This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] White desktop with icons

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My desktop background is only white with icons showing and operable. There is also a message entirled ACTIVE DESKTOP RECOVERY with a box saying "restore my Active Desktop", but when i click on it I get a further message saying "An error has occurred in the script on this page Line :65 Char: 1 Error: Object doesn't support this action Code: 0 URL: file:///C:/Documents%20and%20Settings/Owner/Applicatiob%20Date/Microsoft/Internet%20Explore/Desktop.htt Do you want to continue running scripts on this page? Yes No I have no idea what this means. Also for some time I have not been able to change my desktop backgrounds when I go into Control Pane /Display /Desktop. It seems to be frozen. Thanks

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Hi charlieb1145 and welcome to What the Tech :)

I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:
  • I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine!.
  • The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Refrain from running self fixes as this will hinder the malware removal process.
  • It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
Next:

Please download Rooter.exe to your desktop.

If you have Windows XP: Double click on Rooter to start the application.

If you have Windows Vista: Right click on Rooter and select Run as Administrator to start the application.

  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt.
  • Post the contents of Rooter.txt in your next reply.
Next:

Please download to your desktop DDS from one of the links below:

Link1
Link2
Link3

Disable any Script Blocking protection before running DDS.

If you have Windows XP: Double click on DDS to start the application.

If you have Windows Vista: Right click on DDS and select Run as Administrator to start the application.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finish it will open 2 reports.
  • Copy/paste both reports back here and remove DDS from your desktop.
Note: Two logfiles will be generated with Notepad: DDS.txt and Attach.txt

When completed the above, please post back the following:
  • Any problems encountered and or further symptoms?
  • Rooter Log.
  • Both DDS logs. <– Post them individually please. IE: one Log per post/reply.
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3 C:\ [Fixed] - NTFS - (Total:76308 Mo/Free:2920 Mo) D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) E:\ [Removable] (Total:0 Mo/Free:0 Mo) F:\ [Removable] (Total:0 Mo/Free:0 Mo) G:\ [Removable] (Total:0 Mo/Free:0 Mo) H:\ [Removable] (Total:0 Mo/Free:0 Mo) Thu 05/14/2009|15:03 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe ———- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe ———- C:\Program Files\Common Files\LightScribe\LSSrvc.exe ———- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdnserv.exe ———- C:\WINDOWS\system32\lxdncoms.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\PROGRA~1\AVG\AVG8\avgrsx.exe ———- C:\PROGRA~1\AVG\AVG8\avgemc.exe ———- C:\PROGRA~1\AVG\AVG8\avgnsx.exe ———- C:\Program Files\AVG\AVG8\avgcsrvx.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\alg.exe ———- C:\WINDOWS\AGRSMMSG.exe ———- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe ———- C:\WINDOWS\system32\explorer.exe ———- C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe ———- C:\PROGRA~1\AVG\AVG8\avgtray.exe ———- C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe ———- C:\Program Files\iTunes\iTunesHelper.exe ———- C:\Program Files\Avanquest\AutoSave\AutoSave.exe ———- C:\Program Files\iPod\bin\iPodService.exe ———- C:\Program Files\Lexmark 2600 Series\lxdnmon.exe ———- C:\WINDOWS\system32\hkcmd.exe ———- C:\WINDOWS\system32\igfxpers.exe ———- C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe ———- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ———- C:\WINDOWS\system32\ctfmon.exe ———- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ———- C:\Program Files\Java\jre6\bin\jusched.exe ———- C:\Program Files\Java\jre6\bin\jqs.exe ———- C:\Program Files\Internet Explorer\IEXPLORE.EXE ———- C:\Program Files\Internet Explorer\IEXPLORE.EXE ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_1.txt" - Thu 05/14/2009|15:04
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-05-14.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 2/3/2007 9:01:23 AM System Uptime: 5/6/2009 10:29:08 PM (185 hours ago) Motherboard: ASUSTeK Computer INC. | | Goldfish3 Processor: Intel® Pentium® 4 CPU 2.93GHz | CPU 1 | 2931/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 75 GiB total, 54.85 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP816: 2/14/2009 5:13:22 AM - System Checkpoint RP817: 2/14/2009 9:37:18 AM - Avg8 Update RP818: 2/15/2009 10:13:22 AM - System Checkpoint RP819: 2/16/2009 12:14:26 PM - System Checkpoint RP820: 2/17/2009 1:13:34 PM - System Checkpoint RP821: 2/18/2009 2:15:08 PM - System Checkpoint RP822: 2/19/2009 5:12:36 PM - System Checkpoint RP823: 2/20/2009 6:13:03 PM - System Checkpoint RP824: 2/21/2009 6:13:30 PM - System Checkpoint RP825: 2/22/2009 7:13:29 PM - System Checkpoint RP826: 2/23/2009 7:14:37 PM - System Checkpoint RP827: 2/24/2009 8:14:41 PM - System Checkpoint RP828: 2/25/2009 9:13:38 PM - System Checkpoint RP829: 2/26/2009 3:00:14 AM - Software Distribution Service 3.0 RP830: 2/27/2009 3:54:25 AM - System Checkpoint RP831: 2/28/2009 4:54:27 AM - System Checkpoint RP832: 3/1/2009 5:54:27 AM - System Checkpoint RP833: 3/2/2009 6:54:31 AM - System Checkpoint RP834: 3/3/2009 8:15:29 AM - System Checkpoint RP835: 3/4/2009 9:01:01 AM - System Checkpoint RP836: 3/5/2009 9:54:31 AM - System Checkpoint RP837: 3/6/2009 10:54:30 AM - System Checkpoint RP838: 3/7/2009 11:54:34 AM - System Checkpoint RP839: 3/8/2009 7:57:42 AM - Avg8 Update RP840: 3/9/2009 8:54:35 AM - System Checkpoint RP841: 3/10/2009 9:54:35 AM - System Checkpoint RP842: 3/11/2009 10:54:39 AM - System Checkpoint RP843: 3/12/2009 2:00:14 AM - Software Distribution Service 3.0 RP844: 3/13/2009 2:46:33 AM - System Checkpoint RP845: 3/14/2009 3:46:32 AM - System Checkpoint RP846: 3/15/2009 3:00:15 AM - Software Distribution Service 3.0 RP847: 3/16/2009 3:46:34 AM - System Checkpoint RP848: 3/17/2009 4:46:36 AM - System Checkpoint RP849: 3/18/2009 5:46:35 AM - System Checkpoint RP850: 3/18/2009 9:08:18 AM - Avg8 Update RP851: 3/19/2009 9:46:35 AM - System Checkpoint RP852: 3/20/2009 10:46:36 AM - System Checkpoint RP853: 3/21/2009 11:46:36 AM - System Checkpoint RP854: 3/22/2009 12:46:37 PM - System Checkpoint RP855: 3/23/2009 1:46:42 PM - System Checkpoint RP856: 3/24/2009 2:46:34 PM - System Checkpoint RP857: 3/25/2009 3:08:16 PM - System Checkpoint RP858: 3/26/2009 9:11:40 AM - Software Distribution Service 3.0 RP859: 3/27/2009 3:00:22 AM - Software Distribution Service 3.0 RP860: 3/27/2009 3:07:57 AM - Printer Driver Microsoft XPS Document Writer Installed RP861: 3/27/2009 9:59:42 AM - Avg8 Update RP862: 3/28/2009 10:11:23 AM - System Checkpoint RP863: 3/29/2009 11:11:23 AM - System Checkpoint RP864: 3/30/2009 9:16:35 PM - System Checkpoint RP865: 3/31/2009 9:32:33 PM - System Checkpoint RP866: 4/1/2009 4:18:07 PM - Configured AVG Free 8.5 RP867: 4/2/2009 9:43:33 AM - Avg8 Update RP868: 4/3/2009 10:25:23 AM - System Checkpoint RP869: 4/4/2009 10:41:53 AM - System Checkpoint RP870: 4/5/2009 11:36:41 AM - System Checkpoint RP871: 4/6/2009 12:36:45 PM - System Checkpoint RP872: 4/7/2009 1:36:42 PM - System Checkpoint RP873: 4/8/2009 2:36:45 PM - System Checkpoint RP874: 4/9/2009 2:51:19 PM - System Checkpoint RP875: 4/10/2009 2:59:51 PM - System Checkpoint RP876: 4/11/2009 9:34:45 AM - Avg8 Update RP877: 4/11/2009 11:23:27 PM - Installed Java™ 6 Update 13 RP878: 4/13/2009 12:00:06 AM - System Checkpoint RP879: 4/14/2009 1:00:07 AM - System Checkpoint RP880: 4/14/2009 10:40:45 PM - Configured Microsoft Office Professional 2007 Trial RP881: 4/15/2009 11:32:51 PM - System Checkpoint RP882: 4/16/2009 3:00:14 AM - Software Distribution Service 3.0 RP883: 4/16/2009 9:42:39 AM - Avg8 Update RP884: 4/17/2009 10:18:58 AM - System Checkpoint RP885: 4/18/2009 10:19:07 AM - System Checkpoint RP886: 4/19/2009 11:19:06 AM - System Checkpoint RP887: 4/20/2009 12:19:07 PM - System Checkpoint RP888: 4/21/2009 1:19:07 PM - System Checkpoint RP889: 4/22/2009 1:22:43 PM - System Checkpoint RP890: 4/23/2009 2:19:19 PM - System Checkpoint RP891: 4/24/2009 2:43:44 PM - System Checkpoint RP892: 4/25/2009 3:19:19 PM - System Checkpoint RP893: 4/26/2009 4:19:18 PM - System Checkpoint RP894: 4/27/2009 5:43:35 PM - System Checkpoint RP895: 4/27/2009 9:17:39 PM - Configured Microsoft Office Professional 2007 Trial RP896: 4/28/2009 9:19:18 PM - System Checkpoint RP897: 4/29/2009 10:19:19 PM - System Checkpoint RP898: 4/30/2009 11:19:17 PM - System Checkpoint RP899: 5/2/2009 12:19:26 AM - System Checkpoint RP900: 5/3/2009 1:19:27 AM - System Checkpoint RP901: 5/3/2009 8:16:10 AM - Avg8 Update RP902: 5/3/2009 8:16:51 AM - Avg8 Update RP903: 5/4/2009 8:19:26 AM - System Checkpoint RP904: 5/4/2009 2:46:22 PM - Restore Operation RP905: 5/4/2009 2:54:10 PM - Avg8 Update RP906: 5/4/2009 3:01:09 PM - Restore Operation RP907: 5/4/2009 3:15:40 PM - Software Distribution Service 3.0 RP908: 5/5/2009 4:00:04 PM - System Checkpoint RP909: 5/5/2009 7:26:01 PM - Installed Microsoft Office Professional 2007 Trial RP910: 5/5/2009 9:41:45 PM - Installed ErrorFix RP911: 5/5/2009 10:11:00 PM - Configured Microsoft Office Professional 2007 Trial RP912: 5/6/2009 8:48:16 AM - Removed Microsoft Office Professional 2007 Trial RP913: 5/6/2009 9:06:32 AM - Removed ErrorFix RP914: 5/6/2009 10:04:43 AM - Software Distribution Service 3.0 RP915: 5/6/2009 10:47:04 AM - Printer Driver Microsoft XPS Document Writer Installed RP916: 5/6/2009 9:10:42 PM - Software Distribution Service 3.0 RP917: 5/7/2009 9:33:49 PM - System Checkpoint RP918: 5/8/2009 10:33:48 PM - System Checkpoint RP919: 5/9/2009 8:57:19 PM - Removed Bonjour RP920: 5/10/2009 9:41:35 PM - System Checkpoint RP921: 5/11/2009 10:33:56 PM - System Checkpoint RP922: 5/12/2009 3:24:25 PM - Installed Java™ 6 Update 13 RP923: 5/13/2009 3:00:14 AM - Software Distribution Service 3.0 RP924: 5/14/2009 3:33:56 AM - System Checkpoint ==== Installed Programs ====================== Adobe Acrobat 5.0 Adobe Flash Player 10 ActiveX Adobe Reader 8.1.4 Adobe® Photoshop® Album Starter Edition 3.0 Adobe® Photoshop® Album Starter Edition 3.0.1 Agere Systems PCI Soft Modem Apple Mobile Device Support Apple Software Update Art Explosion Label Factory Deluxe AutoSave AVG Free 8.0 AVS DVDMenu Editor 1.2.1.19 AVS Video Editor 3.5 Brother's Keeper 6.2 Corel Applications Cosmi's Photo Editor Critical Update for Windows Media Player 11 (KB959772) eBay Toolbar Featuring Yahoo! Express Burn Express Dictate Google Toolbar for Internet Explorer High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) ImagXpress Intel® Graphics Media Accelerator Driver iTunes Java 2 Runtime Environment Standard Edition v1.3.1_10 Java™ 6 Update 13 Java™ 6 Update 5 Java™ 6 Update 7 Kudo® Catalog Reader 3.1 Lexmark 2600 Series Lexmark Fax Solutions Lexmark Tools for Office LS_HSI Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2000 Premium Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable mIRC MixPad MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) myTaxExpress 2004 myTaxExpress 2005 myTaxExpress for Y2003 myTaxExpress NETFILE 2006 myTaxExpress NETFILE 2007 myTaxExpress NETFILE 2008 NCH Toolbox Uninstall Nero Suite neroxml Philips Device Manager Picasa 3 Print Perfect Gold QuickTime RegistryFix v7.1 Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) SUPERAntiSpyware Free Edition Uniblue DriverScanner 2009 Update for Windows Internet Explorer 8 (KB968220) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 winvi (remove only) ==== Event Viewer Messages From Past Week ======== 5/9/2009 8:57:23 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found. ==== End Of File =========================== DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 15:08:49.06 on Thu 05/14/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.101 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdnserv.exe C:\WINDOWS\system32\lxdncoms.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe -k DComLaunch C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\WINDOWS\system32\explorer.exe C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Avanquest\AutoSave\AutoSave.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Lexmark 2600 Series\lxdnmon.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Owner\Desktop\Downloads\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.mountaincable.net/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: eBay Toolbar Helper: {22d8e815-4a5e-4dfb-845e-aab64207f5bd} - c:\program files\ebay\ebay toolbar2\eBayTB.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: {5121b863-fae8-4935-ba76-0abe0239aeca} - DeskalertsBHO BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll TB: eBay Toolbar: {92085ad4-f48a-450d-bd93-b28cc7df67ce} - c:\program files\ebay\ebay toolbar2\eBayTB.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [ErrorFix] c:\program files\errorfix\ErrorFix.exe -boot mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" mRun: [IExplorer] c:\windows\system32\explorer.exe mRun: [PhilipsDM] "c:\program files\philips\philips device manager\bin\DeviceManager.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [eBayToolbar] c:\program files\ebay\ebay toolbar2\eBayTBDaemon.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AutoSave] "c:\program files\avanquest\autosave\AutoSave.exe" /Autorun mRun: [lxdnmon.exe] "c:\program files\lexmark 2600 series\lxdnmon.exe" mRun: [lxdnamon] "c:\program files\lexmark 2600 series\lxdnamon.exe" mRun: [FaxCenterServer] "c:\program files\lexmark fax solutions\fm3032.exe" /s mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE uPolicies-explorer: ForceActiveDesktopOn = 1 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: eBay Search - c:\program files\ebay\ebay toolbar2\eBayTb.dll/RCSearch.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx DPF: {CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_3_1_10-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R1 AutoSave;AutoSave;c:\windows\system32\drivers\AutoSave.sys [2008-12-13 30784] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-19 325128] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-8-28 27656] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-19 107272] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-1-15 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-1-15 55024] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-6-21 903960] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-6-19 298264] R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service –> c:\windows\system32\lxdncoms.exe -service [?] R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [2008-12-25 98984] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-1-15 7408] S2 ITGrdEngine;Guard Service; [x] S2 RDPSSW32;RDPSSW32; [x] =============== Created Last 30 ================ 2009-05-14 15:03 –d—– C:\Rooter$ 2009-05-09 20:29 –d—– c:\program files\RegistryFix7 2009-05-07 17:25 26 a——- c:\windows\Zone.Identifier 2009-05-07 17:04 120,208 a——- c:\windows\system32\GDIPFONTCACHEV1.DAT 2009-05-07 17:04 –d—– c:\docume~1\owner\applic~1\RegistryDefense 2009-05-07 17:04 –d—– c:\program files\Registry Defense 2009-05-06 10:51 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat 2009-05-06 10:50 –dsh— c:\documents and settings\owner\PrivacIE 2009-05-06 10:47 –dsh— c:\documents and settings\owner\IETldCache 2009-05-06 10:40 –d—– c:\windows\ie8updates 2009-05-06 10:39 105,984 -c—— c:\windows\system32\dllcache\iecompat.dll 2009-05-06 10:37 -cd-h— c:\windows\ie8 2009-05-06 10:10 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-05-06 10:10 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-05-06 10:10 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-05-06 10:10 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-05-06 10:10 117,760 ——– c:\windows\system32\prntvpt.dll 2009-05-06 10:10 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-05-06 10:10 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-05-06 10:10 –d—– C:\f26418351e86981feaaa21 2009-05-06 09:20 –d—– C:\drivers 2009-05-05 21:57 –d—– c:\program files\Trend Micro 2009-05-05 21:41 –d—– c:\docume~1\owner\applic~1\ErrorFix 2009-05-04 15:07 –d—– c:\program files\iPod 2009-05-04 15:07 –d—– c:\program files\iTunes 2009-05-04 15:07 –d—– c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2009-05-04 14:59 284,160 -c—— c:\windows\system32\dllcache\pdh.dll 2009-05-04 14:59 401,408 -c—— c:\windows\system32\dllcache\rpcss.dll 2009-05-04 14:59 473,600 -c—— c:\windows\system32\dllcache\fastprox.dll 2009-05-04 14:59 227,840 -c—— c:\windows\system32\dllcache\wmiprvse.exe 2009-05-04 14:59 110,592 -c—— c:\windows\system32\dllcache\services.exe 2009-05-04 14:59 729,088 -c—— c:\windows\system32\dllcache\lsasrv.dll 2009-05-04 14:59 453,120 -c—— c:\windows\system32\dllcache\wmiprvsd.dll 2009-05-04 14:59 714,752 -c—— c:\windows\system32\dllcache\ntdll.dll 2009-05-04 14:59 617,472 -c—— c:\windows\system32\dllcache\advapi32.dll 2009-05-04 14:54 1,203,922 -c—— c:\windows\system32\dllcache\sysmain.sdb 2009-05-04 14:54 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-05-04 14:54 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe ==================== Find3M ==================== 2009-05-04 14:41 1,952 a——- c:\windows\system32\winui08.dat 2009-03-09 05:19 410,984 a——- c:\windows\system32\deploytk.dll 2009-03-08 04:34 914,944 a——- c:\windows\system32\wininet.dll 2009-03-08 04:34 43,008 a——- c:\windows\system32\licmgr10.dll 2009-03-08 04:33 18,944 a——- c:\windows\system32\corpol.dll 2009-03-08 04:33 420,352 a——- c:\windows\system32\vbscript.dll 2009-03-08 04:32 72,704 a——- c:\windows\system32\admparse.dll 2009-03-08 04:32 71,680 a——- c:\windows\system32\iesetup.dll 2009-03-08 04:31 34,816 a——- c:\windows\system32\imgutil.dll 2009-03-08 04:31 48,128 a——- c:\windows\system32\mshtmler.dll 2009-03-08 04:31 45,568 a——- c:\windows\system32\mshta.exe 2009-03-08 04:22 156,160 a——- c:\windows\system32\msls31.dll 2009-03-06 10:22 284,160 a——- c:\windows\system32\pdh.dll 2009-01-26 17:03 2,085,953 a——- c:\program files\common files\InternetAntivirusPro.exe 2008-09-25 19:32 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092520080926\index.dat ============= FINISH: 15:09:29.94 ===============
Hi :)

SUPERAntiSpyware Advice:

CAUTION: SuperAntiSpyware comes with a programme called Bootsafe, do not for any reason use this programme, if used on an infected computer it could render it UNBOOTABLE.

Use of Registry Cleaners Advice:

You have one of these types of application installed, the use of which may possibly result in unanticipated and undesirable effects:

Namely: RegistryFix v7.1

I don't personally recommend the use of any registry cleaners. Here is an excerpt from a discussion on regcleaners:

Most reg cleaners aren't "bad" as such, but they aren't perfect and even the best have been known to cause problems.
The point we are trying to make is that the risk of using one far outweighs any benefit.
If it does work perfectly you will not see any difference
If it doesn't work properly you may end up with an expensive doorstop.

Source: http://forums.whatthetech.com/Regcleaner_t42862.html

My advice would be to uninstall the aforementioned application. However that is at your own discretion.

Fix Policies:

Download to your Desktop, FixPolicies.exe, a self-extracting ZIP archive from here.
  • Double-click FixPolicies.exe
  • Click the "Install" button on the bottom toolbar of the box that will open.
  • The program will create a new Folder called FixPolicies.
  • Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd.
  • A black box should briefly appear and then close.
Next:

Please download ATF Cleaner to your desktop.

  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
  • Now click on Exit.
Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please post that log in your next reply.
The log can also be found here:
  • Launch Malwarebytes' Anti-Malware
  • Click on the Logs radio tab.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

Next:

If Malwarebytes' Anti-Malware did not prompt you to Reboot(restart) your computer. Please do so now.

In the event that the ACTIVE DESKTOP RECOVERY message is still displayed, run FixPolicies again.

Then click on Restore my Active Desktop, if still no success just proceed to the below and inform myself in your next reply please, thank you.

Next:

Please download HijackThis from here.
  • Choose the default location of C:\Program Files\Trend Micro\HijackThis as the destination.
  • HJT needs to be in its own folder so that the program itself isn't deleted by accident.
  • Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Click the Install button.
  • Accept the license agreement .
  • The progam will place a shortcut on your desktop. This will make it easier for you to access the tool when required.
  • Click Do a system scan and save a log file. A Notepad file will open.
  • To post the text, first you must highlight the entire text and then press the (Ctrl+C) keys which copies it to your clipboard.
  • Now paste the log into this thread using the (Ctrl + V) buttons.
  • DO NOT use the AnalyzeThis button, its findings are dangerous if misinterpreted.
  • DO NOT have Hijackthis fix anything yet.
When completed the above, please post back the following in the order asked for:
  • How is you computer performing now? Any problems encountered and or further symptoms?
  • Malwarebytes Anti-Malware Log.
  • A HijackThis Log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:59:15 PM, on 5/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdnserv.exe
C:\WINDOWS\system32\lxdncoms.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avanquest\AutoSave\AutoSave.exe
C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mountaincable.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PhilipsDM] "C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AutoSave] "C:\Program Files\Avanquest\AutoSave\AutoSave.exe" /Autorun
O4 - HKLM\..\Run: [lxdnmon.exe] "C:\Program Files\Lexmark 2600 Series\lxdnmon.exe"
O4 - HKLM\..\Run: [lxdnamon] "C:\Program Files\Lexmark 2600 Series\lxdnamon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe
O23 - Service: lxdn_device - - C:\WINDOWS\system32\lxdncoms.exe

–
End of file - 8197 bytes
Hi :)

How is you computer performing now? Any problems encountered and or further symptoms?

I really do need to know this.

Also I would like to see the Malwarebytes Anti-Malware Log(If available) How to provide as follows:

Launch Malwarebytes' Anti-Malware
  • Click on the Logs radio tab.
  • Double click on mbam-log-yr-mm-dd
  • Post the contents in your next reply.
Disable SUPERAntiSpyware:

This is so it does not interfere with the fixing of HijackThis entries. Please make sure you carry out this task.

  • Right-click on the shortcut from the system tray
  • Choose View Control Center (preferences/options)
  • On the General and Startup tab, uncheck Start SUPERAntispyware when Windows starts.
  • Click Close to exit.
Note: Don't forget to re-enable it, when your computer is clean and I give the all clear.

Next:

Please re-open HiJackThis and select Scan. Check the boxes next to all the entries listed below (if present):

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present


Now click on Fix Checked. Close HiJackThis. Then Reboot(restart) your computer.

When completed the above, please post back the following in the order asked for:
  • How is you computer performing now? Any problems encountered and or further symptoms?
  • Malwarebytes Anti-Malware Log(If available).
  • A new HijackThis Log.
Hi :) Do you still need help with your machine? If the instructions are unclear or something isn't working, please let me know before proceeding.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI