This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Windows Firewall Turns Off

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I noticed a slowing of my computer and a pop up bubble that tells me windows firewall has been turned off each time I restart/hibernate my computer… I think this means something is wrong with my computer. I have run adaware and superspyware remover, which removed other problems but has not fixed this one. Please Help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:37:46 AM, on 6/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HPQ\IAM\bin\asghost.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\drivers\svchost.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Button Manager\BM.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe
C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe" //mailurl:mailto:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;*.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'Default user')
O4 - Startup: 80's Arcade.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Arcade.exe
O4 - Startup: Fishy.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Fishy.exe
O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Startup: Silica Calculator.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Silica Calculator.exe
O4 - Startup: Silica Calender.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Silica Calendar.exe
O4 - Startup: Silica CPU Meter.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Silica CPU meter.exe
O4 - Startup: Silica Dictionary Search.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Silica Dictionary Search.exe
O4 - Startup: Silica Drive Meter.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Silica Drive Meter.exe
O4 - Startup: Silica Memory Meter.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Silica Memory Meter.exe
O4 - Startup: Silica Search.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Silica Search.exe
O4 - Startup: Silica Volume Control.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Silica Volume Control.exe
O4 - Startup: Silica Weather.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Silica Weather.exe
O4 - Startup: Stickies.lnk = C:\Program Files\Stardock\Object Desktop\DesktopX\Widgets\Sticky Notes.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Button Manager.lnk = ?
O4 - Global Startup: LaunchU3.exe.lnk = ?
O4 - Global Startup: Magic-i.lnk = C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://0-site.ebrary.com.helin.uri.edu/lib…s/ebraryRdr.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave.com/content/dinerdash…h2.1.0.0.67.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1148585042580
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1148585593546
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVC Download Control) - http://www.shockwave.com/content/davincico…d%20Control.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MgiSvr - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 13936 bytes
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous.
  • Most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete.
  • You can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please resist the urge to run further scans or fix items on your own without my direction.



Please do the following:

STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.


Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
Here are the three logs you requested. As far as symptoms, I have a windows firewall that continues to shut itself off, and the occasional pop-up telling me that some windows file was not working, and asking me to choose to terminate or ignore… I always choose ignore, but the files are different each time. Also, a definite slow down in response time.


Thank you so much for your help!

Katie



DDS


DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 13:11:33.59 on Sun 06/07/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.140 [GMT -4:00]

AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k Cognizance
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HPQ\IAM\bin\asghost.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
"C:\WINDOWS\system32\drivers\svchost.exe"
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Button Manager\BM.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe
C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Katie\Desktop\dds.pif

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe" //mailurl:mailto:
uInternet Settings,ProxyOverride = local.,;*.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Credential Manager for ProtectTools: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\hpq\iam\bin\ItIeAddIN.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\1.2.908.5008\GoogleToolbarNotifier.exe
uRun: [Aim6]
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [SVCHOST.EXE] c:\windows\system32\drivers\svchost.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [CognizanceTS] rundll32.exe c:\progra~1\hpq\iam\bin\AsTsVcc.dll,RegisterModule
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IPHSend] c:\program files\common files\aol\iphsend\IPHSend.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
dRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\80'sar~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Arcade.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\fishy.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Fishy.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\memoni~1.lnk - c:\program files\verizon wireless\v cast music manager\MEMonitor.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Calculator.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~2.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Calendar.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\si190d~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica CPU meter.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~3.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Dictionary Search.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sic552~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Drive Meter.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sie814~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Memory Meter.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\si1a09~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Search.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sid033~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Volume Control.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~4.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Weather.exe
StartupFolder: c:\docume~1\katie\startm~1\programs\startup\stickies.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Sticky Notes.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - c:\program files\common files\autodesk shared\acstart17.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpbutt~1.lnk - c:\program files\hp\button manager\BM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\launch~1.lnk - c:\windows\installer\{d8e363a7-88b7-446d-b2c0-e26ce4dc8e54}\_2cd672ae.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\magic-i.lnk - c:\program files\arcsoft\magic-i 3\Magic-i.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send To &Bluetooth; - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://0-site.ebrary.com.helin.uri.edu/lib/rwu/support/plugins/ebraryRdr.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} - hxxp://www.shockwave.com/content/dinerdash2/sis/DinerDash2.1.0.0.67.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1148585042580
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148585593546
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} - hxxp://www.shockwave.com/content/davincicode/sis/DVC%20Download%20Control.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: OneCard - c:\program files\hpq\iam\bin\AsWlnPkg.dll
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - No File
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli AsWlnPkg

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\katie\applic~1\mozilla\firefox\profiles\5ytejixw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/index.html
FF - plugin: c:\documents and settings\katie\application data\mozilla\firefox\profiles\5ytejixw.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-7 64160]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-8-26 334984]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-8-26 53896]
R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2004-8-4 14336]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-12-21 186016]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-12-21 177824]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-5-27 1757936]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-3-7 101936]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-5-25 87936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090605.003\naveng.sys [2009-6-5 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090605.003\navex15.sys [2009-6-5 876144]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-12-21 83616]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-5-27 169200]

=============== Created Last 30 ================

2009-06-07 10:56 –d—– c:\program files\Trend Micro
2009-06-07 10:51 15,688 a——- c:\windows\system32\lsdelete.exe
2009-06-07 09:39 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-06-07 09:22 -cd-h— c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-05 22:42 56,454 a——- c:\windows\Sysvxd.exe
2009-06-05 20:09 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-06-05 20:09 –d—– c:\program files\SUPERAntiSpyware
2009-06-05 20:09 –d—– c:\docume~1\katie\applic~1\SUPERAntiSpyware.com
2009-06-05 20:08 –d—– c:\program files\common files\Wise Installation Wizard
2009-06-05 19:15 75,776 a——- c:\documents and settings\katie\nah_dixv.exe
2009-06-05 19:15 43,692 a——- c:\windows\system32\drivers\svchost.exe
2009-06-05 14:46 –d—– c:\program files\common files\DivX Shared
2009-06-05 14:46 –d—– c:\program files\DivX
2009-06-04 12:24 –d—– c:\program files\iPod
2009-06-03 23:21 –d—– c:\docume~1\katie\applic~1\OpenOffice.org
2009-06-03 22:29 –d—– c:\program files\JRE
2009-06-03 22:29 –d—– c:\program files\OpenOffice.org 3
2009-06-02 23:12 410,984 a——- c:\windows\system32\deploytk.dll
2009-06-02 23:12 73,728 a——- c:\windows\system32\javacpl.cpl
2009-05-31 15:18 –d—– c:\program files\CueCard
2009-05-26 17:18 90,112 a——- c:\windows\system32\QuickTimeVR.qtx
2009-05-26 17:18 57,344 a——- c:\windows\system32\QuickTime.qts

==================== Find3M ====================

2008-04-10 21:18 90,009 a——- c:\program files\fzuninstv6.5.6.log
2007-11-06 18:51 91,765 a——- c:\program files\setuplog.txt
2007-11-06 18:51 88,692 a——- c:\program files\fzuninstv6.5.1.log

============= FINISH: 13:12:23.98 ===============

Attach


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-05-14.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 7/19/2006 1:57:00 AM
System Uptime: 6/7/2009 11:17:38 AM (2 hours ago)

Motherboard: Hewlett-Packard | | 30A3
Processor: Genuine Intel® CPU T2600 @ 2.16GHz | U10 | 2161/166mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 93 GiB total, 12.965 GiB free.
D: is CDROM (CDFS)

==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

Ad-Aware
Ad-Aware SE Plus
Adobe Flash Player Plugin
Adobe Photoshop 7.0
Adobe Reader 7.1.0
Agere Systems HDA Modem
AIM 6
AiO_Scan
AOL Instant Messenger
Apple Mobile Device Support
Apple Software Update
ArcSoft Magic-i 3
ArcSoft PhotoStudio 5.5
ArcSoft VideoImpression 2
ArcSoft WebCam Companion 2
ATI Catalyst Control Center
ATI Display Driver
AutoCAD 2007 - English
Autodesk DirectConnect 2009 R1
Autodesk DWF Viewer
Autodesk License Manager 1.0.31
AviSynth 2.5
Bonjour
Bonjour Core for Windows
Broadcom 440x 10/100 Integrated Controller
Broadcom 802.11 Wireless LAN Adapter
Broadcom NetXtreme Ethernet Controller
Camera Access Library
Camera Support Core Library
Camera Window DS
Camera Window DVC
Camera Window MC
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window DSLR 5 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX (E)
Compatibility Pack for the 2007 Office system
CueCard (remove only)
DivX Web Player
DVD Decrypter (Remove Only)
Enterprise
Finale NotePad 2007
Fingerprint Sensor Minimum Install
formZ RenderZone Plus v6.5.1
formZ RenderZone Plus v6.5.6
Google Earth
Google SketchUp
Google SketchUp 6
HDAUDIO Soft Data Fax Modem with SmartCP
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB952287)
HP Button Manager
HP Credential Manager for ProtectTools
HP Integrated Module with Bluetooth wireless technology
HP ProtectTools Security Manager 2.00 C3
HP PSC & Officejet 4.2 Corporate Edition
HP Quick Launch Buttons 6.00 D2
HP Webcam User’s Guide
HP Wireless Assistant 2.00 E1
Intel Matrix Storage Manager
Intel® Graphics Media Accelerator Driver
InterActual Player
InterVideo DVD Check
InterVideo WinDVD
iTunes
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 13
LG USB Modem driver
LightScribe [removed]
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash Player 8
Macromedia Shockwave Player
Maple 10
Maya 2009
Maya 2009 Documentation (en_US)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MovieEdit Task
Mozilla Firefox (3.0.10)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Multiframe 11 Demo
Octoshape add-in for Adobe Flash Player
OpenOffice.org 3.1
PhotoStitch
PopCap Browser Plugin
QFolder
QuickTime
RAW Image Task 2.2
RollerCoaster Tycoon 3
Ruckus Player
Scan
Security Update for CAPICOM (KB931906)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB963027)
SimCity 2000® Special Edition
Skype™ 3.8
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic Update Manager
SoundMAX
Spybot - Search & Destroy 1.4
SUPERAntiSpyware Free Edition
Symantec AntiVirus
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
The Sims 2
The Sims 2 Family Fun Stuff
The Sims 2 Glamour Life Stuff
The Sims 2 Nightlife
The Sims 2 Open For Business
The Sims™ 2 Bon Voyage
The Sims™ 2 FreeTime
The Sims™ 2 H&M;® Fashion Stuff
The Sims™ 2 Seasons
The Sims™ 2 Teen Style Stuff
TIPCI
U3Launcher
Uninstall 1.0.0.1
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
V CAST Music Manager
VC80CRTRedist - 8.0.50727.762
Virtual Earth 3D (Beta)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (04/28/2006 1.3.1.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 10
Windows XP Service Pack 3

==== Event Viewer Messages From Past Week ========

6/2/2009 9:54:31 AM, error: SCardSvr [602] - WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.
6/2/2009 10:00:03 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

==== End Of File ===========================

GMER

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-07 16:48:18
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT 86AFD908 ZwConnectPort
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF754B87E]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA43EADC0]
SSDT 876B9DA0 ZwDuplicateObject
SSDT 86B2D9F0 ZwOpenProcess
SSDT 86B2D838 ZwOpenThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA43EB020]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0x9C4E4DF0]

—- User code sections - GMER 1.0.15 —-

? C:\WINDOWS\system32\drivers\svchost.exe[216] image checksum mismatch; number of sections mismatch; time/date stamp mismatch; unknown module: wsock32.dllunknown module: CFGMGR32.dllunknown module: CRTDLL.DLL
.text C:\WINDOWS\system32\drivers\svchost.exe[216] C:\WINDOWS\system32\drivers\svchost.exe section is writeable [0x00401000, 0x16000, 0xE0000060]
C:\WINDOWS\system32\drivers\svchost.exe[216] C:\WINDOWS\system32\drivers\svchost.exe unknown last section [0x0041B000, 0x0, 0x00000000]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@NoChange 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS@Installed 1

—- EOF - GMER 1.0.15 —-
Hi

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Thanks for your quick responses

I am enclosing the Combo Fix Log. The computer seems to be running well, but as it ahs always in the past run well I am not over confident. I am also not pushing it at all like I do during school season. After the combofix ran, both symanntic and windows firewall seem to have enabled themselves again. Not sure if that is a good sign or not.

Katie



Combofix

ComboFix 09-06-07.03 - Katie 06/07/2009 18:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.215 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Katie\nah_dixv.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\svchost.exe
c:\windows\Sysvxd.exe

.
((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.

2009-06-07 14:56 . 2009-06-07 14:56 ——– d—–w- c:\program files\Trend Micro
2009-06-07 14:51 . 2009-06-07 13:38 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-07 13:39 . 2009-06-07 13:37 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-07 13:38 . 2009-06-07 13:38 314200 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-07 13:38 . 2009-06-07 13:38 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-07 13:38 . 2009-06-07 13:38 169312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-07 13:38 . 2009-06-07 13:38 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-07 13:38 . 2009-06-07 13:38 348496 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-07 13:38 . 2009-06-07 13:38 294240 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-07 13:38 . 2009-06-07 13:38 83808 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-07 13:37 . 2009-06-07 13:37 1630048 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-07 13:37 . 2009-06-07 13:37 212848 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-07 13:37 . 2009-06-07 13:37 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-07 13:37 . 2009-06-07 13:37 40288 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-07 13:37 . 2009-06-07 13:37 640360 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-07 13:37 . 2009-06-07 13:37 540536 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-07 13:37 . 2009-06-07 13:37 559464 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-07 13:36 . 2009-06-07 13:36 2352456 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-07 13:36 . 2009-06-07 13:36 627536 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-07 13:36 . 2009-06-07 13:36 518488 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-07 13:36 . 2009-06-07 13:36 1005904 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-07 13:22 . 2009-06-07 13:22 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-07 13:22 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-07 13:22 . 2009-06-07 13:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-06 00:09 . 2009-06-07 15:21 117760 —-a-w- c:\documents and settings\Katie\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-06 00:09 . 2009-06-06 00:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-06 00:09 . 2009-06-06 00:09 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-06-06 00:09 . 2009-06-06 00:09 ——– d—–w- c:\documents and settings\Katie\Application Data\SUPERAntiSpyware.com
2009-06-06 00:08 . 2009-06-06 00:08 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-05 23:16 . 2009-06-05 23:16 10121 —-a-w- c:\documents and settings\Katie\Application Data\Autodesk\kern.dll
2009-06-05 23:16 . 2009-06-05 23:16 11410 —-a-w- c:\documents and settings\Katie\Application Data\Atari\msgdi.dll
2009-06-05 23:16 . 2009-06-05 23:16 16141 —-a-w- c:\documents and settings\Katie\Application Data\ArcSoft\lego.exe
2009-06-05 23:16 . 2009-06-05 23:16 145131 —-a-w- c:\documents and settings\Katie\Application Data\Apple Computer\nomad.exe
2009-06-05 23:16 . 2009-06-05 23:16 422 —-a-w- c:\documents and settings\Katie\Application Data\AdobeUM\socks1.exe
2009-06-05 23:16 . 2009-06-05 23:16 13221 —-a-w- c:\documents and settings\Katie\Application Data\Adobe\rengo.dll
2009-06-05 23:16 . 2009-06-05 23:16 11232 —-a-w- c:\documents and settings\Katie\Application Data\acccore\shalom.exe
2009-06-05 18:46 . 2009-06-05 18:46 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-06-05 18:46 . 2009-06-05 18:47 ——– d—–w- c:\program files\DivX
2009-06-04 16:24 . 2009-06-04 16:24 ——– d—–w- c:\program files\iPod
2009-06-04 15:45 . 2009-06-04 15:45 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-04 03:22 . 2009-06-04 03:22 1 —-a-w- c:\documents and settings\Katie\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-04 03:21 . 2009-06-04 03:21 ——– d—–w- c:\documents and settings\Katie\Application Data\OpenOffice.org
2009-06-04 02:29 . 2009-06-04 02:29 ——– d—–w- c:\program files\JRE
2009-06-04 02:29 . 2009-06-04 02:29 ——– d—–w- c:\program files\OpenOffice.org 3
2009-06-03 03:12 . 2009-06-03 03:11 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-02 18:23 . 2009-06-02 18:23 152576 —-a-w- c:\documents and settings\Katie\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-31 19:18 . 2009-05-31 19:18 ——– d—–w- c:\program files\CueCard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 22:56 . 2009-01-19 00:38 ——– d—–w- c:\documents and settings\Katie\Application Data\Skype
2009-06-07 22:32 . 2006-06-13 20:24 ——– d—–w- c:\program files\Symantec AntiVirus
2009-06-07 20:02 . 2009-01-19 00:40 ——– d—–w- c:\documents and settings\Katie\Application Data\skypePM
2009-06-07 13:22 . 2006-05-31 15:28 ——– d—–w- c:\program files\Lavasoft
2009-06-06 01:04 . 2007-08-29 14:15 ——– d—–w- c:\documents and settings\Katie\Application Data\U3
2009-06-05 23:40 . 2006-05-31 12:42 ——– d—–w- c:\program files\Google
2009-06-05 23:31 . 2008-10-12 04:05 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2009-06-05 23:29 . 2009-02-06 01:35 ——– d—–w- c:\program files\Autodesk Student Community Download Tool
2009-06-05 23:26 . 2006-05-31 13:22 141336 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-05 23:16 . 2007-05-15 21:12 ——– d—–w- c:\documents and settings\Katie\Application Data\Autodesk
2009-06-05 23:16 . 2006-08-18 02:01 ——– d—–w- c:\documents and settings\Katie\Application Data\Atari
2009-06-05 23:16 . 2006-08-01 22:29 ——– d—–w- c:\documents and settings\Katie\Application Data\ArcSoft
2009-06-05 23:16 . 2006-07-19 01:06 ——– d—–w- c:\documents and settings\Katie\Application Data\Apple Computer
2009-06-05 23:16 . 2006-08-01 18:51 ——– d—–w- c:\documents and settings\Katie\Application Data\AdobeUM
2009-06-05 23:16 . 2006-09-01 02:17 ——– d—–w- c:\documents and settings\Katie\Application Data\acccore
2009-06-04 16:25 . 2006-10-17 14:20 ——– d—–w- c:\program files\iTunes
2009-06-04 16:24 . 2007-08-03 00:55 ——– d—–w- c:\program files\Common Files\Apple
2009-06-04 16:12 . 2006-05-31 12:46 ——– d—–w- c:\program files\QuickTime
2009-06-03 03:11 . 2006-07-20 01:23 ——– d—–w- c:\program files\Java
2009-05-26 03:29 . 2007-09-04 16:19 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-05-08 23:54 . 2007-10-05 13:29 ——– d—–w- c:\documents and settings\Katie\Application Data\Move Networks
2009-04-30 22:14 . 2006-05-31 15:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-09 16:09 . 2009-04-09 16:09 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-09 12:03 . 2009-04-09 12:03 ——– d—–w- c:\program files\Multiframe 10
2009-03-21 23:21 . 2009-03-21 23:21 965344 —-a-w- c:\documents and settings\Katie\Application Data\Move Networks\MoveMediaPlayer_win_mozilla_071303000006.exe
2009-03-19 20:32 . 2009-03-19 20:32 23400 —-a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-04-11 01:18 . 2008-02-18 22:38 90009 —-a-w- c:\program files\fzuninstv6.5.6.log
2007-11-06 22:51 . 2007-11-06 22:51 91765 —-a-w- c:\program files\setuplog.txt
2007-11-06 22:51 . 2007-11-06 22:51 88692 —-a-w- c:\program files\fzuninstv6.5.1.log
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-02 131072]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-31 761946]
"CognizanceTS"="c:\progra~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 17920]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-12-21 48800]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-05-27 85744]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-03 148888]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-07 518488]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-12-12 88203]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-9-4 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-2-15 581693]
HP Button Manager.lnk - c:\program files\HP\Button Manager\BM.exe [2009-1-18 249856]
LaunchU3.exe.lnk - c:\windows\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_2cd672ae.exe [2007-8-29 1078]
Magic-i.lnk - c:\program files\ArcSoft\Magic-i 3\Magic-i.exe [2009-1-18 530944]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2005-07-25 22:41 40960 —-a-w- c:\program files\HPQ\IAM\Bin\AsWlnPkg.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli AsWlnPkg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Ruckus Player\\Ruckus.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\formZ\\formZ RenderZone Plus v6.5.1\\formZ RenderZone Plus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Katie\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Maple 10\\jre\\bin\\maple.exe"=
"c:\\Program Files\\Autodesk\\Maya2009\\bin\\maya.exe"=
"c:\\Program Files\\formZ\\formZ RenderZone Plus v6.5.6\\formZ RenderZone Plus.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/7/2009 9:39 AM 64160]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [8/4/2004 8:00 AM 14336]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys [3/7/2009 12:23 AM 101936]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [5/25/2006 3:18 PM 87936]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1005904]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [5/27/2006 4:06 PM 169200]

— Other Services/Drivers In Memory —

*NewlyCreated* - AUJASNKJ
*Deregistered* - aujasnkj

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASChannel
.
Contents of the 'Scheduled Tasks' folder

2009-06-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 13:37]

2009-06-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]

2009-05-28 c:\windows\Tasks\At2.job
- c:\progra~1\Spybot~1\spybotsd.exe [2006-05-31 19:31]

2009-05-29 c:\windows\Tasks\At3.job
- c:\progra~1\Lavasoft\Ad-Awa~1\ad-aware.exe [2006-05-31 18:23]

2009-05-22 c:\windows\Tasks\At4.job
- c:\progra~1\symantec\liveup~1\luall.exe [2006-06-13 21:32]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-IPHSend - c:\program files\Common Files\AOL\IPHSend\IPHSend.exe
SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe" //mailurl:mailto:
uInternet Settings,ProxyOverride = local.,;*.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Katie\Application Data\Mozilla\Firefox\Profiles\5ytejixw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/index.html
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Katie\Application Data\Mozilla\Firefox\Profiles\5ytejixw.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-07 18:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1060)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\HPQ\IAM\Bin\AsWlnPkg.dll
c:\program files\HPQ\IAM\Bin\ASChnl.dll
c:\program files\HPQ\IAM\Bin\ItMsg.dll

- - - - - - - > 'lsass.exe'(1116)
c:\program files\HPQ\IAM\bin\AsWlnPkg.dll
.
Completion time: 2009-06-07 19:04
ComboFix-quarantined-files.txt 2009-06-07 23:03

Pre-Run: 17,096,417,280 bytes free
Post-Run: 23,404,371,968 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

260 — E O F — 2009-06-05 23:39
Please do the following:

Please download GooredFix and save it to your Desktop.
  • Double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)


  • under the Scan section on the left:
    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.


In your next reply please include
  • GooredFix Log
  • MBAM Log
  • Kaspersky report
Hi CatByte I could not get the Kaspersky Scan to work at all, it would not open up. However, here are the other two logs Thanks, Katie Goored GooredFix v1.92 by jpshortstuff Log created at 10:04 on 08/06/2009 running Option #2 (Katie) Firefox version 3.0.10 (en-US) =====Goored Deletions===== =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions] "Plugins"="C:\Program Files\Mozilla Firefox\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions] "Components"="C:\Program Files\Mozilla Firefox\components" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" MBAM Malwarebytes' Anti-Malware 1.37 Database version: 2247 Windows 5.1.2600 Service Pack 3 6/8/2009 10:12:49 AM mbam-log-2009-06-08 (10-12-49).txt Scan type: Quick Scan Objects scanned: 98882 Time elapsed: 6 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\downloader.downloaderctrl.1 (Adware.2020search) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Program Files\Mozilla Firefox\chrome\amba.jar (Trojan.Hanam) -> Quarantined and deleted successfully.
Hi,

Please do this scan instead:

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Hi. I finally ran that scan, and have included the log with this post. I thought the computer was better, seeing as the firewall is no longer turning off. However, it needed a hard shut down last night when it completely froze, and it seems that some things requiring javascript are not working correctly, but it may have just been one thing. thanks Katie ESET ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=6.00.2900.5512 (xpsp.080413-2105) # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=1209f270b2b57245bbad3494d3af3145 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-06-09 05:28:53 # local_time=2009-06-09 01:28:53 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=3585 63 50 0 0 # scanned=173231 # found=1 # cleaned=0 # scan_time=6234 C:\Documents and Settings\Katie\My Documents\My Things\Jump Drive - Summer 2008\autorun.inf Win32/PSW.OnLineGames.NLE trojan 00000000000000000000000000000000
Hi,

Please do the following

Navidate with windows explorer (windows key + E) to the following file and delete it: (right click and select Delete)


C:\Documents and Settings\Katie\My Documents\My Things\Jump Drive - Summer 2008\autorun.inf

NEXT

Go to Start > Control Panel > Add/Remove programs:

locate the following and select REMOVE

J2SE Runtime Environment 5.0 Update 6
PopCap Browser Plugin



NEXT

Configure Java Updates

Automatic Update Feature

Click Start > Settings > Control Panel. (classic view)
Double-click Java icon. (looks like a coffee cup)
The Java Control Panel appears.
Click the Update tab.
To enable Java Update to automatically check for updates, select the Check for Updates Automatically check box.
(have it update now to install the latest version of Java - version 6 update 14)

Now, please follow these instructions to enable Java though your Web browser:

Open Internet Explorer
Click "Tools" –> "Internet Options"
Select the Advanced Tab, and scroll down to "Java (Sun)"
Check the box next to the Java version
Next, select the Security Tab, and select the "Custom Level" button
Scroll down to "Scripting of Java applets"
Make sure the "Enable" radio button is checked.
Click OK to save your preference.

see if you can now access the Kaspersky scan.

NEXT

Visit Adobe and download the latest Reader for your system (9.1), it reduces risk of vulnerabilities to have the latest version insalled.
http://get.adobe.com/reader/

NEXT

Please run a new DDS and post the resulting log
Hi So, a couple things. First, I got Kaspersky to work in IE but not in Mozilla Firefox, it is still having Java problems. Also, I could not install Adobe Reader as it has said repeatedly that it cannot access a certain registry key and it uses error code 1402. Finally, Firefox refused to open while I was setting up the Kaspersky scan in IE, and would not open until after the scan when I restarted the PC. However, here are the logs you requested. Katie Kaspersky ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Wednesday, June 10, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, June 10, 2009 03:28:40 Records in database: 2333111 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 175002 Threat name: 3 Infected objects: 3 Suspicious objects: 0 Duration of the scan: 03:29:12 File name / Threat name / Threats count C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B1C0000\4FDCD85C.VBN Infected: Trojan.Win32.Vaklik.alq 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CAC0000\4DEFC561.VBN Infected: Exploit.Win32.Pidief.aaf 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\svchost.exe.vir Infected: Trojan-Downloader.Win32.Small.aled 1 The selected area was scanned. DDS DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 8:55:45.48 on Wed 06/10/2009 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.321 [GMT -4:00] AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\System32\svchost.exe -k Cognizance C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\HPQ\IAM\bin\asghost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\HP\Button Manager\BM.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\WINDOWS\system32\msiexec.exe C:\Documents and Settings\Katie\Desktop\dds.pif ============== Pseudo HJT Report =============== uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe" //mailurl:mailto: uInternet Settings,ProxyOverride = local.,;*.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Credential Manager for ProtectTools: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\hpq\iam\bin\ItIeAddIN.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1 uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [CognizanceTS] rundll32.exe c:\progra~1\hpq\iam\bin\AsTsVcc.dll,RegisterModule mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\80'sar~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Arcade.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\fishy.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Fishy.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\memoni~1.lnk - c:\program files\verizon wireless\v cast music manager\MEMonitor.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Calculator.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~2.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Calendar.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\si190d~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica CPU meter.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~3.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Dictionary Search.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sic552~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Drive Meter.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sie814~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Memory Meter.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\si1a09~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Search.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\sid033~1.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Volume Control.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\silica~4.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Silica Weather.exe StartupFolder: c:\docume~1\katie\startm~1\programs\startup\stickies.lnk - c:\program files\stardock\object desktop\desktopx\widgets\Sticky Notes.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - c:\program files\common files\autodesk shared\acstart17.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpbutt~1.lnk - c:\program files\hp\button manager\BM.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\launch~1.lnk - c:\windows\installer\{d8e363a7-88b7-446d-b2c0-e26ce4dc8e54}\_2cd672ae.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\magic-i.lnk - c:\program files\arcsoft\magic-i 3\Magic-i.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://0-site.ebrary.com.helin.uri.edu/lib/rwu/support/plugins/ebraryRdr.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} - hxxp://www.shockwave.com/content/dinerdash2/sis/DinerDash2.1.0.0.67.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1148585042580 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148585593546 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} - hxxp://www.shockwave.com/content/davincicode/sis/DVC%20Download%20Control.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: igfxcui - igfxdev.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll Notify: OneCard - c:\program files\hpq\iam\bin\AsWlnPkg.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - No File SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL LSA: Notification Packages = scecli AsWlnPkg ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\katie\applic~1\mozilla\firefox\profiles\5ytejixw.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/index.html FF - plugin: c:\documents and settings\katie\application data\mozilla\firefox\profiles\5ytejixw.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-7 64160] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944] R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-8-26 334984] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-8-26 53896] R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2004-8-4 14336] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-12-21 186016] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-12-21 177824] R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-5-27 1757936] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-3-7 101936] R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-5-25 87936] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090605.003\naveng.sys [2009-6-5 89104] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090605.003\navex15.sys [2009-6-5 876144] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904] S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-12-21 83616] S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-5-27 169200] =============== Created Last 30 ================ 2009-06-08 23:41 –d—– c:\program files\ESET 2009-06-08 10:05 –d—– c:\docume~1\katie\applic~1\Malwarebytes 2009-06-08 10:05 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-08 10:05 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-08 10:05 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-06-08 10:05 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-06-07 18:41 a-dshr– C:\cmdcons 2009-06-07 18:36 161,792 a——- c:\windows\SWREG.exe 2009-06-07 18:36 154,624 a——- c:\windows\PEV.exe 2009-06-07 18:36 98,816 a——- c:\windows\sed.exe 2009-06-07 10:56 –d—– c:\program files\Trend Micro 2009-06-07 10:51 15,688 a——- c:\windows\system32\lsdelete.exe 2009-06-07 09:39 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-06-07 09:22 -cd-h— c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-06-05 20:09 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-06-05 20:09 –d—– c:\program files\SUPERAntiSpyware 2009-06-05 20:09 –d—– c:\docume~1\katie\applic~1\SUPERAntiSpyware.com 2009-06-05 20:08 –d—– c:\program files\common files\Wise Installation Wizard 2009-06-05 14:46 –d—– c:\program files\common files\DivX Shared 2009-06-05 14:46 –d—– c:\program files\DivX 2009-06-04 12:24 –d—– c:\program files\iPod 2009-06-03 23:21 –d—– c:\docume~1\katie\applic~1\OpenOffice.org 2009-06-03 22:29 –d—– c:\program files\JRE 2009-06-03 22:29 –d—– c:\program files\OpenOffice.org 3 2009-06-02 23:12 410,984 a——- c:\windows\system32\deploytk.dll 2009-06-02 23:12 73,728 a——- c:\windows\system32\javacpl.cpl 2009-05-31 15:18 –d—– c:\program files\CueCard 2009-05-26 17:18 90,112 a——- c:\windows\system32\QuickTimeVR.qtx 2009-05-26 17:18 57,344 a——- c:\windows\system32\QuickTime.qts ==================== Find3M ==================== 2008-04-10 21:18 90,009 a——- c:\program files\fzuninstv6.5.6.log 2007-11-06 18:51 91,765 a——- c:\program files\setuplog.txt 2007-11-06 18:51 88,692 a——- c:\program files\fzuninstv6.5.1.log ============= FINISH: 8:56:28.07 =============== Attach UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-05-14.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 7/19/2006 1:57:00 AM System Uptime: 6/10/2009 8:21:06 AM (0 hours ago) Motherboard: Hewlett-Packard | | 30A3 Processor: Genuine Intel® CPU T2600 @ 2.16GHz | U10 | 994/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 93 GiB total, 21.649 GiB free. D: is CDROM (CDFS) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1: 6/7/2009 6:36:30 PM - System Checkpoint RP2: 6/8/2009 6:39:44 PM - System Checkpoint RP3: 6/9/2009 9:36:21 PM - System Checkpoint RP4: 6/9/2009 11:00:51 PM - Removed J2SE Runtime Environment 5.0 Update 6 RP5: 6/9/2009 11:09:49 PM - Installed Java™ 6 Update 14 RP6: 6/9/2009 11:23:53 PM - Removed Adobe Reader 7.1.0 RP7: 6/9/2009 11:25:35 PM - Installed Adobe Reader 9.1. RP8: 6/9/2009 11:29:12 PM - Installed Adobe Reader 9.1. RP9: 6/10/2009 8:18:51 AM - Installed Adobe Reader 9.1. RP10: 6/10/2009 8:55:31 AM - Installed Adobe Reader 9.1. ==== Installed Programs ====================== Ad-Aware Ad-Aware SE Plus Adobe Flash Player Plugin Adobe Photoshop 7.0 Agere Systems HDA Modem AIM 6 AiO_Scan AOL Instant Messenger Apple Mobile Device Support Apple Software Update ArcSoft Magic-i 3 ArcSoft PhotoStudio 5.5 ArcSoft VideoImpression 2 ArcSoft WebCam Companion 2 ATI Catalyst Control Center ATI Display Driver AutoCAD 2007 - English Autodesk DirectConnect 2009 R1 Autodesk DWF Viewer Autodesk License Manager 1.0.31 AviSynth 2.5 Bonjour Bonjour Core for Windows Broadcom 440x 10/100 Integrated Controller Broadcom 802.11 Wireless LAN Adapter Broadcom NetXtreme Ethernet Controller Camera Access Library Camera Support Core Library Camera Window DS Camera Window DVC Camera Window MC Canon Camera Access Library Canon Camera Support Core Library Canon Camera Window DC_DV 5 for ZoomBrowser EX Canon Camera Window DC_DV 6 for ZoomBrowser EX Canon Camera Window DSLR 5 for ZoomBrowser EX Canon Camera Window MC 6 for ZoomBrowser EX Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon Utilities PhotoStitch 3.1 Canon ZoomBrowser EX (E) Compatibility Pack for the 2007 Office system CueCard (remove only) DivX Web Player DVD Decrypter (Remove Only) Enterprise ESET Online Scanner v3 Finale NotePad 2007 Fingerprint Sensor Minimum Install formZ RenderZone Plus v6.5.1 formZ RenderZone Plus v6.5.6 Google Earth Google SketchUp Google SketchUp 6 HDAUDIO Soft Data Fax Modem with SmartCP High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows XP (KB952287) HP Button Manager HP Credential Manager for ProtectTools HP Integrated Module with Bluetooth wireless technology HP ProtectTools Security Manager 2.00 C3 HP PSC & Officejet 4.2 Corporate Edition HP Quick Launch Buttons 6.00 D2 HP Webcam User’s Guide HP Wireless Assistant 2.00 E1 Intel Matrix Storage Manager Intel® Graphics Media Accelerator Driver InterActual Player InterVideo DVD Check InterVideo WinDVD iTunes Java™ 6 Update 14 LG USB Modem driver LightScribe 1.4.74.1 LiveUpdate 2.6 (Symantec Corporation) Macromedia Flash Player 8 Macromedia Shockwave Player Malwarebytes' Anti-Malware Maple 10 Maya 2009 Maya 2009 Documentation (en_US) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MovieEdit Task Mozilla Firefox (3.0.10) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) Multiframe 11 Demo Octoshape add-in for Adobe Flash Player OpenOffice.org 3.1 PhotoStitch QFolder QuickTime RAW Image Task 2.2 RollerCoaster Tycoon 3 Ruckus Player Scan Security Update for CAPICOM (KB931906) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB963027) SimCity 2000® Special Edition Skype™ 3.8 Sonic Audio Module Sonic Copy Module Sonic Data Module Sonic Express Labeler Sonic Update Manager SoundMAX Spybot - Search & Destroy 1.4 SUPERAntiSpyware Free Edition Symantec AntiVirus Synaptics Pointing Device Driver Texas Instruments PCIxx21/x515/xx12 drivers. The Sims 2 The Sims 2 Family Fun Stuff The Sims 2 Glamour Life Stuff The Sims 2 Nightlife The Sims 2 Open For Business The Sims™ 2 Bon Voyage The Sims™ 2 FreeTime The Sims™ 2 H&M® Fashion Stuff The Sims™ 2 Seasons The Sims™ 2 Teen Style Stuff TIPCI U3Launcher Uninstall 1.0.0.1 Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) V CAST Music Manager VC80CRTRedist - 8.0.50727.762 Virtual Earth 3D (Beta) Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (04/28/2006 1.3.1.0) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Media Connect Windows Media Format 11 runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 10 Windows XP Service Pack 3 ==== Event Viewer Messages From Past Week ======== 6/9/2009 4:03:00 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer KIMBERLY that believes that it is the master browser for the domain on transport NetBT_Tcpip_{5902D2E4-C309-4859-. The master browser is stopping or an election is being forced. 6/8/2009 10:15:41 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 6/8/2009 10:15:27 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde 6/7/2009 6:44:23 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 6/5/2009 9:01:22 PM, error: SCardSvr [602] - WDM Reader driver initialization cannot open reader device: The system cannot find the path specified. ==== End Of File ===========================
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

DDS::
uInternet Settings,ProxyOverride = local.,;*.local
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT

The Adobe Issue may have to do with Tea Timer. Please disable TeaTimer, your AV / Firewall and try the installation again.

To disable teatimer:
  • Run Spybot-S&D in Advanced Mode.
  • If it is not already set to do this Go to the Mode menu select "Advanced Mode"
  • On the left hand side, Click on Tools
  • Then click on the Resident Icon in the List
  • Uncheck "Resident TeaTimer" and OK any prompts.
  • Restart your computer.<–You need to do this for it to take effect
Please don't shut me down… I am still working on this… spybot search and destroy is not functioning properly on my computer, it won't start up at all. I am trying to re-install it at the moment… jsut give me a few more days, life has gotten hectic. Thanks a lot Katie
Sorry for the delay

Here is the combo fix log. Still cannot get the Acrobat installed, despite uninstalling Spybot, so if you can figure that one out that would be really fantastic as I use that on a regular basis and now cannot open PDFs. If it helps, at the bottom of this log, there are three registry values that are locked, and the third one is the one mentioned in the install error.

Thank you so much

Katie

Combofix Log

ComboFix 09-06-18.02 - Katie 06/18/2009 19:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.138 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Katie\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((( Files Created from 2009-05-18 to 2009-06-18 )))))))))))))))))))))))))))))))
.

2009-06-10 03:05 . 2009-06-10 03:05 152576 —-a-w- c:\documents and settings\Katie\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-09 03:41 . 2009-06-09 03:41 ——– d—–w- c:\program files\ESET
2009-06-08 14:05 . 2009-06-08 14:05 ——– d—–w- c:\documents and settings\Katie\Application Data\Malwarebytes
2009-06-08 14:05 . 2009-05-26 17:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-08 14:05 . 2009-06-08 14:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-08 14:05 . 2009-05-26 17:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-08 14:05 . 2009-06-08 14:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-07 14:56 . 2009-06-07 14:56 ——– d—–w- c:\program files\Trend Micro
2009-06-07 14:51 . 2009-06-07 13:38 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-07 13:39 . 2009-06-07 13:37 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-07 13:38 . 2009-06-07 13:38 314200 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-07 13:38 . 2009-06-07 13:38 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-07 13:38 . 2009-06-07 13:38 169312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-07 13:38 . 2009-06-07 13:38 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-07 13:38 . 2009-06-07 13:38 348496 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-07 13:38 . 2009-06-07 13:38 294240 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-07 13:38 . 2009-06-07 13:38 83808 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-07 13:37 . 2009-06-07 13:37 1630048 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-07 13:37 . 2009-06-07 13:37 212848 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-07 13:37 . 2009-06-07 13:37 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-07 13:37 . 2009-06-07 13:37 40288 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-07 13:37 . 2009-06-07 13:37 640360 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-07 13:37 . 2009-06-07 13:37 540536 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-07 13:37 . 2009-06-07 13:37 559464 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-07 13:36 . 2009-06-07 13:36 2352456 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-07 13:36 . 2009-06-07 13:36 627536 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-07 13:36 . 2009-06-07 13:36 518488 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-07 13:36 . 2009-06-07 13:36 1005904 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-07 13:22 . 2009-06-07 13:22 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-07 13:22 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-07 13:22 . 2009-06-07 13:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-06 00:09 . 2009-06-10 12:24 117760 —-a-w- c:\documents and settings\Katie\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-06 00:09 . 2009-06-06 00:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-06 00:09 . 2009-06-06 00:09 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-06-06 00:09 . 2009-06-06 00:09 ——– d—–w- c:\documents and settings\Katie\Application Data\SUPERAntiSpyware.com
2009-06-06 00:08 . 2009-06-06 00:08 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-05 23:16 . 2009-06-05 23:16 10121 —-a-w- c:\documents and settings\Katie\Application Data\Autodesk\kern.dll
2009-06-05 23:16 . 2009-06-05 23:16 11410 —-a-w- c:\documents and settings\Katie\Application Data\Atari\msgdi.dll
2009-06-05 23:16 . 2009-06-05 23:16 16141 —-a-w- c:\documents and settings\Katie\Application Data\ArcSoft\lego.exe
2009-06-05 23:16 . 2009-06-05 23:16 145131 —-a-w- c:\documents and settings\Katie\Application Data\Apple Computer\nomad.exe
2009-06-05 23:16 . 2009-06-05 23:16 422 —-a-w- c:\documents and settings\Katie\Application Data\AdobeUM\socks1.exe
2009-06-05 23:16 . 2009-06-05 23:16 13221 —-a-w- c:\documents and settings\Katie\Application Data\Adobe\rengo.dll
2009-06-05 23:16 . 2009-06-05 23:16 11232 —-a-w- c:\documents and settings\Katie\Application Data\acccore\shalom.exe
2009-06-05 18:46 . 2009-06-05 18:46 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-06-05 18:46 . 2009-06-05 18:47 ——– d—–w- c:\program files\DivX
2009-06-04 16:24 . 2009-06-04 16:24 ——– d—–w- c:\program files\iPod
2009-06-04 15:45 . 2009-06-04 15:45 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-04 03:22 . 2009-06-04 03:22 1 —-a-w- c:\documents and settings\Katie\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-04 03:21 . 2009-06-04 03:21 ——– d—–w- c:\documents and settings\Katie\Application Data\OpenOffice.org
2009-06-04 02:29 . 2009-06-04 02:29 ——– d—–w- c:\program files\JRE
2009-06-04 02:29 . 2009-06-04 02:29 ——– d—–w- c:\program files\OpenOffice.org 3
2009-06-03 03:12 . 2009-05-21 15:33 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-02 18:23 . 2009-06-02 18:23 152576 —-a-w- c:\documents and settings\Katie\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-31 19:18 . 2009-05-31 19:18 ——– d—–w- c:\program files\CueCard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-18 23:59 . 2009-01-19 00:38 ——– d—–w- c:\documents and settings\Katie\Application Data\Skype
2009-06-18 23:40 . 2006-06-13 20:24 ——– d—–w- c:\program files\Symantec AntiVirus
2009-06-18 20:03 . 2009-01-19 00:40 ——– d—–w- c:\documents and settings\Katie\Application Data\skypePM
2009-06-17 03:12 . 2006-05-31 12:53 ——– d—–w- c:\program files\Common Files\Adobe
2009-06-16 13:53 . 2006-05-31 15:29 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-06-15 22:17 . 2006-05-31 15:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-12 12:55 . 2007-08-29 14:15 ——– d—–w- c:\documents and settings\Katie\Application Data\U3
2009-06-10 03:10 . 2006-07-20 01:23 ——– d—–w- c:\program files\Java
2009-06-07 13:22 . 2006-05-31 15:28 ——– d—–w- c:\program files\Lavasoft
2009-06-05 23:40 . 2006-05-31 12:42 ——– d—–w- c:\program files\Google
2009-06-05 23:31 . 2008-10-12 04:05 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2009-06-05 23:29 . 2009-02-06 01:35 ——– d—–w- c:\program files\Autodesk Student Community Download Tool
2009-06-05 23:26 . 2006-05-31 13:22 141336 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-05 23:16 . 2007-05-15 21:12 ——– d—–w- c:\documents and settings\Katie\Application Data\Autodesk
2009-06-05 23:16 . 2006-08-18 02:01 ——– d—–w- c:\documents and settings\Katie\Application Data\Atari
2009-06-05 23:16 . 2006-08-01 22:29 ——– d—–w- c:\documents and settings\Katie\Application Data\ArcSoft
2009-06-05 23:16 . 2006-07-19 01:06 ——– d—–w- c:\documents and settings\Katie\Application Data\Apple Computer
2009-06-05 23:16 . 2006-08-01 18:51 ——– d—–w- c:\documents and settings\Katie\Application Data\AdobeUM
2009-06-05 23:16 . 2006-09-01 02:17 ——– d—–w- c:\documents and settings\Katie\Application Data\acccore
2009-06-04 16:25 . 2006-10-17 14:20 ——– d—–w- c:\program files\iTunes
2009-06-04 16:24 . 2007-08-03 00:55 ——– d—–w- c:\program files\Common Files\Apple
2009-06-04 16:12 . 2006-05-31 12:46 ——– d—–w- c:\program files\QuickTime
2009-05-26 03:29 . 2007-09-04 16:19 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-05-08 23:54 . 2007-10-05 13:29 ——– d—–w- c:\documents and settings\Katie\Application Data\Move Networks
2009-05-07 15:32 . 2004-08-04 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2004-08-04 12:00 666624 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-04 12:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-03-21 23:21 . 2009-03-21 23:21 965344 —-a-w- c:\documents and settings\Katie\Application Data\Move Networks\MoveMediaPlayer_win_mozilla_071303000006.exe
2008-04-11 01:18 . 2008-02-18 22:38 90009 —-a-w- c:\program files\fzuninstv6.5.6.log
2007-11-06 22:51 . 2007-11-06 22:51 91765 —-a-w- c:\program files\setuplog.txt
2007-11-06 22:51 . 2007-11-06 22:51 88692 —-a-w- c:\program files\fzuninstv6.5.1.log
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-07_22.56.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-16 13:53 . 2009-06-16 13:53 16384 c:\windows\Temp\Perflib_Perfdata_594.dat
+ 2008-01-25 15:18 . 2009-06-17 03:10 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-02-20 08:10 . 2009-04-29 04:46 81920 c:\windows\system32\dllcache\ieencode.dll
- 2009-02-20 08:10 . 2009-02-20 08:10 81920 c:\windows\system32\dllcache\ieencode.dll
- 2009-05-20 15:32 . 2009-05-20 15:32 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-06-12 07:10 . 2009-06-12 07:10 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2006-10-27 01:13 . 2006-10-27 01:13 72472 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\XL12CNVP.DLL
+ 2006-06-13 20:04 . 2009-06-12 07:06 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2004-08-04 12:00 . 2009-04-29 04:46 620032 c:\windows\system32\urlmon.dll
+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-06-10 03:11 . 2009-05-21 15:34 148888 c:\windows\system32\javaws.exe
- 2009-06-03 03:12 . 2009-06-03 03:12 148888 c:\windows\system32\javaws.exe
- 2009-06-03 03:12 . 2009-06-03 03:12 144792 c:\windows\system32\javaw.exe
+ 2009-06-10 03:11 . 2009-05-21 15:34 144792 c:\windows\system32\javaw.exe
- 2009-06-03 03:12 . 2009-06-03 03:11 144792 c:\windows\system32\java.exe
+ 2009-06-10 03:11 . 2009-05-21 15:34 144792 c:\windows\system32\java.exe
+ 2006-05-25 19:00 . 2009-06-12 07:17 462824 c:\windows\system32\FNTCACHE.DAT
- 2006-05-25 19:00 . 2009-06-04 20:01 462824 c:\windows\system32\FNTCACHE.DAT
+ 2008-04-21 06:44 . 2009-04-29 04:46 666624 c:\windows\system32\dllcache\wininet.dll
+ 2008-06-26 08:15 . 2009-04-29 04:46 620032 c:\windows\system32\dllcache\urlmon.dll
+ 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll
+ 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
- 2006-06-13 20:04 . 2009-05-20 15:33 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2006-06-13 20:04 . 2009-05-20 15:33 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2006-06-13 20:04 . 2009-06-12 07:06 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2004-08-04 12:00 . 2009-03-02 23:04 1499136 c:\windows\system32\shdocvw.dll
+ 2004-08-04 12:00 . 2009-04-29 04:46 1499136 c:\windows\system32\shdocvw.dll
+ 2004-08-04 12:00 . 2009-04-29 04:46 3068928 c:\windows\system32\mshtml.dll
+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-14 20:04 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys
+ 2008-06-26 08:15 . 2009-04-29 04:46 1499136 c:\windows\system32\dllcache\shdocvw.dll
- 2008-06-26 08:15 . 2009-03-02 23:04 1499136 c:\windows\system32\dllcache\shdocvw.dll
+ 2008-04-21 06:44 . 2009-04-29 04:46 3068928 c:\windows\system32\dllcache\mshtml.dll
+ 2006-05-25 20:26 . 2009-06-01 16:51 23635392 c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-02 131072]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-31 761946]
"CognizanceTS"="c:\progra~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 17920]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-12-21 48800]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-05-27 85744]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-07 518488]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-12-12 88203]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-9-4 113664]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-2-15 581693]
HP Button Manager.lnk - c:\program files\HP\Button Manager\BM.exe [2009-1-18 249856]
LaunchU3.exe.lnk - c:\windows\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_2cd672ae.exe [2007-8-29 1078]
Magic-i.lnk - c:\program files\ArcSoft\Magic-i 3\Magic-i.exe [2009-1-18 530944]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2005-07-25 22:41 40960 —-a-w- c:\program files\HPQ\IAM\Bin\AsWlnPkg.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli AsWlnPkg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Ruckus Player\\Ruckus.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\formZ\\formZ RenderZone Plus v6.5.1\\formZ RenderZone Plus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Katie\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Maple 10\\jre\\bin\\maple.exe"=
"c:\\Program Files\\Autodesk\\Maya2009\\bin\\maya.exe"=
"c:\\Program Files\\formZ\\formZ RenderZone Plus v6.5.6\\formZ RenderZone Plus.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/7/2009 9:39 AM 64160]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [8/4/2004 8:00 AM 14336]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys [3/7/2009 12:23 AM 101936]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [5/25/2006 3:18 PM 87936]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1005904]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [5/27/2006 4:06 PM 169200]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASChannel
.
Contents of the 'Scheduled Tasks' folder

2009-06-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 13:37]

2009-06-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]

2009-06-18 c:\windows\Tasks\At2.job
- c:\progra~1\Spybot~1\spybotsd.exe [2006-05-31 19:31]

2009-06-18 c:\windows\Tasks\At3.job
- c:\progra~1\Lavasoft\Ad-Awa~1\ad-aware.exe [2006-05-31 18:23]

2009-06-11 c:\windows\Tasks\At4.job
- c:\progra~1\symantec\liveup~1\luall.exe [2006-06-13 21:32]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe


.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe" //mailurl:mailto:
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-18 20:03
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1056)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\HPQ\IAM\Bin\AsWlnPkg.dll
c:\program files\HPQ\IAM\Bin\ASChnl.dll
c:\program files\HPQ\IAM\Bin\ItMsg.dll
c:\windows\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(1112)
c:\program files\HPQ\IAM\bin\AsWlnPkg.dll

- - - - - - - > 'explorer.exe'(460)
c:\program files\HPQ\IAM\Bin\SFSShell.dll
c:\program files\HPQ\IAM\bin\ItMsg.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-06-19 20:09
ComboFix-quarantined-files.txt 2009-06-19 00:09
ComboFix2.txt 2009-06-07 23:04

Pre-Run: 22,610,194,432 bytes free
Post-Run: 22,670,848,000 bytes free

308 — E O F — 2009-06-18 13:54

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI