This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can't even run HijackThis

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi I am not sure if this post belongs here as I am not even able to run HijackThis-thus there is no log to post. Admins feel free to move if need be. Here is my situation. I am using an Acer Aspire 7720 laptop running Vista Home premium Svpk1. Everything worked fantastic until Saturday night. The only thing I can think of is visiting a questionable torrent search site. But whatever the culprit the following is what I have been experiencing since Saturday night (6/13/09). I spent all day yesterday trying to fix it on my own. The first problem is that Personal Antivirus (PAV) got onto my laptop and I can't remove it. It seems to have taken over the laptop, with trojan notifications and (not positive this is PAV) but almost every site I try to visit now may load and if so I receive this red box stating Warning! Visiting this site may harm your computer! This web site probably contains malicious software program, which can cause damage to your computer or perform actions without your permission. Your computer may be infected after visiting such web site. We recommend you to install (or activate) antivirus security software I do realize that visiting this site can cause harm to my computer. and from that point on the page is blocked. I have tried uninstall-no good. Also since Saturday-Every google link redirects me to some shopping site of one kind or another. I discovered that if I copy/paste the actual URL into the address bar I can get to the page I wanted to go to. It is about 50/50 whether the site will be blocked or not. I am at work so I am going on memory here, but these are the programs I've loaded or tried to load: Spybot Search and Destroy Malwarebytes' Anti-Malware Hijackthis adaware pcdoctor pc pitstop Kaspersky spyhunter security suite There are problems with each and everyone of them. HijackThis took forever to even allow the software to load-saved to desktop-It gets to install to ……….and then get the Hijackthis icon-I click it -absolutely nothing happens Others are blocked, others say bad connection when trying to load others say "blank" has stopped working-windows will try and find how to resolve it. This "blank" has stopped working error also comes up constantly I have AVG as my default antivirus. It runs fine-has detected a trojan or 2, but never seems to fix the problem. spyhunter security suite seem to be the only program that will run a full scan. It shows like 18 or so infected files, registry, but won't allow a fix until you pay and register. I was ready to do that by this point, I was blocked everytime I tried to go to register. Now I think I read that spyhunter is a bogus program anyway. I failed to mention I was able to download and run EUS??? registry cleaner and fixer, but all the same problems remained. I also want to mention that just about everything I tried in regular mode, I also used in safe mode-with networking. It did seem to help a lot, but obviosly didn't fix anything. The only other thing I'll mention is that I was unable to even load most of the programs from their sites, but was able to from CNET or Downloads.com Sorry for the lengthy post, but as you all know it can be very frustrating. I am willing to try anything, so any help would be greatly appreciated Mark
Hi,

We need to be able to get you to download and run some programs,

so lets see if we can eliminate one of the problems stopping you:

First show hidden files and folders:

  • Close all programs so that you are at your desktop.
  • Open the Control Panel menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and exit My Computer.
  • Now your computer is configured to show all hidden files.

Next

Navigate to this folder and delete it:

c:\documents and settings\All Users\Start Menu\PAV


If you cannot locate it at that location (that's it;s usual installation place on most machines, but no guarantee that's where it will be on yours)

use windows explorer (windows key +E) to search for the PAV folder and delete it.

Then do the following:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.
Here yoou go.

DDS.txt

DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 17:17:09.30 on 15/06/2009
Internet Explorer: 8.0.6001.18783
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.1109 [GMT -4:00]

SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NCH Software\BroadCam\broadCam.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxczcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PSIService.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter3.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
C:\Windows\system32\taskeng.exe
C:\Users\Mark\Desktop\dds.pif
C:\Windows\system32\rundll32.exe
C:\Windows\system32\conime.exe

============== Pseudo HJT Report ===============

uStart Page = www.google.com/
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL = hxxp://ca.yahoo.com/?fr=fp-yie8
mStart Page = hxxp://en.ca.acer.yahoo.com
mDefault_Page_URL = hxxp://en.ca.acer.yahoo.com
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: &Helper: {2e59498d-7e44-4452-9044-0973b080b9e8} - c:\windows\system32\winexplorer.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {2D337EB0-3BFB-42A3-B314-A24BBA8C085B} - hxxp://download.yahoo.com/dl/mail/yautoiol1.cab
DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1217524564667&h=a7bb39296449244c01aa6065c9783ad0/&filename=jinstall-6u7-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab
DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
TCP: NameServer = 85.255.112.104,85.255.112.155
TCP: {8501B573-C9B5-4E69-9CB0-0B6A2F963A00} = 85.255.112.104,85.255.112.155
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-14 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-24 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-24 108552]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2008-2-9 12800]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-8-31 32256]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-8-31 179712]

============== File Associations ===============

regfile=NOTEPAD.EXE %1
scrfile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1

=============== Created Last 30 ================

2009-06-15 00:41 335 a——- C:\spyhunter.fix
2009-06-15 00:41 –d—– c:\program files\Enigma Software Group
2009-06-14 23:56 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 23:56 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-14 23:56 –d—– c:\programdata\Malwarebytes
2009-06-14 23:56 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-14 23:56 –d—– c:\progra~2\Malwarebytes
2009-06-14 23:24 –d—– c:\program files\Eusing Free Registry Cleaner
2009-06-14 21:47 15,688 a——- c:\windows\system32\lsdelete.exe
2009-06-14 21:40 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-06-14 21:39 -cd-h— c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 21:39 -cd-h— c:\progra~2\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 21:39 –d—– c:\program files\Lavasoft
2009-06-14 20:49 –d—– c:\users\mark\appdata\roaming\SUPERAntiSpyware.com
2009-06-14 20:49 –d—– c:\program files\SUPERAntiSpyware
2009-06-14 19:47 199,829,553 a——- c:\windows\MEMORY.DMP
2009-06-14 16:55 –d—– c:\program files\common files\Wise Installation Wizard
2009-06-14 04:34 376,320 a——- c:\windows\system32\winexplorer.dll
2009-06-14 04:33 –d—– c:\program files\common files\Uninstall
2009-06-14 04:32 –d—– c:\program files\PAV
2009-06-14 03:34 –d—– c:\program files\Trend Micro
2009-06-14 01:20 –d—– c:\programdata\PCPitstop
2009-06-14 01:20 –d—– c:\progra~2\PCPitstop
2009-06-14 01:19 –d—– c:\program files\PCPitstop
2009-06-14 01:01 –d—– c:\programdata\Lavasoft
2009-06-13 18:14 –d—– c:\program files\BHVideo
2009-06-13 17:13 –d—– c:\program files\uTorrent
2009-06-13 17:11 –d—– c:\users\mark\appdata\roaming\uTorrent
2009-06-10 02:13 2,033,152 a——- c:\windows\system32\win32k.sys
2009-06-10 02:01 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-05-27 21:59 –d—– c:\users\mark\appdata\roaming\Camfrog
2009-05-25 19:20 –d—– c:\programdata\NCH Software
2009-05-25 19:19 –d—– c:\users\mark\appdata\roaming\NCH Software
2009-05-25 19:19 –d—– c:\program files\NCH Software
2009-05-24 22:21 –d-h— C:\$AVG8.VAULT$
2009-05-24 21:25 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-05-24 21:25 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-05-24 21:25 325,896 a——- c:\windows\system32\drivers\avgldx86.sys
2009-05-24 21:25 –d—– c:\windows\system32\drivers\Avg
2009-05-24 21:25 –d—– c:\programdata\avg8
2009-05-24 21:25 –d—– c:\program files\AVG
2009-05-24 21:25 –d—– c:\progra~2\avg8
2009-05-22 16:37 –d—– c:\users\mark\appdata\roaming\ooVoo Details
2009-05-22 02:27 –d—– c:\users\mark\appdata\roaming\Acer
2009-05-18 15:07 –d—– c:\users\Mark
2009-05-16 20:11 –d—– c:\program files\Paradise8

==================== Find3M ====================

2009-05-23 22:18 5,850 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-05-09 01:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-04-23 08:42 636,928 a——- c:\windows\system32\localspl.dll
2009-03-12 21:17 143,360 a——- c:\windows\inf\infstrng.dat
2009-03-12 21:17 143,360 a——- c:\windows\inf\infstor.dat
2009-03-12 21:17 86,016 a——- c:\windows\inf\infpub.dat
2008-07-07 11:32 174 a–sh— c:\program files\desktop.ini
2008-07-02 14:32 665,600 a——- c:\windows\inf\drvindex.dat
2007-12-22 15:19 476,752 a——- c:\programdata\pswi_preloaded.exe
2007-12-22 15:19 476,752 a——- c:\progra~2\pswi_preloaded.exe
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2007-12-30 19:17 8 —shr– c:\windows\system32\58FCD56796.sys
2007-12-22 15:20 88 —shr– c:\windows\system32\6C1FC0BF72.sys

============= FINISH: 17:18:06.04 ===============


Attatch.txt

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-05-14.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 02/12/2007 3:18:03 AM
System Uptime: 15/06/2009 5:14:42 PM (0 hours ago)

Motherboard: Acer | | Poyang
Processor: Intel® Core™2 Duo CPU T5250 @ 1.50GHz | uPGA-478 | 1500/166mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 112 GiB total, 60.432 GiB free.
D: is FIXED (NTFS) - 111 GiB total, 111.343 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Tun Miniport Adapter
Device ID: ROOT\*TUNMP\0001
Manufacturer: Microsoft
Name: Teredo Tunneling Pseudo-Interface
PNP Device ID: ROOT\*TUNMP\0001
Service: tunmp

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Broadcom NetLink ™ Gigabit Ethernet
Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2
Manufacturer: Broadcom
Name: Broadcom NetLink ™ Gigabit Ethernet
PNP Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2
Service: b57nd60x

==== System Restore Points ===================


==== Installed Programs ======================

2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office system
Acer Assist
Acer Crystal Eye
Acer Crystal Eye webcam
Acer eAudio Management
Acer eDataSecurity Management
Acer eLock Management
Acer Empowering Technology
Acer eNet Management
Acer ePower Management
Acer ePresentation Management
Acer eSettings Management
Acer Mobility Center Plug-In
Acer Registration
Acer ScreenSaver
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements 6.0
Adobe Reader 8.1.2
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
ArcSoft MediaConverter 2
µTorrent
Authentium AntiVirus SDK - 2
AutoUpdate
AVG Free 8.5
BHVideo
Bonjour
BroadCam
CDDRV_Installer
Corel Paint Shop Pro Photo XI
CorelDRAW Graphics Suite X3
Debut Video Capture Software
DirectXInstallService
DivX Codec
DivX Converter
DivX Player
DivX Web Player
EMC 10 Content
eMusic Download Manager
EN
Eusing Free Registry Cleaner
FlashLynx Video Download Software
FontNav
Google Earth
Google Toolbar for Internet Explorer
HDAUDIO Soft Data Fax Modem with SmartCP
helptut
helpug
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes
Java™ 6 Update 7
KhalInstallWrapper
LightScribe 1.4.142.1
Luxor 2
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft WorldWide Telescope
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
NCH Toolbox
NTI Backup NOW! 4.7
NTI CD & DVD-Maker
ooVoo
Paradise 8
PC Pitstop Exterminate2 2.0
Photilla Photo Album Software
PowerProducer 3.72
Prism Video Converter
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio Central Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Disc Gallery
Roxio Easy Media Creator 10 Suite
Roxio File Backup
Roxio MediaShare
Roxio Update Manager
Safari
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for Microsoft Office Excel 2007 (KB969682)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Visio 2007 (KB947590)
SmartSound Quicktracks Plugin
Spelling Dictionaries Support For Adobe Reader 8
SpyHunter
SUPERAntiSpyware Free Edition
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Microsoft Office Outlook 2007 Help (KB957246)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb970012)
Update Manager
VBA
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Windows Live Mail
Windows Live Messenger
WinRAR archiver
XVID Codec Installation
Zuma Deluxe
Zuma Deluxe 1.0

==== End Of File ===========================


GMER.txt
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-15 20:18:09
Windows 6.0.6001 Service Pack 1


—- System - GMER 1.0.15 —-

Code 98397E78 ZwCreateSection
Code 983969B8 ZwDuplicateObject
Code 8DE1DAD8 ZwEnumerateKey
Code 8DCFA0E0 ZwFlushInstructionCache
Code 9838B4B8 ZwSetInformationFile
Code 9838B018 ZwSetSystemInformation
Code 9838B620 ZwWriteFile
Code 8DCF7DDD IofCallDriver
Code 8DE23996 IofCompleteRequest
Code 98397E77 NtCreateSection
Code 983969B7 NtDuplicateObject
Code 9838B4B7 NtSetInformationFile
Code 9838B61F NtWriteFile

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!IofCallDriver 82492169 5 Bytes JMP 8DCF7DE2
.text ntoskrnl.exe!IofCompleteRequest 824921D6 5 Bytes JMP 8DE2399B
PAGE ntoskrnl.exe!ZwFlushInstructionCache 825F41C2 5 Bytes JMP 8DCFA0E4
PAGE ntoskrnl.exe!ZwSetSystemInformation 8260013E 5 Bytes JMP 9838B01C
PAGE ntoskrnl.exe!ZwEnumerateKey 8261F58C 5 Bytes JMP 8DE1DADC
PAGE ntoskrnl.exe!SeCreateAccessState + 1BA2 8263D51B 7 Bytes JMP 9838BC2C
PAGE ntoskrnl.exe!NtWriteFile 82648A22 7 Bytes JMP 9838B624
PAGE ntoskrnl.exe!NtCreateSection 82655B1F 7 Bytes JMP 98397E7C
PAGE ntoskrnl.exe!FsRtlGetFileSize + 194 82660041 7 Bytes JMP 98397A74
PAGE ntoskrnl.exe!NtDuplicateObject 82667AE3 7 Bytes JMP 983969BC
PAGE ntoskrnl.exe!RtlUpcaseUnicodeChar + 58 8266D703 7 Bytes JMP 983978E4
PAGE ntoskrnl.exe!NtSetInformationFile 82674C09 5 Bytes JMP 9838B4BC
PAGE ntoskrnl.exe!FsRtlIsNameInExpression + 439 82676763 7 Bytes JMP 9838BEB4

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74907BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [749498C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7490D3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [748FF527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74907599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [748FE43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [7493B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7490D68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7490012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74900095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [748F71F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7498D802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [749275E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [748FDAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [748F668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [748F66BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74901E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\fastfat \FatCdrom Code 9838B2A8

AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \FileSystem\fastfat \Fat Code 9838B2A8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.15 —-

Service C:\Windows\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys (*** hidden *** ) [SYSTEM] MSIVXserv.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001583b7e356
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001583b7e356
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll

—- Files - GMER 1.0.15 —-

File C:\Windows\System32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys 79872 bytes executable <– ROOTKIT !!!
File C:\Windows\System32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll 26624 bytes executable
File C:\Windows\System32\MSIVXcount 4 bytes
File C:\Windows\System32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll 52224 bytes executable

—- EOF - GMER 1.0.15 —-



Thanks
Mark
Hi,

Please do the following:

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
Here you go

ComboFix 09-06-15.05 - Mark 16/06/2009 0:09.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.586 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\drv\Tuner\Yuan\Resources\_desktop.ini
c:\program files\PAV
c:\users\Mark\AppData\Local\Temp\install_flash_player.exe
c:\windows\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
c:\windows\system32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll
c:\windows\system32\winexplorer.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSIVXserv.sys


((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.

2009-06-16 04:29 . 2009-06-16 04:29 ——– d—–w- c:\users\Mark\AppData\Local\temp
2009-06-16 04:29 . 2009-06-16 04:29 ——– d—–w- c:\users\Tamara\AppData\Local\temp
2009-06-16 04:29 . 2009-06-16 04:29 ——– d—–w- c:\users\Guest\AppData\Local\temp
2009-06-15 04:41 . 2009-06-15 22:25 ——– d—–w- c:\program files\Enigma Software Group
2009-06-15 03:56 . 2009-05-26 17:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 03:56 . 2009-06-15 05:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 03:56 . 2009-06-15 03:56 ——– d—–w- c:\programdata\Malwarebytes
2009-06-15 03:56 . 2009-05-26 17:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 03:24 . 2009-06-15 03:24 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2009-06-15 01:47 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-15 01:47 . 2009-06-15 01:47 121348 —-a-w- c:\programdata\Lavasoft\Ad-Aware\ThreatWork\Submit\psdutil.dll
2009-06-15 01:40 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-15 01:40 . 2009-03-12 08:17 2902048 -c–a-w- c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-15 01:39 . 2009-06-15 01:40 ——– dc-h–w- c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-15 01:39 . 2009-06-15 01:39 ——– d—–w- c:\program files\Lavasoft
2009-06-15 00:49 . 2009-06-15 03:44 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-06-15 00:49 . 2009-06-15 00:49 ——– d—–w- c:\users\Mark\AppData\Roaming\SUPERAntiSpyware.com
2009-06-14 20:55 . 2009-06-14 20:55 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-14 08:33 . 2009-06-14 08:33 ——– d—–w- c:\program files\Common Files\Uninstall
2009-06-14 07:34 . 2009-06-14 07:34 ——– d—–w- c:\program files\Trend Micro
2009-06-14 05:20 . 2009-06-15 05:52 ——– d—–w- c:\programdata\PCPitstop
2009-06-14 05:19 . 2009-06-15 05:51 ——– d—–w- c:\program files\PCPitstop
2009-06-14 05:01 . 2009-06-15 01:39 ——– d—–w- c:\programdata\Lavasoft
2009-06-13 22:14 . 2009-06-13 22:14 ——– d—–w- c:\program files\BHVideo
2009-06-13 21:13 . 2009-06-13 21:13 ——– d—–w- c:\program files\uTorrent
2009-06-13 21:11 . 2009-06-14 00:11 ——– d—–w- c:\users\Mark\AppData\Roaming\uTorrent
2009-06-13 15:44 . 2009-06-13 15:44 ——– d—–w- c:\users\Guest\AppData\Roaming\NCH Software
2009-06-13 15:04 . 2009-06-13 15:04 ——– d—–w- c:\users\Guest\AppData\Local\Google
2009-06-12 21:02 . 2009-06-12 21:02 456304 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb7F1F.tmp.exe
2009-06-10 06:13 . 2009-04-21 11:55 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-06-10 06:03 . 2009-04-23 12:42 636928 —-a-w- c:\windows\system32\localspl.dll
2009-06-10 06:03 . 2009-05-09 05:50 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-10 06:03 . 2009-05-09 05:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-06-10 06:01 . 2009-04-23 12:43 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-06-06 01:10 . 2009-06-14 22:01 1356 —-a-w- c:\users\Mark\AppData\Local\d3d9caps.dat
2009-06-05 17:35 . 2009-06-05 17:35 ——– d—–w- c:\users\Mark\AppData\Roaming\Roxio
2009-06-01 04:44 . 2009-06-01 04:44 ——– d—–w- c:\users\Mark\AppData\Local\Microsoft Games
2009-05-28 01:59 . 2009-06-13 18:56 ——– d—–w- c:\users\Mark\AppData\Roaming\Camfrog
2009-05-27 04:45 . 2009-05-28 01:22 ——– d—–w- c:\users\Mark\AppData\Local\Yahoo
2009-05-25 23:20 . 2009-06-12 21:28 ——– d—–w- c:\programdata\NCH Software
2009-05-25 23:19 . 2009-06-12 21:27 ——– d—–w- c:\program files\NCH Software
2009-05-25 23:19 . 2009-06-05 17:01 ——– d—–w- c:\users\Mark\AppData\Roaming\NCH Software
2009-05-25 17:50 . 2009-05-25 17:50 ——– d—–w- c:\users\Mark\AppData\Local\Deployment
2009-05-25 17:50 . 2009-05-25 17:50 ——– d—–w- c:\users\Mark\AppData\Local\Apps
2009-05-25 02:21 . 2009-06-15 02:34 ——– d–h–w- C:\$AVG8.VAULT$
2009-05-25 01:25 . 2009-05-25 01:25 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-25 01:25 . 2009-05-25 01:25 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-25 01:25 . 2009-05-25 01:25 325896 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-25 01:25 . 2009-06-15 21:49 ——– d—–w- c:\windows\system32\drivers\Avg
2009-05-25 01:25 . 2009-05-25 01:25 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-25 01:25 . 2009-06-14 17:53 ——– d—–w- c:\programdata\avg8
2009-05-25 01:25 . 2009-05-25 01:25 ——– d—–w- c:\program files\AVG
2009-05-24 02:18 . 2009-05-24 02:19 ——– d—–w- c:\users\Mark\AppData\Roaming\Corel
2009-05-22 20:37 . 2009-05-22 20:37 ——– d—–w- c:\users\Mark\AppData\Roaming\ooVoo Details
2009-05-22 06:27 . 2009-05-22 06:27 ——– d—–w- c:\users\Mark\AppData\Roaming\Acer
2009-05-22 05:36 . 2009-05-22 05:36 93248 —-a-w- c:\users\Mark\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-21 03:32 . 2009-06-15 20:57 ——– d—–w- c:\users\Mark\AppData\Local\Adobe
2009-05-20 03:13 . 2009-05-20 03:13 ——– d—–w- c:\users\Mark\AppData\Local\Apple
2009-05-18 19:09 . 2009-05-18 19:09 ——– d—–w- c:\users\Mark\AppData\Roaming\Yahoo!
2009-05-18 19:09 . 2009-06-13 17:05 ——– d—–w- c:\users\Mark\AppData\Local\Google
2009-05-17 05:51 . 2009-05-17 05:51 ——– d—–w- c:\users\Tamara\AppData\Roaming\ooVoo Details

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 04:06 . 2008-05-31 17:29 12 —-a-w- c:\windows\bthservsdp.dat
2009-06-10 07:05 . 2007-12-29 22:34 ——– d—–w- c:\programdata\Microsoft Help
2009-06-05 17:50 . 2008-06-16 20:27 ——– d—–w- c:\program files\Roxio
2009-06-05 16:31 . 2008-05-10 20:31 ——– d—–w- c:\programdata\NCH Swift Sound
2009-06-05 16:31 . 2008-05-10 20:30 ——– d—–w- c:\program files\NCH Swift Sound
2009-05-28 01:26 . 2007-12-02 17:47 ——– d—–w- c:\program files\Yahoo!
2009-05-28 01:24 . 2009-03-06 18:19 ——– d—–w- c:\programdata\Yahoo!
2009-05-24 02:18 . 2007-12-22 19:20 5850 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-17 00:22 . 2009-05-17 00:11 ——– d—–w- c:\program files\Paradise8
2009-05-15 21:43 . 2009-05-09 21:17 680 —-a-w- c:\users\Tamara\AppData\Local\d3d9caps.dat
2009-05-15 21:41 . 2009-05-03 22:15 93248 —-a-w- c:\users\Tamara\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-15 13:26 . 2007-12-02 16:33 ——– d—–w- c:\program files\Windows Live
2009-05-15 13:14 . 2007-12-02 16:40 ——– d—–w- c:\program files\Windows Live Toolbar
2009-05-15 13:10 . 2007-08-31 05:59 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-14 13:13 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-13 16:43 . 2009-05-13 16:43 ——– d—–w- c:\program files\Common Files\Windows Live
2009-05-10 23:13 . 2008-02-09 16:37 ——– d—–w- c:\programdata\iolo
2009-05-06 23:20 . 2009-05-03 22:58 ——– d—–w- c:\program files\Planet7 Casino
2009-05-06 23:20 . 2009-05-03 23:23 ——– d—–w- c:\program files\Silver Oak Casino
2009-05-06 23:17 . 2009-05-06 23:17 ——– d—–w- c:\users\Tamara\AppData\Roaming\DivX
2009-05-03 22:59 . 2009-05-03 22:15 ——– d—–w- c:\users\Tamara\AppData\Roaming\iolo
2009-05-03 22:20 . 2009-05-03 22:20 ——– d—–w- c:\users\Tamara\AppData\Roaming\Yahoo!
2009-05-03 22:15 . 2009-05-03 22:15 ——– d—–w- c:\users\Tamara\AppData\Roaming\Leadertech
2009-05-03 22:15 . 2009-05-03 22:15 ——– d—–w- c:\users\Tamara\AppData\Roaming\Roxio
2007-12-30 23:17 . 2007-12-30 23:17 8 –sh–r- c:\windows\System32\58FCD56796.sys
2007-12-22 19:20 . 2007-12-22 19:20 88 –sh–r- c:\windows\System32\6C1FC0BF72.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-04 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{5F51E54C-1883-4E02-8952-66B3F119A062}"= UDP:c:\windows\System32\lxczcoms.exe:Lexmark Communications System
"{22018E50-F1AC-4262-B5DA-8D3A721A5A5A}"= TCP:c:\windows\System32\lxczcoms.exe:Lexmark Communications System
"{6B10E6D6-ECC9-4881-BFCC-E8B9E9448C82}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{638E84D0-5F23-4AC4-AFA4-D38FD8462BEF}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{FC8C58D3-7AFD-456A-AA57-C10B494EC600}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A341D81B-4574-4841-9FA4-5DC8D7FA3DA4}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{5E0BD40D-C918-4DFE-913C-CA2D27F72F59}"= UDP:c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
"{C4CA3A20-EB69-4789-8B5C-40904F97AADE}"= TCP:c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
"{39D2F4A6-2483-43F1-B517-09F4519F418A}"= UDP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus®
"{72EA8900-5A0C-4EB0-B45B-2CC805431804}"= TCP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus®
"{BDDA12AD-3C55-4105-8CF0-DF68FFA32B30}"= UDP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe:iolo AntiVirus® Email Protection
"{A576B66D-C2DE-46E6-9713-226934565BA2}"= TCP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe:iolo AntiVirus® Email Protection
"{1587DF41-847B-4B0D-B94D-13CC5A9AA97A}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{C391511B-7C8A-4B03-9360-FB9E6E9A43D5}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{8C7262D4-96DE-4EA7-872E-3889C3F80081}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{53E6180E-A55E-49DE-8C3D-2114C0F61705}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{BD48FC19-009E-4343-9B40-0258423D584C}"= TCP:2799:Altova License Metering Port (UDP)
"{FD3A5CD1-07E9-4B92-ABDF-BE28656953F5}"= UDP:2799:Altova License Metering Port (TCP)
"{A3EA3C91-088C-4730-9ACF-C54470AD7CC6}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FCF40573-826A-40CB-AD38-B2A60AF1EBD7}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{8B19B348-B662-49AA-BA58-74DE76C69912}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9012AEF3-0363-46B7-A596-D38F73CC8A39}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7B3029E2-32FC-4170-836C-62FB9524AC0F}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{AC81E57B-534C-4A1F-BA3E-FBF89C3AAF2A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{7F9FDA0F-0FF2-4109-A331-F4461401E9A6}c:\\program files\\oovoo\\oovoo.exe"= UDP:c:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{ACB06F30-44FA-4500-A752-077B5816623A}c:\\program files\\oovoo\\oovoo.exe"= TCP:c:\program files\oovoo\oovoo.exe:ooVoo
"{B82A096E-A5A3-4463-98F6-9C44ED1893A7}"= Disabled:UDP:443:ooVoo TCP port 443
"{A35FE2BF-1B8B-4114-92D8-CB8A73F5CF1C}"= Disabled:TCP:443:ooVoo UDP port 443
"{F4DE7FBA-7F54-49DE-B71B-3343A7308FB4}"= Disabled:UDP:37674:ooVoo TCP port 37674
"{EF73B2EF-101E-499C-8BC2-DF38819BB8CC}"= Disabled:TCP:37674:ooVoo UDP port 37674
"{F7AFE01C-D1AD-47BC-8D54-8102158C513C}"= Disabled:TCP:37675:ooVoo UDP port 37675
"TCP Query User{4F534D5A-C7D6-4750-9AE2-710505B220F5}c:\\program files\\oovoo\\oovoo.exe"= UDP:c:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{0D218826-5A75-44F5-BFDE-626D62764C4A}c:\\program files\\oovoo\\oovoo.exe"= TCP:c:\program files\oovoo\oovoo.exe:ooVoo
"{BCED55B6-2975-4EA6-8971-35DAE2953A28}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{1C6AAB50-ADB7-4F12-884D-631328010F45}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{373EB1B1-952C-4E42-B595-8000E9C2A01C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{D606E421-D8CE-4450-8ECB-3D48FE65E1FA}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{D3EF95AA-CCF2-477F-BE57-9C1F42C931AF}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{F7A4D666-A976-4C51-A6C3-465EF79B9475}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{69BEB895-8B5D-46ED-8A46-C94A5AA505C3}"= UDP:86:BroadCam Web Server
"{A962B5B6-6B92-4635-9511-95591D79805C}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{18810E61-73D1-4D6F-8D13-DC82DA6B1D38}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C38A14C4-6E0E-4443-BDA7-65B36C5BEEC4}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{728CDABC-5F8E-42B6-84D6-A8D2D0B1114C}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= c:\acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= c:\acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= c:\acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [14/06/2009 9:40 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [24/05/2009 9:25 PM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [24/05/2009 9:25 PM 108552]
R1 ElRawDisk;ElRawDisk;c:\windows\System32\drivers\elrawdsk.sys [09/02/2008 12:49 PM 12800]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [02/10/2007 3:46 PM 124832]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [24/05/2009 9:25 PM 298776]
R2 BroadCamService;BroadCam Service;c:\program files\NCH Software\BroadCam\broadCam.exe [25/05/2009 7:20 PM 368644]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 3:06 PM 951632]
R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [24/08/2007 4:52 PM 166384]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [31/08/2007 1:11 AM 32256]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [24/08/2007 4:52 PM 1083888]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [24/08/2007 4:53 PM 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [24/08/2007 4:52 PM 309744]
S2 SessionLauncher;SessionLauncher; [x]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [31/08/2007 1:11 AM 179712]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [24/08/2007 4:53 PM 72176]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [15/06/2009 1:51 AM 77312]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{2F813C91-EA31-42E0-8FCE-06CD7310A732}.job
- c:\windows\system32\msfeedssync.exe [2009-04-04 11:31]

2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{539DC73A-5177-4DF4-8A08-C6FCCCA86A3E}.job
- c:\windows\system32\msfeedssync.exe [2009-04-04 11:31]

2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{F52471F2-32F4-49AB-B265-602BD793045F}.job
- c:\windows\system32\msfeedssync.exe [2009-04-04 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.com/
mStart Page = hxxp://en.ca.acer.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
.
.
——- File Associations ——-
.
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 00:29
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-16 0:30
ComboFix-quarantined-files.txt 2009-06-16 04:30

Pre-Run: 64,783,515,648 bytes free
Post-Run: 71,225,159,680 bytes free

282 — E O F — 2009-06-13 05:50
Hi,

You are showing you have AVG on your system as well as Iolo AV, please advise the status of both these AV's..did you attempt to uninstall AVG?

Please do the following

  • Open your Malware Bytes AntiMalware programe
  • Select the updates tab, and allow the program to update
  • run a quick scan on your system
  • Allow the program to remove any detected items
  • post the resulting log.
NEXT

It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course:

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hi CatByte On your 1st question - I'm not even sure what a lolo-AV is, so I don't think I ever downloaded it. I couldn't find it on search. I do have AVG. I donn't think I've tried to uninstall it. I did fiddle with it a bit when you asked that I not have 2 virus apllications running at the same time. I hope that helps. I am posting 2 Maleware bytes logs-one before deleting the 6 infections and one after. Malwarebytes' Anti-Malware 1.37 Database version: 2290 Windows 6.0.6001 Service Pack 1 16/06/2009 7:35:08 PM mbam-log-2009-06-16 (19-34-57).txt Scan type: Quick Scan Objects scanned: 100877 Time elapsed: 4 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BHVideo (Trojan.DNSChanger) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\BHVideo (Trojan.DNSChanger) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BHVideo (Trojan.DNSChanger) -> No action taken. C:\Program Files\BHVideo (Trojan.DNSChanger) -> No action taken. Files Infected: c:\Users\Mark\AppData\Roaming\microsoft\Windows\start menu\Programs\BHVideo\Uninstall.lnk (Trojan.DNSChanger) -> No action taken. c:\program files\BHVideo\Uninstall.exe (Trojan.DNSChanger) -> No action taken. Malwarebytes' Anti-Malware 1.37 Database version: 2290 Windows 6.0.6001 Service Pack 1 16/06/2009 7:35:14 PM mbam-log-2009-06-16 (19-35-14).txt Scan type: Quick Scan Objects scanned: 100877 Time elapsed: 4 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Program Files\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: c:\Users\Mark\AppData\Roaming\microsoft\Windows\start menu\Programs\BHVideo\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully. c:\program files\BHVideo\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully. I can't believe it-I know I save the Kasper log to my desktop-but I can't find it anywhere. carp**-that took a long time-I guess I will do it again tonight. Thanks Mark
Hi CatByte I'll try this again On your 1st question - I'm not even sure what a lolo-AV is, so I don't think I ever downloaded it. I couldn't find it on search. I do have AVG. I donn't think I've tried to uninstall it. I did fiddle with it a bit when you asked that I not have 2 virus apllications running at the same time. I hope that helps. I am posting 2 Maleware bytes logs-one before deleting the 6 infections and one after. Malwarebytes' Anti-Malware 1.37 Database version: 2290 Windows 6.0.6001 Service Pack 1 16/06/2009 7:35:08 PM mbam-log-2009-06-16 (19-34-57).txt Scan type: Quick Scan Objects scanned: 100877 Time elapsed: 4 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BHVideo (Trojan.DNSChanger) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\BHVideo (Trojan.DNSChanger) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BHVideo (Trojan.DNSChanger) -> No action taken. C:\Program Files\BHVideo (Trojan.DNSChanger) -> No action taken. Files Infected: c:\Users\Mark\AppData\Roaming\microsoft\Windows\start menu\Programs\BHVideo\Uninstall.lnk (Trojan.DNSChanger) -> No action taken. c:\program files\BHVideo\Uninstall.exe (Trojan.DNSChanger) -> No action taken. Malwarebytes' Anti-Malware 1.37 Database version: 2290 Windows 6.0.6001 Service Pack 1 16/06/2009 7:35:14 PM mbam-log-2009-06-16 (19-35-14).txt Scan type: Quick Scan Objects scanned: 100877 Time elapsed: 4 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Program Files\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: c:\Users\Mark\AppData\Roaming\microsoft\Windows\start menu\Programs\BHVideo\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully. c:\program files\BHVideo\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully. Kaspersky log ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Wednesday, June 17, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Thursday, June 18, 2009 02:37:50 Records in database: 2359259 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 127588 Threat name: 2 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 02:01:38 File name / Threat name / Threats count C:\Qoobox\Quarantine\C\Windows\System32\drivers\_MSIVXqkpafndmvxgwwietautbpprvympfvotv_.sys.zip Infected: Trojan.Win32.Tdss.ahpu 1 C:\Qoobox\Quarantine\C\Windows\System32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll.vir Infected: Trojan.Win32.Agent.clxm 1 The selected area was scanned.
Hi,

This was the program I was referring to:

c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus®


Anyway,

The file found by Kaspersky is already in quarantine, so cannot harm the computer.

NEXT


Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 14)


NEXT


Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT


Please run a fresh DDS log so I can make sure you are clean, then we can begin our final clean up.

Also please asbise how your computer is running now and if there are any outstanding issues.
Hi Is there any arm in having both QUOTE c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall® c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus® ? or do I need to delete one? I updated Java & Adobe Here are my DDS logs DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 15:43:40.16 on 18/06/2009 Internet Explorer: 8.0.6001.18783 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.859 [GMT -4:00] SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\NCH Software\BroadCam\broadCam.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe C:\Acer\Empowering Technology\eNet\eNet Service.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\lxczcoms.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Acer\Mobility Center\MobilityService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\PSIService.exe C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\DRIVERS\xaudio.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe C:\Acer\Empowering Technology\ePower\ePowerSvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\system32\conime.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\msiexec.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Mark\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = www.google.com/ mStart Page = hxxp://en.ca.acer.yahoo.com BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572 \swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} DPF: {2D337EB0-3BFB-42A3-B314-A24BBA8C085B} - hxxp://download.yahoo.com/dl/mail/yautoiol1.cab DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\windows\system32\avgrsstx.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-17 64160] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-24 325896] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-24 108552] R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2008-2-9 12800] R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\adobe\photoshop elements 6.0\PhotoshopElementsFileAgent.exe [2007 -10-2 124832] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-24 298776] R2 BroadCamService;BroadCam Service;c:\program files\nch software\broadcam\broadCam.exe [2009-5-25 368644] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1003344] R2 lxcz_device;lxcz_device;c:\windows\system32\lxczcoms.exe -service –> c:\windows\system32\lxczcoms.exe -service [?] R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatch10.exe [2007-8-24 166384] R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-8-31 32256] R3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2007-8-24 1083888] S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2007-8-24 362992] S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxLiveShare10.exe [2007-8-24 309744] S2 SessionLauncher;SessionLauncher; [x] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-8-31 179712] S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe [2007-8-24 72176] S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2009-6-15 77312] ============== File Associations =============== VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-06-18 14:36 410,984 a——- c:\windows\system32\deploytk.dll 2009-06-18 13:42 –d—– c:\users\mark\JavaRa 2009-06-18 13:41 –d—– c:\users\mark\New Folder 2009-06-18 01:20 –d—– c:\program files\Camfrog 2009-06-17 23:56 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-06-16 01:15 428,544 a——- c:\windows\system32\EncDec.dll 2009-06-16 01:15 293,376 a——- c:\windows\system32\psisdecd.dll 2009-06-16 01:15 217,088 a——- c:\windows\system32\psisrndr.ax 2009-06-16 01:15 177,664 a——- c:\windows\system32\mpg2splt.ax 2009-06-16 01:15 80,896 a——- c:\windows\system32\MSNP.ax 2009-06-16 00:58 –d—– c:\users\mark\appdata\roaming\Malwarebytes 2009-06-16 00:30 –dsh— C:\$RECYCLE.BIN 2009-06-15 23:50 161,792 a——- c:\windows\SWREG.exe 2009-06-15 23:50 155,136 a——- c:\windows\PEV.exe 2009-06-15 23:50 98,816 a——- c:\windows\sed.exe 2009-06-15 23:50 –ds—- C:\Combo-Fix 2009-06-15 00:41 335 a——- C:\spyhunter.fix 2009-06-15 00:41 –d—– c:\program files\Enigma Software Group 2009-06-14 23:56 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-14 23:56 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-14 23:56 –d—– c:\programdata\Malwarebytes 2009-06-14 23:56 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-06-14 23:56 –d—– c:\progra~2\Malwarebytes 2009-06-14 23:24 –d—– c:\program files\Eusing Free Registry Cleaner 2009-06-14 21:47 15,688 a——- c:\windows\system32\lsdelete.exe 2009-06-14 21:39 -cd-h— c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-06-14 21:39 -cd-h— c:\progra~2\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-06-14 21:39 –d—– c:\program files\Lavasoft 2009-06-14 20:49 –d—– c:\users\mark\appdata\roaming\SUPERAntiSpyware.com 2009-06-14 20:49 –d—– c:\program files\SUPERAntiSpyware 2009-06-14 19:47 199,829,553 a——- c:\windows\MEMORY.DMP 2009-06-14 16:55 –d—– c:\program files\common files\Wise Installation Wizard 2009-06-14 04:33 –d—– c:\program files\common files\Uninstall 2009-06-14 03:34 –d—– c:\program files\Trend Micro 2009-06-14 01:20 –d—– c:\programdata\PCPitstop 2009-06-14 01:20 –d—– c:\progra~2\PCPitstop 2009-06-14 01:19 –d—– c:\program files\PCPitstop 2009-06-14 01:01 –d—– c:\programdata\Lavasoft 2009-06-13 17:13 –d—– c:\program files\uTorrent 2009-06-13 17:11 –d—– c:\users\mark\appdata\roaming\uTorrent 2009-06-10 02:13 2,033,152 a——- c:\windows\system32\win32k.sys 2009-06-10 02:01 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-05-27 21:59 –d—– c:\users\mark\appdata\roaming\Camfrog 2009-05-25 19:20 –d—– c:\programdata\NCH Software 2009-05-25 19:19 –d—– c:\users\mark\appdata\roaming\NCH Software 2009-05-25 19:19 –d—– c:\program files\NCH Software 2009-05-24 22:21 –d-h— C:\$AVG8.VAULT$ 2009-05-24 21:25 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-05-24 21:25 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-05-24 21:25 325,896 a——- c:\windows\system32\drivers\avgldx86.sys 2009-05-24 21:25 –d—– c:\windows\system32\drivers\Avg 2009-05-24 21:25 –d—– c:\programdata\avg8 2009-05-24 21:25 –d—– c:\program files\AVG 2009-05-24 21:25 –d—– c:\progra~2\avg8 2009-05-22 16:37 –d—– c:\users\mark\appdata\roaming\ooVoo Details 2009-05-22 02:27 –d—– c:\users\mark\appdata\roaming\Acer ==================== Find3M ==================== 2009-05-23 22:18 5,850 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-05-09 01:50 915,456 a——- c:\windows\system32\wininet.dll 2009-05-09 01:34 71,680 a——- c:\windows\system32\iesetup.dll 2009-04-23 08:42 636,928 a——- c:\windows\system32\localspl.dll 2009-03-12 21:17 143,360 a——- c:\windows\inf\infstrng.dat 2009-03-12 21:17 143,360 a——- c:\windows\inf\infstor.dat 2009-03-12 21:17 86,016 a——- c:\windows\inf\infpub.dat 2008-07-07 11:32 174 a–sh— c:\program files\desktop.ini 2008-07-02 14:32 665,600 a——- c:\windows\inf\drvindex.dat 2007-12-22 15:19 476,752 a——- c:\programdata\pswi_preloaded.exe 2007-12-22 15:19 476,752 a——- c:\progra~2\pswi_preloaded.exe 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2007-12-30 19:17 8 —shr– c:\windows\system32\58FCD56796.sys 2007-12-22 15:20 88 —shr– c:\windows\system32\6C1FC0BF72.sys ============= FINISH: 15:44:21.25 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-05-14.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 02/12/2007 3:18:03 AM System Uptime: 18/06/2009 1:18:38 PM (2 hours ago) Motherboard: Acer | | Poyang Processor: Intel® Core™2 Duo CPU T5250 @ 1.50GHz | uPGA-478 | 1500/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 112 GiB total, 65.334 GiB free. D: is FIXED (NTFS) - 111 GiB total, 111.343 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Microsoft Tun Miniport Adapter Device ID: ROOT\*TUNMP\0001 Manufacturer: Microsoft Name: Teredo Tunneling Pseudo-Interface PNP Device ID: ROOT\*TUNMP\0001 Service: tunmp Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Broadcom NetLink ™ Gigabit Ethernet Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2 Manufacturer: Broadcom Name: Broadcom NetLink ™ Gigabit Ethernet PNP Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2 Service: b57nd60x Class GUID: Description: Device ID: ROOT\LEGACY_BEEP\XX_LONNYRJONES_XX Manufacturer: Name: PNP Device ID: ROOT\LEGACY_BEEP\XX_LONNYRJONES_XX Service: MSIVXserv.sys ==== System Restore Points =================== RP618: 10/06/2009 3:00:17 AM - Windows Update RP619: 13/06/2009 1:50:05 AM - Windows Update RP620: 14/06/2009 3:00:34 AM - Restore Operation RP621: 14/06/2009 3:06:15 AM - Restore Operation RP622: 14/06/2009 9:52:17 AM - Restore Operation RP630: 16/06/2009 1:32:46 AM - Windows Update RP631: 16/06/2009 7:24:21 PM - Windows Update RP632: 17/06/2009 3:00:12 AM - Windows Update RP633: 18/06/2009 2:19:38 PM - Scheduled Checkpoint RP634: 18/06/2009 2:35:39 PM - Installed Java™ 6 Update 14 RP635: 18/06/2009 2:56:14 PM - Windows Update RP636: 18/06/2009 2:57:19 PM - Installed Adobe Reader 9.1. ==== Installed Programs ====================== 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office system Acer Assist Acer Crystal Eye Acer Crystal Eye webcam Acer eAudio Management Acer eDataSecurity Management Acer eLock Management Acer Empowering Technology Acer eNet Management Acer ePower Management Acer ePresentation Management Acer eSettings Management Acer Mobility Center Plug-In Acer Registration Acer ScreenSaver Ad-Aware Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Photoshop Elements 6.0 Adobe Reader 9.1.2 ALPS Touch Pad Driver Apple Mobile Device Support Apple Software Update ArcSoft MediaConverter 2 µTorrent Authentium AntiVirus SDK - 2 AutoUpdate AVG Free 8.5 Bonjour BroadCam Camfrog Video Chat 5.3 CDDRV_Installer Corel Paint Shop Pro Photo XI CorelDRAW Graphics Suite X3 Debut Video Capture Software DirectXInstallService DivX Codec DivX Converter DivX Player DivX Web Player EMC 10 Content eMusic Download Manager EN Eusing Free Registry Cleaner FlashLynx Video Download Software FontNav Google Earth Google Toolbar for Internet Explorer HDAUDIO Soft Data Fax Modem with SmartCP helptut helpug Intel® Graphics Media Accelerator Driver Intel® Matrix Storage Manager iTunes Java™ 6 Update 14 Java™ 6 Update 7 KhalInstallWrapper LightScribe 1.4.142.1 Luxor 2 Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB929729) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Hybrid 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft WorldWide Telescope MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) NCH Toolbox NTI Backup NOW! 4.7 NTI CD & DVD-Maker ooVoo Paradise 8 PC Pitstop Exterminate2 2.0 Photilla Photo Album Software PowerProducer 3.72 Prism Video Converter QuickTime Realtek High Definition Audio Driver Roxio Activation Module Roxio BackOnTrack Roxio Central Audio Roxio Central Copy Roxio Central Core Roxio Central Data Roxio Central Tools Roxio CinePlayer Roxio CinePlayer Decoder Pack Roxio Disc Gallery Roxio Easy Media Creator 10 Suite Roxio File Backup Roxio MediaShare Roxio Update Manager Safari Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB950114) Security Update for Microsoft Office system 2007 (KB954326) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office Word 2007 (KB969604) Security Update for Visio 2007 (KB947590) SmartSound Quicktracks Plugin Spelling Dictionaries Support For Adobe Reader 8 SUPERAntiSpyware Free Edition Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Outlook 2007 (KB969907) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (kb970012) Update Manager VBA Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Windows Live Mail Windows Live Messenger WinRAR archiver XVID Codec Installation Zuma Deluxe Zuma Deluxe 1.0 ==== Event Viewer Messages From Past Week ======== 18/06/2009 2:58:19 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect. 18/06/2009 2:58:19 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 18/06/2009 2:58:19 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 17/06/2009 11:56:49 PM, Error: Service Control Manager [7000] - The Lbd service failed to start due to the following error: The system cannot find the file specified. 16/06/2009 1:19:01 AM, Error: Service Control Manager [7030] - The Local System Utility service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 15/06/2009 5:16:12 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD 15/06/2009 2:34:07 AM, Error: EventLog [6008] - The previous system shutdown at 2:32:30 AM on 15/06/2009 was unexpected. 15/06/2009 11:50:57 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the PEVSystemStart service to connect. 15/06/2009 11:50:56 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 14/06/2009 9:53:15 PM, Error: EventLog [6008] - The previous system shutdown at 9:51:29 PM on 14/06/2009 was unexpected. 14/06/2009 9:01:17 PM, Error: EventLog [6008] - The previous system shutdown at 8:59:28 PM on 14/06/2009 was unexpected. 14/06/2009 8:58:28 PM, Error: EventLog [6008] - The previous system shutdown at 8:56:47 PM on 14/06/2009 was unexpected. 14/06/2009 8:53:47 PM, Error: EventLog [6008] - The previous system shutdown at 8:52:02 PM on 14/06/2009 was unexpected. 14/06/2009 8:51:02 PM, Error: EventLog [6008] - The previous system shutdown at 8:49:15 PM on 14/06/2009 was unexpected. 14/06/2009 7:47:56 PM, Error: EventLog [6008] - The previous system shutdown at 7:45:21 PM on 14/06/2009 was unexpected. 14/06/2009 5:40:17 PM, Error: EventLog [6008] - The previous system shutdown at 5:38:35 PM on 14/06/2009 was unexpected. 14/06/2009 5:39:56 PM, Error: ACPI [13] - : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly. 14/06/2009 4:55:18 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 14/06/2009 4:10:58 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgTdiX 14/06/2009 3:01:51 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service RoxMediaDB10 with arguments "" in order to run the server: {14EFC14B-A5E8-4CC7-8E8F-2E46FA6A3878} 14/06/2009 2:51:02 PM, Error: EventLog [6008] - The previous system shutdown at 2:49:12 PM on 14/06/2009 was unexpected. 14/06/2009 2:21:19 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 ElRawDisk spldr Wanarpv6 14/06/2009 2:21:19 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 14/06/2009 2:20:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 14/06/2009 2:20:27 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 14/06/2009 2:20:25 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 14/06/2009 2:20:18 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 14/06/2009 11:47:25 PM, Error: EventLog [6008] - The previous system shutdown at 11:46:08 PM on 14/06/2009 was unexpected. 14/06/2009 11:39:46 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 14/06/2009 11:39:46 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23). 14/06/2009 11:39:08 PM, Error: EventLog [6008] - The previous system shutdown at 11:37:19 PM on 14/06/2009 was unexpected. 14/06/2009 1:36:16 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user CAMPO-LAPTOP\Mark SID (S-1-5-21-3021740154-2341606432-4124999485-1008) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 14/06/2009 1:36:16 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {A47979D2-C419-11D9-A5B4-001185AD2B89} to the user CAMPO-LAPTOP\Mark SID (S-1-5-21-3021740154-2341606432-4124999485-1008) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 14/06/2009 1:36:16 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {375FF000-DD27-11D9-8F9C-0002B3988E81} to the user CAMPO-LAPTOP\Mark SID (S-1-5-21-3021740154-2341606432-4124999485-1008) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 14/06/2009 1:36:16 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user CAMPO-LAPTOP\Mark SID (S-1-5-21-3021740154-2341606432-4124999485-1008) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 14/06/2009 1:03:44 AM, Error: Service Control Manager [7023] - The Secure Socket Tunneling Protocol Service service terminated with the following error: The RPC server is unavailable. 14/06/2009 1:03:44 AM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Secure Socket Tunneling Protocol Service service which failed to start because of the following error: The RPC server is unavailable. 14/06/2009 1:01:52 AM, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 13/06/2009 12:04:28 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service. 11/06/2009 6:52:59 AM, Error: Service Control Manager [7000] - The SessionLauncher service failed to start due to the following error: The system cannot find the path specified. 11/06/2009 5:01:37 PM, Error: EventLog [6008] - The previous system shutdown at 7:08:44 AM on 11/06/2009 was unexpected. ==== End Of File =========================== The laptop seems to be running OK. Alll major issues seem pretty much cleared up. I so appreciate all you have done so far. I will await my next instructions. Thanks Mark
Hi,

c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus® ? or do I need to delete one?


no, you need both an antivirus and a firewall but now I don't see System Mechanic Professional 7 installed anymore - did you uninstall it?

I can recommend a free antivirus and a free firewall if you wish.

Three excellent free AntiVirus products are:

Avira AntiVir
Avast
AVG

set the one you choose to receive automatic updates so you are always as fully protected as possible from the newest virus threats.

If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

NOTE: DO NOT install more than one anti-virus program as they will conflict, and provide less protection, not more.


Three excellent free firewalls are:

Comodo
Sunbelt Kerio
Sygate
NOTE: DO NOT install more than one firewall.

Note: If you choose Comodo - Please be careful with the installation of the Comodo program, it comes bundled with an adware toolbar which you need to de-select when you are going through the installation process. It's not a malicious program, but it may be a privacy risk and I don't think you want it on your system.

NEXT

P2P - I see you have P2P software utorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

NEXT


While you are in Add / Remove programs locate Java™ 6 Update 7 and remove it. as its still showing as installed. (leave java 6 update 14 - that is the up to date version)


NEXT

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]



NEXT


Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Hi

I ran the OTC as directed but no
"•A list of tool components used in the Cleanup of malware will be downloaded" never showed up.
It went directly to the •Click Yes to begin the Cleanup process command.
So my desktop still looks like
[external image: Posted Image]

What do you think we should do?

Thanks
Mark
Use this tool instead:

Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI