RarSFX4\_start.exe
C:\DOCUME~1\Angela\LOCALS~1\Temp\RarSFX4\setup.exe
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OnAccess] "C:\Program Files\eAcceleration\OnAccess\onaccess.exe" -erk
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\pando.exe" /Minimized
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O9 - Extra 'Tools' menuitem: Block This Page - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: eAcceleration Notification Service (eac_notifysvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
O23 - Service: FWService - eAcceleration Corp - C:\Program Files\eAcceleration\Firewall\FWService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: sopidkc Service (sopidkc) - Unknown owner - C:\WINDOWS\system32\sopidkc.exe
O23 - Service: tdctxte Service (tdctxte) - Unknown owner - C:\WINDOWS\system32\tdctxte.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 9156 bytes
Hi Demented Dolly,

One or more infections have been identified as having backdoor capabilities. This may allow remote access to your computer.

I strongly suggest you do the following immediately:
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Processes
    explorer.exe
    
    :Services
    afisicx
    sopidkc
    tdctxte
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\afisicx.exe
    C:\WINDOWS\system32\sopidkc.exe
    C:\WINDOWS\system32\tdctxte.exe
    C:\WINDOWS\system32\dxonool32.sys
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Next

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • OTMOVEIT3 log
  • MBAM log
  • a new HJT log obtained last
How's the computer?

Thanks
as requested the following scan reports are below.

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
Service\Driver afisicx stopped successfully.
Service\Driver afisicx deleted successfully.
Service\Driver sopidkc stopped successfully.
Service\Driver sopidkc deleted successfully.
Service\Driver tdctxte stopped successfully.
Service\Driver tdctxte deleted successfully.
========== REGISTRY ==========
========== FILES ==========
C:\WINDOWS\system32\afisicx.exe moved successfully.
C:\WINDOWS\system32\sopidkc.exe moved successfully.
C:\WINDOWS\system32\tdctxte.exe moved successfully.
C:\WINDOWS\system32\dxonool32.sys moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Angela\LOCALS~1\Temp\etilqs_HfERjQXHyeRneWMQnmlJ scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Angela\LOCALS~1\Temp\~DFF5F3.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\078a39f4-1c8a-4f0d-8b4b-129c106d5bf0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\28eea70e-157d-4bca-b65b-9fee9ee38cda.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_754.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_880.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\~DF648B.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03222009_160945

********************************************************************************
**********
********************************************************************************
**********

Malwarebytes' Anti-Malware 1.34
Database version: 1887
Windows 5.1.2600 Service Pack 3

3/22/2009 4:32:34 PM
mbam-log-2009-03-22 (16-32-34).txt

Scan type: Quick Scan
Objects scanned: 62513
Time elapsed: 6 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tpszxyd.sys (Backdoor.Bot) -> Quarantined and deleted successfully.


********************************************************************************
**********
********************************************************************************
**********

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:47:39 PM, on 3/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
C:\Program Files\eAcceleration\Firewall\FWService.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\eAcceleration\OnAccess\onaccess.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pando Networks\Pando\pando.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\eAcceleration\Station\station_bk.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OnAccess] "C:\Program Files\eAcceleration\OnAccess\onaccess.exe" -erk
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\pando.exe" /Minimized
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O9 - Extra 'Tools' menuitem: Block This Page - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: eAcceleration Notification Service (eac_notifysvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
O23 - Service: FWService - eAcceleration Corp - C:\Program Files\eAcceleration\Firewall\FWService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 8511 bytes
Hi Demented Dolly,

First, I must apologize for missing your reply. :smack: Somehow I just didn't notice you had replied.

Second, did OTMoveIT3 reboot your computer? The logs would indicate it didn't.

We will use OTMoveit3 with the following fix and make sure to say YES when prompted to reboot.


:Processes
explorer.exe

:Services

:Reg

:Files
C:\afisicx.exe /s

:Commands
[emptytemp]
[start explorer]
[Reboot]

Please post back with the OTMoveIt3 log and a new HJT log, then we will clean up our tools if you have no problems.

Thanks
Good Morning Oldman360. No worries about the reply lol I figured it was Sunday and you were takin a break, which is a good thing. Listed below are the two new scans you asked for. Thanks again for all your help.

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\_OTMoveIt\MovedFiles\03222009_160945\WINDOWS\system32\afisicx.exe moved successfully.
C:\_OTMoveIt\MovedFiles\03232009_103344\_OTMoveIt\MovedFiles\03222009_160945\WINDOWS\system32\afisicx.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Angela\LOCALS~1\Temp\IM\MSG19.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Angela\LOCALS~1\Temp\etilqs_KXVO0HiL3Ybh1uKixaCY scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\47cc60ed-5a09-4b06-846d-fb241efb738e.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\59e12d8d-d53a-42b5-ab0c-cfc35ca53a1b.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\869de3a0-2901-4e55-aae0-8cd0a200572e.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\a3ee1637-f77f-41df-867a-d5502ed97869.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\b7bcac12-af18-43af-a324-7a1ac2e12d7e.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6a4.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_8dc.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\~DF340A.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03232009_103344

Files moved on Reboot…
File C:\DOCUME~1\Angela\LOCALS~1\Temp\IM\MSG19.tmp not found!
File C:\DOCUME~1\Angela\LOCALS~1\Temp\etilqs_KXVO0HiL3Ybh1uKixaCY not found!
File C:\WINDOWS\temp\47cc60ed-5a09-4b06-846d-fb241efb738e.tmp not found!
File C:\WINDOWS\temp\59e12d8d-d53a-42b5-ab0c-cfc35ca53a1b.tmp not found!
File C:\WINDOWS\temp\869de3a0-2901-4e55-aae0-8cd0a200572e.tmp not found!
C:\WINDOWS\temp\a3ee1637-f77f-41df-867a-d5502ed97869.tmp moved successfully.
File C:\WINDOWS\temp\b7bcac12-af18-43af-a324-7a1ac2e12d7e.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_6a4.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_8dc.dat moved successfully.
C:\WINDOWS\temp\~DF340A.tmp moved successfully.
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\ahzywolk.default\XUL.mfl moved successfully.
********************************************************************************
***********************************
********************************************************************************
***********************************

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:45:07 AM, on 3/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\PSIService.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
C:\Program Files\eAcceleration\Firewall\FWService.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\eAcceleration\OnAccess\onaccess.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pando Networks\Pando\pando.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
C:\Program Files\eAcceleration\Station\station_bk.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OnAccess] "C:\Program Files\eAcceleration\OnAccess\onaccess.exe" -erk
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\pando.exe" /Minimized
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O9 - Extra 'Tools' menuitem: Block This Page - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: eAcceleration Notification Service (eac_notifysvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
O23 - Service: FWService - eAcceleration Corp - C:\Program Files\eAcceleration\Firewall\FWService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 8536 bytes
Hi Demented Dolly,

Good morning to you too.

You have AVG8 and Stop Sign installed. You should have only one anti virus program. Please advise on your intention.


MBAM-is that the trial version or the paid version you have installed?

Thanks
Ill uninstall the stopsign one and just have AVG. Im not sure however what this MBAM is that you speak of. Could you elaborate please?
Hi Demented Dolly Malwarebytes' Anti-Malware-MBAM I had you download it. I wasn't sure if you went for the freebie or the paid version. The trial version will revert to on demand after the trial period. It's a very good scanner and I suggest you keep it as an on demand scanner at the very least. Once you uninstall Stop Sign completely you will need to turn on the Windows Firewall until we do the clean up. A 3rd party firewall will be in the recommendations posted with the clean up instructions. Let me know how the uninstall goes and please post 1 more HJT log. Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI