This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Hijack This Log - please help, Internet Explorer Script

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

When I turn my computer on and log in the following error box is displayed every time:
"Internet Explorer Script Error
An error has occurred in the script on this page.
Line 3
Char: 1
Syntax Error
Code: 0
URL - file:///C:Documents%20and%20Settings/Owner/Application%20Data/Microsoft/Internet%20Explorer/Desktop.htt"


I have tried clicking on yes, no and xing out of it, but nothing works to remove this error permanently. After I get out of the error box, my computer continually "runs" (meaning I can hear it still trying to compute data in the modem). When I then try to log on to the internet, it takes an extremely LONG time (could be 5 mins. if I'm extremely lucky, but more than likely takes at least 15 mins.-30 mins.) for a webpage to show up on the screen. Once a webpage finally comes up, if a try to go to a different website it takes just as long for a new webpage to come up.

Below is my hijacklog from today:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:18:55 PM, on 4/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wltray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iGive_Toolbar\igvtt.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\regscan.exe
C:\Program Files\iGive_Toolbar\igvtp.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Dynex G USB Network Adapter\DynexWCUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,jiqhpbc.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Smart-Shopper - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
O3 - Toolbar: iGive Toolbar - {FA73AE1B-4BA9-4E8B-832B-54A287FF1B7F} - C:\Program Files\iGive_Toolbar\igvtb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
O4 - HKLM\..\Run: [u4a7] C:\documents and settings\owner\local settings\temp\u4a7.exe
O4 - HKLM\..\Run: [hnATqcjm] C:\windows\system32\hnATqcjm.exe
O4 - HKLM\..\Run: [5f533594e4d8] C:\WINDOWS\System32\certcli1.exe
O4 - HKLM\..\Run: [Qjmpnao] C:\Program Files\Chvzc\Dprp.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ikqqogc] C:\WINDOWS\system32\pemgmrr.exe r
O4 - HKLM\..\Run: [aldpsywA] C:\WINDOWS\aldpsywA.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\ywwioi.exe reg_run
O4 - HKLM\..\Run: [iuwrft] C:\WINDOWS\system32\idsafv.exe reg_run
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager] C:\WINDOWS\system32\wltray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [igvtm] "C:\Program Files\iGive_Toolbar\igvtt.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [rsvxpr] C:\WINDOWS\System32\rsvxpr.exe
O4 - HKCU\..\Run: [MoneyAgent] C:\Program Files\Microsoft Money\System\mnyexpr.exe
O4 - HKCU\..\Run: [eresg] C:\WINDOWS\system32\idsafv.exe reg_run
O4 - HKCU\..\Run: [wallp2.exe] C:\WINDOWS\system32\wallp2.exe
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Policies\Explorer\Run: [rsvxpr] C:\WINDOWS\System32\rsvxpr.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Dynex Wireless Networking Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O12 - Plugin for .midi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O15 - Trusted Zone: http://www.gapbuster.com
O15 - Trusted Zone: http://www.xec.gapbuster.com
O15 - Trusted Zone: http://registration.iwon.com
O15 - Trusted Zone: http://origin.rockstar.msn.com
O15 - Trusted Zone: http://login.myspace.com
O15 - Trusted Zone: http://www.myspace.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWire…loadControl.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jin…indows-i586.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Common Files\nidos.html

–
End of file - 12630 bytes

Please help. Thank you very much.

Melinda
Hi,

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi,

I put my Hijack Log Report on this forum on 4/11/09 and was told to run the ComboFix program. I have done so and below is the log from ComboFix. Please let me know what I need to do next. Thank you.

Melinda


ComboFix 09-04-15.03 - Owner 04/14/2009 19:19.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.247.62 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
AV: BellSouth Internet Security Anti-Virus *On-access scanning disabled* (Updated)
FW: BellSouth Internet Security Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Application Data\ASKS~1
c:\documents and settings\Owner\Application Data\ICROSO~1
c:\documents and settings\Owner\Application Data\SCURIT~1
c:\documents and settings\Owner\Application Data\SEMBLY~1
c:\documents and settings\Owner\Application Data\SpamBlocker
c:\documents and settings\Owner\Application Data\YSTEM~1
c:\documents and settings\Owner\Application Data\YSTEM~1\smss.exe
c:\documents and settings\Owner\My Documents\ASKS~1
c:\documents and settings\Owner\My Documents\FNTS~1
c:\documents and settings\Owner\My Documents\ICROSO~1.NET
c:\documents and settings\Owner\My Documents\MCROSO~1.NET
c:\documents and settings\Owner\My Documents\SMANTE~1
c:\documents and settings\Owner\My Documents\SSTEM~1
c:\documents and settings\Owner\My Documents\SSTEM3~1
C:\lswmv.ini
c:\program files\Common Files\asembl~1
c:\program files\Common Files\fnts~1
c:\program files\Common Files\nidos.html
c:\program files\Common Files\sembly~1
c:\program files\Common Files\sks~1
c:\program files\Common Files\sks~1\rotr.exe
c:\program files\Common Files\ssembl~1
c:\program files\Common Files\sstem~1
c:\program files\Common Files\stem32~1
c:\program files\Common Files\uninstall information
c:\program files\Common Files\ymbols~1
c:\program files\dns
c:\program files\dns\affid.dat
c:\program files\dns\regexp.dat
c:\program files\dns\regexpDate.dat
c:\program files\dns\uid.dat
c:\program files\dns\urls.dat
c:\program files\dns\version.txt
c:\program files\dns\x.bmp
c:\program files\ecurit~1
c:\program files\fnts~1
c:\program files\fnts~2
c:\program files\mantec~1
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\4.bin\MWSOEMON.EXE_tobedeleted
c:\program files\MyWebSearch\bar\4.bin\MWSOESTB.DLL_tobedeleted
c:\program files\newdotnet
c:\program files\newdotnet\readme.html
c:\program files\newdotnet\uninstall6_38.exe
c:\program files\sks~1
c:\program files\sstem3~1
c:\program files\wnsxs~1
c:\program files\ymante~1
c:\windows\crosof~1
c:\windows\Downloaded Program Files\UDC6_0001_D9M1705NetInstaller.exe
c:\windows\Downloaded Program Files\UWA6P_0001_N68M2301NetInstaller.exe
c:\windows\IE4 Error Log.txt
c:\windows\mantec~1
c:\windows\ms056261211682006.exe
c:\windows\NDNuninstall6_38.exe
c:\windows\pi1.exe
c:\windows\pppatc~1
c:\windows\racle~1
c:\windows\smbols~1
c:\windows\system32\~.exe
c:\windows\system32\crosof~1
c:\windows\system32\curity~1
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\icroso~1.net
c:\windows\system32\oins.exe
c:\windows\system32\regscan.exe
c:\windows\system32\sks~1
c:\windows\system32\ssembl~1
c:\windows\system32\sstem3~1
c:\windows\system32\wintit.exe
c:\windows\wnsxs~1
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_CMDSERVICE


((((((((((((((((((((((((( Files Created from 2009-03-15 to 2009-04-15 )))))))))))))))))))))))))))))))
.

2009-04-11 17:50 . 2009-04-11 17:53 ——– d–h–w C:\$AVG8.VAULT$
2009-04-11 17:44 . 2009-04-11 17:44 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-11 17:44 . 2009-04-11 17:44 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-11 17:43 . 2009-04-11 17:43 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-11 17:43 . 2009-04-14 23:41 ——– d—–w c:\windows\system32\drivers\Avg
2009-04-11 17:43 . 2009-04-11 17:51 ——– d—–w c:\documents and settings\Owner\Application Data\AVGTOOLBAR
2009-04-11 17:42 . 2009-04-11 17:42 ——– d—–w c:\program files\AVG
2009-04-11 17:42 . 2009-04-11 17:59 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-03-30 02:25 . 2009-03-30 02:25 ——– d—–w c:\program files\ERUNT
2009-03-29 15:28 . 2009-03-29 15:28 ——– d—–w c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 00:40 . 2008-11-28 13:18 ——– d—–w c:\documents and settings\Owner\Application Data\iGive_Toolbar
2009-04-14 02:45 . 2009-02-08 19:23 ——– d—–w c:\documents and settings\Owner\Application Data\Smart-Shopper
2009-03-29 14:56 . 2004-05-02 16:41 ——– d—–w c:\program files\Common Files\Adobe
2009-02-26 05:47 . 2007-04-26 22:48 ——– d—–w c:\program files\Google
2009-02-09 10:19 . 1999-06-13 19:22 1846272 —-a-w c:\windows\system32\win32k.sys
2007-09-29 15:10 . 2003-08-23 14:12 52496 —-a-w c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2005-03-01 02:03 . 2005-03-01 02:03 61440 —-a-w c:\documents and settings\Owner\Application Data\tizupd.bin
2003-08-24 03:26 . 2005-05-14 05:17 29352 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2003-08-23 14:12 . 2005-05-14 05:17 128 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2003-08-23 14:12 . 2003-08-23 14:12 128 —-a-w c:\documents and settings\Owner\Local Settings\Application Data\fusioncache.dat
2001-06-20 21:19 . 2001-06-19 21:34 40960 —-a-w c:\program files\ACMonitor_X83.exe
2007-03-12 09:2007-04-09 00:22 01:33 . c:\program files\mozilla firefox\components\jar50.dll
2007-03-12 09:2007-04-09 00:22 01:34 . c:\program files\mozilla firefox\components\jsd3250.dll
2007-03-12 09:2007-04-09 00:22 01:36 . c:\program files\mozilla firefox\components\myspell.dll
2007-03-12 09:2007-04-09 00:22 01:38 . c:\program files\mozilla firefox\components\spellchk.dll
2007-03-12 09:2007-04-09 00:22 01:40 . c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-CEC4-75A487FD6484}]
2008-11-12 12:12 1909248 —-a-w c:\progra~1\mypoints\mypoints.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-CEC4-75A487FD6484}"= "c:\progra~1\mypoints\mypoints.dll" [2008-11-12 1909248]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-cec4-75a487fd6484}]
[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A057A204-BACC-4D26-CEC4-75A487FD6484}"= "c:\progra~1\mypoints\mypoints.dll" [2008-11-12 1909248]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-cec4-75a487fd6484}]
[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-04 143360]
"BellSouthAlertManager.exe"="c:\program files\BellSouth\Alert Manager\BellSouthAlertManager.exe" [2006-01-10 1896448]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-06-14 1282048]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-30 185896]
"igvtm"="c:\program files\iGive_Toolbar\igvtt.exe" [2008-08-29 300328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-11 1932568]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-08-14 5562368]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
AutoTBar.exe [2003-6-18 53248]
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Dynex Wireless Networking Utility.lnk - c:\program files\Dynex G USB Network Adapter\DynexWCUI.exe [2008-4-2 1458176]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-11 17:44 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.D263"= xl_x263dec.dll
"VIDC.YV12"= xl_yv12.dll
"VIDC.XJPG"= camfc.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 8.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 8.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Corel Registration.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Corel Registration.lnk
backup=c:\windows\pss\Corel Registration.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL 9.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CorelCENTRAL 9.LNK
backup=c:\windows\pss\CorelCENTRAL 9.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL Alarms.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CorelCENTRAL Alarms.LNK
backup=c:\windows\pss\CorelCENTRAL Alarms.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Application Director 9.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Desktop Application Director 9.LNK
backup=c:\windows\pss\Desktop Application Director 9.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=c:\windows\pss\MyWebSearch Email Plugin.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
backup=c:\windows\pss\MyWebSearch Email Plugin.lnkStartup
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^PalNetaware.lnk]
backup=c:\windows\pss\PalNetaware.lnkStartup
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\PalNetaware.lnk

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
backup=c:\windows\pss\spamsubtract.lnkStartup
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
2005-08-05 20:08 67160 —-a-w c:\progra~1\AIM\aim.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoTKit]
2003-06-19 02:19 53248 —-a-w c:\hp\bin\AUTOTKIT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupNotify]
2003-06-23 04:25 24576 —-a-w c:\program files\Hewlett-Packard\Digital Imaging\bin\BackupNotify.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
2002-10-07 14:23 90112 —-a-w c:\program files\Hewlett-Packard\Digital Imaging\\Unload\HpqCmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2004-08-20 21:51 118784 —-a-w c:\windows\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-06-14 06:53 49152 —-a-w c:\program files\HP\HP Software Update\hpwuSchd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2002-11-22 19:49 188416 —-a-w c:\windows\System32\spool\drivers\w32x86\3\hpztsb07.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon04]
2002-11-22 19:48 348160 —-a-w c:\windows\System32\hphmon04.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
2003-05-23 09:55 483328 —-a-w c:\windows\System32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD04]
2002-11-22 19:50 49152 —-a-w c:\program files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
2003-05-23 10:03 49152 —-a-w c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 23:04 52736 —-a-w c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-12 03:02 61440 —-a-w c:\hp\KBD\kbd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2003-05-03 06:19 4640768 —-a-w c:\windows\System32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-10-16 23:57 81920 —-a-w c:\windows\system32\ps2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 04:42 212992 —-a-w c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
2002-04-17 16:42 69632 —-a-w c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tgcmd]
2003-09-15 02:44 1847296 —-a-w c:\program files\Support.com\bin\tgcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-04-30 00:58 185896 —-a-w c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
2004-11-11 04:15 111816 —-a-w c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
2005-09-02 20:50 302528 —-a-w c:\program files\WildTangent\Apps\CDA\CDAEngine0400.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 19:47 57344 —-a-w c:\windows\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]
2003-05-03 06:19 835654 —-a-w c:\windows\system32\nview.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2003-05-03 06:19 323584 —-a-w c:\windows\system32\nwiz.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"55630:TCP"= 55630:TCP:PORT_55630
"57705:TCP"= 57705:TCP:PORT_57705
"33950:TCP"= 33950:TCP:PORT_33950
"32111:TCP"= 32111:TCP:PORT_32111
"58958:TCP"= 58958:TCP:PORT_58958
"14903:TCP"= 14903:TCP:PORT_14903
"9904:TCP"= 9904:TCP:PORT_9904
"33616:TCP"= 33616:TCP:PORT_33616
"10809:TCP"= 10809:TCP:PORT_10809
"19748:TCP"= 19748:TCP:PORT_19748
"6459:TCP"= 6459:TCP:PORT_6459
"6591:TCP"= 6591:TCP:PORT_6591
"57379:TCP"= 57379:TCP:PORT_57379
"24573:TCP"= 24573:TCP:PORT_24573
"11903:TCP"= 11903:TCP:PORT_11903
"9000:TCP"= 9000:TCP:PORT_9000
"55761:TCP"= 55761:TCP:PORT_55761
"49066:TCP"= 49066:TCP:PORT_49066
"46476:TCP"= 46476:TCP:PORT_46476
"22684:TCP"= 22684:TCP:PORT_22684
"14871:TCP"= 14871:TCP:PORT_14871
"36123:TCP"= 36123:TCP:PORT_36123
"65195:TCP"= 65195:TCP:PORT_65195
"24225:TCP"= 24225:TCP:PORT_24225
"45225:TCP"= 45225:TCP:PORT_45225
"59523:TCP"= 59523:TCP:PORT_59523
"21309:TCP"= 21309:TCP:PORT_21309
"58853:TCP"= 58853:TCP:PORT_58853
"20376:TCP"= 20376:TCP:PORT_20376
"31763:TCP"= 31763:TCP:PORT_31763
"49116:TCP"= 49116:TCP:PORT_49116
"15544:TCP"= 15544:TCP:PORT_15544
"54798:TCP"= 54798:TCP:PORT_54798
"59822:TCP"= 59822:TCP:PORT_59822
"49430:TCP"= 49430:TCP:PORT_49430
"29645:TCP"= 29645:TCP:PORT_29645
"7831:TCP"= 7831:TCP:PORT_7831
"9973:TCP"= 9973:TCP:PORT_9973
"48215:TCP"= 48215:TCP:PORT_48215
"54680:TCP"= 54680:TCP:PORT_54680
"42974:TCP"= 42974:TCP:PORT_42974
"49297:TCP"= 49297:TCP:PORT_49297
"44728:TCP"= 44728:TCP:PORT_44728
"20461:TCP"= 20461:TCP:PORT_20461
"41443:TCP"= 41443:TCP:PORT_41443
"12888:TCP"= 12888:TCP:PORT_12888
"34365:TCP"= 34365:TCP:PORT_34365
"55906:TCP"= 55906:TCP:PORT_55906
"64953:TCP"= 64953:TCP:PORT_64953
"25673:TCP"= 25673:TCP:PORT_25673
"21200:TCP"= 21200:TCP:PORT_21200
"13950:TCP"= 13950:TCP:PORT_13950
"49950:TCP"= 49950:TCP:PORT_49950
"10296:TCP"= 10296:TCP:PORT_10296
"45781:TCP"= 45781:TCP:PORT_45781
"21028:TCP"= 21028:TCP:PORT_21028
"24673:TCP"= 24673:TCP:PORT_24673
"55270:TCP"= 55270:TCP:PORT_55270
"24733:TCP"= 24733:TCP:PORT_24733
"59098:TCP"= 59098:TCP:PORT_59098
"54458:TCP"= 54458:TCP:PORT_54458
"10578:TCP"= 10578:TCP:PORT_10578
"64559:TCP"= 64559:TCP:PORT_64559
"39743:TCP"= 39743:TCP:PORT_39743
"13769:TCP"= 13769:TCP:PORT_13769
"30033:TCP"= 30033:TCP:PORT_30033
"54938:TCP"= 54938:TCP:PORT_54938
"34368:TCP"= 34368:TCP:PORT_34368
"33769:TCP"= 33769:TCP:PORT_33769
"58758:TCP"= 58758:TCP:PORT_58758
"35801:TCP"= 35801:TCP:PORT_35801
"8314:TCP"= 8314:TCP:PORT_8314
"46064:TCP"= 46064:TCP:PORT_46064
"58441:TCP"= 58441:TCP:PORT_58441
"23020:TCP"= 23020:TCP:PORT_23020
"17607:TCP"= 17607:TCP:PORT_17607
"25477:TCP"= 25477:TCP:PORT_25477
"29625:TCP"= 29625:TCP:PORT_29625
"24512:TCP"= 24512:TCP:PORT_24512
"55643:TCP"= 55643:TCP:PORT_55643
"60866:TCP"= 60866:TCP:PORT_60866
"47879:TCP"= 47879:TCP:PORT_47879
"9688:TCP"= 9688:TCP:PORT_9688
"39758:TCP"= 39758:TCP:PORT_39758
"44781:TCP"= 44781:TCP:PORT_44781
"50386:TCP"= 50386:TCP:PORT_50386
"9261:TCP"= 9261:TCP:PORT_9261
"23380:TCP"= 23380:TCP:PORT_23380
"32790:TCP"= 32790:TCP:PORT_32790
"34115:TCP"= 34115:TCP:PORT_34115
"30325:TCP"= 30325:TCP:PORT_30325
"32199:TCP"= 32199:TCP:PORT_32199
"26820:TCP"= 26820:TCP:PORT_26820
"17367:TCP"= 17367:TCP:PORT_17367
"45800:TCP"= 45800:TCP:PORT_45800
"46281:TCP"= 46281:TCP:PORT_46281
"7891:TCP"= 7891:TCP:PORT_7891
"21266:TCP"= 21266:TCP:PORT_21266
"60427:TCP"= 60427:TCP:PORT_60427
"50271:TCP"= 50271:TCP:PORT_50271
"14257:TCP"= 14257:TCP:PORT_14257
"34476:TCP"= 34476:TCP:PORT_34476
"58411:TCP"= 58411:TCP:PORT_58411
"17563:TCP"= 17563:TCP:PORT_17563
"46151:TCP"= 46151:TCP:PORT_46151
"19161:TCP"= 19161:TCP:PORT_19161
"22614:TCP"= 22614:TCP:PORT_22614
"33132:TCP"= 33132:TCP:PORT_33132
"36317:TCP"= 36317:TCP:PORT_36317
"56606:TCP"= 56606:TCP:PORT_56606
"8728:TCP"= 8728:TCP:PORT_8728
"25851:TCP"= 25851:TCP:PORT_25851
"33469:TCP"= 33469:TCP:PORT_33469
"57928:TCP"= 57928:TCP:PORT_57928
"28333:TCP"= 28333:TCP:PORT_28333
"38235:TCP"= 38235:TCP:PORT_38235
"29891:TCP"= 29891:TCP:PORT_29891
"53153:TCP"= 53153:TCP:PORT_53153
"60968:TCP"= 60968:TCP:PORT_60968
"42696:TCP"= 42696:TCP:PORT_42696
"33316:TCP"= 33316:TCP:PORT_33316
"35727:TCP"= 35727:TCP:PORT_35727
"50039:TCP"= 50039:TCP:PORT_50039
"18599:TCP"= 18599:TCP:PORT_18599
"16785:TCP"= 16785:TCP:PORT_16785
"31367:TCP"= 31367:TCP:PORT_31367
"18100:TCP"= 18100:TCP:PORT_18100
"12798:TCP"= 12798:TCP:PORT_12798
"6446:TCP"= 6446:TCP:PORT_6446
"25426:TCP"= 25426:TCP:PORT_25426
"63956:TCP"= 63956:TCP:PORT_63956
"25114:TCP"= 25114:TCP:PORT_25114
"37221:TCP"= 37221:TCP:PORT_37221
"50278:TCP"= 50278:TCP:PORT_50278
"14016:TCP"= 14016:TCP:PORT_14016
"57054:TCP"= 57054:TCP:PORT_57054
"23891:TCP"= 23891:TCP:PORT_23891
"49082:TCP"= 49082:TCP:PORT_49082
"51656:TCP"= 51656:TCP:PORT_51656
"65292:TCP"= 65292:TCP:PORT_65292
"35140:TCP"= 35140:TCP:PORT_35140
"58156:TCP"= 58156:TCP:PORT_58156
"32880:TCP"= 32880:TCP:PORT_32880
"58805:TCP"= 58805:TCP:PORT_58805
"57103:TCP"= 57103:TCP:PORT_57103
"47586:TCP"= 47586:TCP:PORT_47586
"49083:TCP"= 49083:TCP:PORT_49083
"27684:TCP"= 27684:TCP:PORT_27684
"49250:TCP"= 49250:TCP:PORT_49250
"64770:TCP"= 64770:TCP:PORT_64770
"43204:TCP"= 43204:TCP:PORT_43204
"11219:TCP"= 11219:TCP:PORT_11219
"7750:TCP"= 7750:TCP:PORT_7750
"37035:TCP"= 37035:TCP:PORT_37035
"62926:TCP"= 62926:TCP:PORT_62926
"21778:TCP"= 21778:TCP:PORT_21778
"21983:TCP"= 21983:TCP:PORT_21983
"57851:TCP"= 57851:TCP:PORT_57851
"47146:TCP"= 47146:TCP:PORT_47146
"55844:TCP"= 55844:TCP:PORT_55844
"53165:TCP"= 53165:TCP:PORT_53165
"50373:TCP"= 50373:TCP:PORT_50373
"11696:TCP"= 11696:TCP:PORT_11696
"23173:TCP"= 23173:TCP:PORT_23173
"30778:TCP"= 30778:TCP:PORT_30778
"7957:TCP"= 7957:TCP:PORT_7957
"59643:TCP"= 59643:TCP:PORT_59643
"42425:TCP"= 42425:TCP:PORT_42425
"15248:TCP"= 15248:TCP:PORT_15248
"28540:TCP"= 28540:TCP:PORT_28540
"36586:TCP"= 36586:TCP:PORT_36586
"10047:TCP"= 10047:TCP:PORT_10047
"33871:TCP"= 33871:TCP:PORT_33871
"14517:TCP"= 14517:TCP:PORT_14517
"21713:TCP"= 21713:TCP:PORT_21713
"56621:TCP"= 56621:TCP:PORT_56621
"64333:TCP"= 64333:TCP:PORT_64333
"46258:TCP"= 46258:TCP:PORT_46258
"5919:TCP"= 5919:TCP:PORT_5919
"12910:TCP"= 12910:TCP:PORT_12910
"29760:TCP"= 29760:TCP:PORT_29760
"64606:TCP"= 64606:TCP:PORT_64606
"21352:TCP"= 21352:TCP:PORT_21352
"53125:TCP"= 53125:TCP:PORT_53125
"48552:TCP"= 48552:TCP:PORT_48552
"56375:TCP"= 56375:TCP:PORT_56375
"47540:TCP"= 47540:TCP:PORT_47540
"45910:TCP"= 45910:TCP:PORT_45910
"19213:TCP"= 19213:TCP:PORT_19213
"9219:TCP"= 9219:TCP:PORT_9219
"60282:TCP"= 60282:TCP:PORT_60282
"34378:TCP"= 34378:TCP:PORT_34378
"46725:TCP"= 46725:TCP:PORT_46725
"34637:TCP"= 34637:TCP:PORT_34637
"13157:TCP"= 13157:TCP:PORT_13157
"24004:TCP"= 24004:TCP:PORT_24004
"50806:TCP"= 50806:TCP:PORT_50806
"30780:TCP"= 30780:TCP:PORT_30780
"57226:TCP"= 57226:TCP:PORT_57226
"7227:TCP"= 7227:TCP:PORT_7227
"11067:TCP"= 11067:TCP:PORT_11067
"23325:TCP"= 23325:TCP:PORT_23325
"36568:TCP"= 36568:TCP:PORT_36568
"28423:TCP"= 28423:TCP:PORT_28423
"8219:TCP"= 8219:TCP:PORT_8219
"10196:TCP"= 10196:TCP:PORT_10196
"22004:TCP"= 22004:TCP:PORT_22004
"30541:TCP"= 30541:TCP:PORT_30541
"34711:TCP"= 34711:TCP:PORT_34711
"16321:TCP"= 16321:TCP:PORT_16321
"40215:TCP"= 40215:TCP:PORT_40215
"30703:TCP"= 30703:TCP:PORT_30703
"23676:TCP"= 23676:TCP:PORT_23676
"38204:TCP"= 38204:TCP:PORT_38204
"16678:TCP"= 16678:TCP:PORT_16678
"9657:TCP"= 9657:TCP:PORT_9657
"55528:TCP"= 55528:TCP:PORT_55528
"7784:TCP"= 7784:TCP:PORT_7784
"11836:TCP"= 11836:TCP:PORT_11836
"53141:TCP"= 53141:TCP:PORT_53141
"64332:TCP"= 64332:TCP:PORT_64332
"51278:TCP"= 51278:TCP:PORT_51278
"32775:TCP"= 32775:TCP:PORT_32775
"51919:TCP"= 51919:TCP:PORT_51919
"58330:TCP"= 58330:TCP:PORT_58330
"42066:TCP"= 42066:TCP:PORT_42066
"32955:TCP"= 32955:TCP:PORT_32955
"28890:TCP"= 28890:TCP:PORT_28890
"31723:TCP"= 31723:TCP:PORT_31723
"30239:TCP"= 30239:TCP:PORT_30239
"20695:TCP"= 20695:TCP:PORT_20695
"11857:TCP"= 11857:TCP:PORT_11857
"23065:TCP"= 23065:TCP:PORT_23065
"12259:TCP"= 12259:TCP:PORT_12259
"34995:TCP"= 34995:TCP:PORT_34995
"15986:TCP"= 15986:TCP:PORT_15986
"26606:TCP"= 26606:TCP:PORT_26606
"47570:TCP"= 47570:TCP:PORT_47570
"14238:TCP"= 14238:TCP:PORT_14238
"47563:TCP"= 47563:TCP:PORT_47563
"40446:TCP"= 40446:TCP:PORT_40446
"12413:TCP"= 12413:TCP:PORT_12413
"20060:TCP"= 20060:TCP:PORT_20060
"37641:TCP"= 37641:TCP:PORT_37641
"29048:TCP"= 29048:TCP:PORT_29048
"51414:TCP"= 51414:TCP:PORT_51414
"20828:TCP"= 20828:TCP:PORT_20828
"12320:TCP"= 12320:TCP:PORT_12320
"52763:TCP"= 52763:TCP:PORT_52763
"6294:TCP"= 6294:TCP:PORT_6294
"60688:TCP"= 60688:TCP:PORT_60688
"20403:TCP"= 20403:TCP:PORT_20403
"44993:TCP"= 44993:TCP:PORT_44993
"30805:TCP"= 30805:TCP:PORT_30805
"36088:TCP"= 36088:TCP:PORT_36088
"9341:TCP"= 9341:TCP:PORT_9341
"34828:TCP"= 34828:TCP:PORT_34828
"60867:TCP"= 60867:TCP:PORT_60867
"16797:TCP"= 16797:TCP:PORT_16797
"18534:TCP"= 18534:TCP:PORT_18534
"43110:TCP"= 43110:TCP:PORT_43110
"56930:TCP"= 56930:TCP:PORT_56930
"38064:TCP"= 38064:TCP:PORT_38064
"44876:TCP"= 44876:TCP:PORT_44876
"21658:TCP"= 21658:TCP:PORT_21658
"34603:TCP"= 34603:TCP:PORT_34603
"53981:TCP"= 53981:TCP:PORT_53981
"38560:TCP"= 38560:TCP:PORT_38560
"24739:TCP"= 24739:TCP:PORT_24739
"24818:TCP"= 24818:TCP:PORT_24818
"20535:TCP"= 20535:TCP:PORT_20535
"22135:TCP"= 22135:TCP:PORT_22135
"34797:TCP"= 34797:TCP:PORT_34797
"40270:TCP"= 40270:TCP:PORT_40270
"37513:TCP"= 37513:TCP:PORT_37513
"33433:TCP"= 33433:TCP:PORT_33433
"8414:TCP"= 8414:TCP:PORT_8414
"53651:TCP"= 53651:TCP:PORT_53651
"13487:TCP"= 13487:TCP:PORT_13487
"10711:TCP"= 10711:TCP:PORT_10711
"9471:TCP"= 9471:TCP:PORT_9471
"20216:TCP"= 20216:TCP:PORT_20216
"33798:TCP"= 33798:TCP:PORT_33798
"27473:TCP"= 27473:TCP:PORT_27473
"18801:TCP"= 18801:TCP:PORT_18801
"37837:TCP"= 37837:TCP:PORT_37837
"13676:TCP"= 13676:TCP:PORT_13676
"8665:TCP"= 8665:TCP:PORT_8665
"26102:TCP"= 26102:TCP:PORT_26102
"39641:TCP"= 39641:TCP:PORT_39641
"42161:TCP"= 42161:TCP:PORT_42161
"48838:TCP"= 48838:TCP:PORT_48838
"7673:TCP"= 7673:TCP:PORT_7673
"50378:TCP"= 50378:TCP:PORT_50378
"32009:TCP"= 32009:TCP:PORT_32009
"47606:TCP"= 47606:TCP:PORT_47606
"12385:TCP"= 12385:TCP:PORT_12385
"7297:TCP"= 7297:TCP:PORT_7297
"51273:TCP"= 51273:TCP:PORT_51273
"10997:TCP"= 10997:TCP:PORT_10997
"12870:TCP"= 12870:TCP:PORT_12870
"22887:TCP"= 22887:TCP:PORT_22887
"50142:TCP"= 50142:TCP:PORT_50142
"47193:TCP"= 47193:TCP:PORT_47193
"14785:TCP"= 14785:TCP:PORT_14785
"39628:TCP"= 39628:TCP:PORT_39628
"9615:TCP"= 9615:TCP:PORT_9615
"8649:TCP"= 8649:TCP:PORT_8649
"35318:TCP"= 35318:TCP:PORT_35318
"15813:TCP"= 15813:TCP:PORT_15813
"58251:TCP"= 58251:TCP:PORT_58251
"32800:TCP"= 32800:TCP:PORT_32800

R2 BulkUsb;Genesys Logic USB Scanner Controller NT 5.0;c:\windows\system32\Drivers\usbscan.sys [2004-08-04 15104]
R3 NdisWDM;Dynex Wireless G USB Network Adapter Service;c:\windows\system32\DRIVERS\ndiswdm.sys [2007-08-31 198528]
R3 XIRLINK;eVision 123 digital camera;c:\windows\system32\DRIVERS\ucdnt.sys [2001-12-06 880008]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-11 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-11 108552]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-11 298264]


— Other Services/Drivers In Memory —

*Deregistered* - 6to4
*Deregistered* - AFD
*Deregistered* - agp440
*Deregistered* - ALG
*Deregistered* - Apple Mobile Device
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avg8wd
*Deregistered* - AvgLdx86
*Deregistered* - AvgMfx86
*Deregistered* - AvgTdiX
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - CSS DVP
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - dvpapi
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Freedom
*Deregistered* - FreeTdi
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - ImapiService
*Deregistered* - ip6fw
*Deregistered* - IpNat
*Deregistered* - iPod Service
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MCSTRM
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - nv_agp
*Deregistered* - NVSvc
*Deregistered* - omniserv
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - RasAcd
*Deregistered* - RasAuto
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SISAGP
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - SymWSC
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - tunmp
*Deregistered* - UMWdf
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - viaagp1
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wltrysvc
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder

2009-02-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]

2006-06-16 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-08-29 23:26]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-rsvxpr - c:\windows\System32\rsvxpr.exe
HKCU-Run-MoneyAgent - c:\program files\Microsoft Money\System\mnyexpr.exe
HKCU-Run-wallp2.exe - c:\windows\system32\wallp2.exe
HKCU-Run-RssReader - c:\program files\RssReader\RssReader.exe
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-u4a7 - c:\documents and settings\owner\local settings\temp\u4a7.exe
HKLM-Run-hnATqcjm - c:\windows\system32\hnATqcjm.exe
HKLM-Run-5f533594e4d8 - c:\windows\System32\certcli1.exe
HKLM-Run-Qjmpnao - c:\program files\Chvzc\Dprp.exe
HKLM-Run-Microsoft Works Update Detection - c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
HKLM-Run-ikqqogc - c:\windows\system32\pemgmrr.exe
HKLM-Run-aldpsywA - c:\windows\aldpsywA.exe
HKCU-Explorer_Run-rsvxpr - c:\windows\System32\rsvxpr.exe
MSConfigStartUp-BJCFD - c:\program files\BroadJump\Client Foundation\CFD.exe
MSConfigStartUp-BullsEye Network - c:\program files\BullsEye Network\bin\bargains.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-ccRegVfy - c:\program files\Common Files\Symantec Shared\ccRegVfy.exe
MSConfigStartUp-Internet Optimizer - c:\program files\Internet Optimizer\optimize.exe
MSConfigStartUp-Megapanel - c:\program files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
MSConfigStartUp-mmtask - c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
MSConfigStartUp-MyWebSearch Email Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
MSConfigStartUp-NetMeter - c:\program files\NetRatingsNetmeter\NetMeter\NielsenOnline.exe
MSConfigStartUp-Notn - c:\documents and settings\Owner\Application Data\wtta.exe
MSConfigStartUp-Qhpzbr - c:\windows\System32\lgonui.exe
MSConfigStartUp-salm - c:\temp\salm.exe
MSConfigStartUp-Tsa2 - c:\progra~1\COMMON~1\tsa\tsm2.exe
MSConfigStartUp-twt - c:\windows\twt.exe
MSConfigStartUp-Weather - c:\progra~1\AWS\WEATHE~1\Weather.EXE
MSConfigStartUp-WebRebates0 - c:\program files\Web_Rebates\WebRebates0.exe
MSConfigStartUp-Windows AdService - c:\program files\Windows AdService\WinAdServ.exe
MSConfigStartUp-WT GameChannel - c:\program files\WildTangent\Apps\GameChannel.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/
uDefault_Search_URL = hxxp://ie.search.msn.com
mSearch Bar =
IE: &AIM; Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
IE: &eBay; Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
Trusted Zone: gapbuster.com\www
Trusted Zone: gapbuster.com\www.xec
Trusted Zone: ice.com\www
Trusted Zone: iwon.com\registration
Trusted Zone: msn.com\origin.rockstar
Trusted Zone: myspace.com\login
Trusted Zone: myspace.com\www
Trusted Zone: nascar.com\www
Trusted Zone: qwizonline.com\www
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-14 19:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\TEMP\XJR75.tmp 0 bytes
c:\windows\TEMP\XJR76.tmp 0 bytes

scan completed successfully
hidden files: 2

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\wltrysvc.exe
c:\windows\system32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Command Software\dvpapi.exe
c:\program files\Softex\OmniPass\omniServ.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\iGive_Toolbar\igvtp.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-04-15 19:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-15 00:49

Pre-Run: 8,272,510,976 bytes free
Post-Run: 8,217,657,344 bytes free

787 — E O F — 2009-03-11 19:22
Hi,

Sorry for the very late reply, but you started a new topic instead of adding a reply to the original topic and I missed it.

Please make sure you select the [external image: Posted Image] button when responding.

Please answer this question:

Do you do a lot of gaming…are you aware of all the Globally OpenPorts on your system, are they there for a reason?


>>>NEXT<<<

Please do the following:


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



>>>NEXT<<<


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply I need

  • MBAM Log
  • Kaspersky report
  • FreshHJT Log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI