This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can someone please help me?

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I registered in 2007, donated money the last time y'all helped me and I'll do the same if y'all can help me again… I was registered as Kelly Sovka (member since 2007) but no one replied to my post while other topics posted after mine were getting help…

The only response I got so far was that I am not allowed to post multiple topics… Ok. I won't anymore. But I still haven't got a response and it's been 48 hours. Any suggestions? I will gladly pay money first for help if that's what it takes.

+++++

It seems like the more details I post the less help I receive, so I'll go with the basic "please help me"! :) and hope for the best.

I followed all of the "before posting" instructions to the letter and really… I desperatley need help with this because my business is going down the tubes.

Here is my hijackthis log, lemme know what to do and I'll do it!

+++++

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:28:26 PM, on 6/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\cisvc.exe
C:\CFusionMX\runtime\bin\jrunsvc.exe
C:\CFusionMX\db\slserver52\bin\swagent.exe
C:\CFusionMX\runtime\bin\jrun.exe
C:\CFusionMX\db\slserver52\bin\swstrtr.exe
C:\CFusionMX\db\slserver52\bin\swsoc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Mail Enable\Bin\MELSC.EXE
C:\Program Files\Mail Enable\Bin\MEMTA.EXE
C:\Program Files\Mail Enable\Bin\MEPOC.EXE
C:\Program Files\Mail Enable\Bin\MEPOPS.EXE
C:\Program Files\Mail Enable\Bin\MESMTPC.EXE
c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://secure-ausomxana.crmondemand.com/On…mp;reason=logon
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.0.0.135\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1231211354656
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1231211338765
O16 - DPF: {C77FB8C0-8B6D-440E-AC26-2BD39E97E8F2} (SpdTCtl Class) - http://speedtest.adelphia.net/customerdiag…TESTACTIVEX.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {E53458D2-5A83-4BD1-8DE2-EEEBE73BAB49} - http://www.content-loader.com/load/ccaccess.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O22 - SharedTaskScheduler: IPC Configuration Utility - IPC Configuration Utility - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ColdFusion MX Application Server - Macromedia Inc. - C:\CFusionMX\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - C:\CFusionMX\db\slserver52\bin\swagent.exe
O23 - Service: ColdFusion MX ODBC Server - Unknown owner - C:\CFusionMX\db\slserver52\bin\swstrtr.exe
O23 - Service: Google Update Service (gupdate1c9957150372d6a) (gupdate1c9957150372d6a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MailEnable List Connector (MELCS) - MailEnable Pty Ltd - C:\Program Files\Mail Enable\Bin\MELSC.EXE
O23 - Service: MailEnable Mail Transfer Agent (MEMTAS) - MailEnable Pty Ltd - C:\Program Files\Mail Enable\Bin\MEMTA.EXE
O23 - Service: MailEnable Postoffice Connector (MEPOCS) - MailEnable Pty Ltd - C:\Program Files\Mail Enable\Bin\MEPOC.EXE
O23 - Service: MailEnable POP Service (MEPOPS) - MailEnable Pty Ltd - C:\Program Files\Mail Enable\Bin\MEPOPS.EXE
O23 - Service: MailEnable SMTP Connector (MESMTPCS) - MailEnable Pty Ltd - C:\Program Files\Mail Enable\Bin\MESMTPC.EXE
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 11196 bytes
Hi what problems are you experiencing ?

I will look a bit deeper to see what I can find

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
I downloaded OTS, closed all programs, started OTS, checked the "scan all users", and under additional selected File - Lop Check, File - Purity Scan, and Evnt - EvtViewer (last 10). Then I clicked "run scan", formatted notepad by unchecking wordwrap and attached the log in this post. Thank you. OTS Scan Results attached…

Attachments:

Thanks for your time. I'm a big fan of your work! I have not received a reply yet so I sure hope I'm doing this right. I'm willing to pay money if that will expedite my issue. I FINALLY FOUND THE ERROR LOGS FROM THE PROGRAMS AND PAGES THAT WERE CRASHING MY SYSTEM! They all resemble the following error or message: FILE LOCATION: C:\DOCUME~1\kelly\LOCALS~1\Temp\d191_appcompat.txt

I'm willing to pay money if that will expedite my issue.

That will not get faster help as we are all volunteers here and work for altruistic reasons

Nuff said

You are showing the remnants of a downloader trojan. So I will need to employ a bigger hammer

Start OTS. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-776561741-1177238915-839522115-1003\] > -> HKEY_USERS\S-1-5-21-776561741-1177238915-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{855F3B16-6D32-4FE6-8A56-BBB695989046}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
YN -> "IPC Configuration Utility" [HKLM] -> Reg Error: Key error. [IPC Configuration Utility]
[File - Lop Check]
NY -> SecTaskMan -> C:\Documents and Settings\All Users\Application Data\SecTaskMan
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here.

THEN

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt

If necessary run combofix in safe mode, it will complain but let it run. I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
Do you want to be Kelly Sovka or Registered07? There are many others that have waited longer then you have for help and it doesn't help when you post logs using two user names and 3 or 4 logs. I wil be closing the HJT logs with the user Kelly Sovka.
Wow. That was the longest 8 hours of my life. I did exactly what you told me to do step by step and the following happened:

I started OTS, pasted the information you provided into the OTS pane where it says "paste fix here" and then clicked the "run fix" button. When the fix was complete a got a message box that said finished. I clicked ok and notepad opened with the following results below:

[Registry - Safe List]
Registry value HKEY_USERS\S-1-5-21-776561741-1177238915-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-21-776561741-1177238915-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-21-776561741-1177238915-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\IPC Configuration Utility deleted successfully.
[File - Lop Check]
C:\Documents and Settings\All Users\Application Data\SecTaskMan folder moved successfully.
[Empty Temp Folders]

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Opera cache emptied: 1937734 bytes

User: All Users

User: CustomASP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: kelly
File delete failed. C:\Documents and Settings\kelly\Local Settings\Temp\~DF118A.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\kelly\Local Settings\Temp\~DF11A2.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\kelly\Local Settings\Temp\~DF1322.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\kelly\Local Settings\Temp\~DF1383.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\kelly\Local Settings\Temp\~DFBAF5.tmp scheduled to be deleted on reboot.
->Temp folder emptied: 410624 bytes
File delete failed. C:\Documents and Settings\kelly\Local Settings\Temporary Internet Files\Content.IE5\DGN086O7\Can_someone_please_help_me_t104144[1].html scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\kelly\Local Settings\Temporary Internet Files\Content.IE5\3UEYQP0F\iframe[3].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\kelly\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 23757426 bytes
->Java cache emptied: 2940233 bytes
->Opera cache emptied: 292628 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 32835 bytes

User: MEMPHISS-TS7P1S

User: NetworkService
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_900.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_99c.dat scheduled to be deleted on reboot.
->Temp folder emptied: 32768 bytes
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
C:\WINDOWS\msdownld.tmp folder deleted successfully.
%systemroot% .tmp files removed: 39097 bytes
%systemroot%\System32 .tmp files removed: 7041536 bytes
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_968.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_dcc.dat scheduled to be deleted on reboot.
Windows Temp folder emptied: 657648 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 58.59 mb

< End of fix log >
OTS by OldTimer - Version 3.0.5.3 fix logfile created on 06152009_145425

THEN…

I downloaded combofix from link 1 and renamed it to Combo-Fix as instructed. I double clicked on "Combo-Fix.exe" and followed the prompts and when the status bar finished a blue MSDOS window popped up and just hung for a while, then a pop up appeared asking me if I wanted to update to a newer version, i didn't click on anything, went to task manager and tried to delete the application (update window only) and it would not go away (the x in upper right was faded and unselectable). Then it eventually went away after about 10 minutes and the MSDOS window read: "please wait, combofix is preparing to run. After another 10 minutes it crashed my desktop, an error appeard (nircmd in title bar) real quick and then it was gone, then in another 10 minutes my desktop recovered displaying the following messages:

CAUTION - combofix.exe may be downloaded from above sites… If downloaded from anywhere else it is tainted… I suggest you delete current copy and download one from the above sites. The above sites were http://download.bleepingcomputer.com/sUBs/ComboFix.exe / http://forospyware.com/sUBs/ComboFix.exe / subs.geekstogo.com/Combofix.exe. I tired to reboot and run combofix in safe mode but it did the exact same thing. The process running was: CF9063.exe…

Then I rebooted normally and my startwindow just hung and hung, I let it ride for about 15 minutes, then pulled the cord, rebooted again and the same thing happened (hangs on windows start up window). A time or two I reached my desktop after about a half hour but nothing was clickable and it just hung there frozen. That's what I've been doing for the past oh, six or eight hours…. Trying to gain access to my computer and the internet.

For the heck of it, I dis-assembled my PC (cards, memory, heat sync, etc. Then reassembled it and shuffeled up cards and memory sticks) and what do you know. I am on my computer right now eagerly waiting on your thoughts…

I hope this helps a little bit and sorry about the delay. Lemme know what you think!
Re-run combofix and if it ask to download a newer version then let it do so otherwise you will get the problems you described as the old version will be disabled. This is a safety feature
Hello. Sorry about the delay, I had to go to Cleveland yesterday…

My computer is slower than ever now that Combo-Fix got involved. I did the following this time:

I downloaded combofix from link 1 and renamed it to Combo-Fix as instructed. I double clicked on "Combo-Fix.exe" and followed the prompts and when the status bar finished a blue MSDOS window popped up and just hung for a while, then a pop up appeared asking me if I wanted to update to a newer version, I clicked on ok to download newer version then Combo-Fix began to run by backing up registry, THEN created system restore point, THEN a pop up window appeared = This machine does not have microsoft windows recovery software, without it CF will not attempt to fix some serious infections. I Clicked YES, the MSDOS Window read connecting… Then I clicked YES on end user agreement and YES on license agreement. CF began running again = downloading MS recovery console = 100% downloaded (the ##### 100% message just hung and hung and hung…), THEN I received a congratulations message for MS recovery console. CF automatically rebooted and ran, I clicked YES to scan for Malware, then the Autoscan took about 15 minutes then generated the following report:

COMBO FIX LOG IS PASTED BELOW AND ATTACHED AS A FILE (word wrap unchecked):

ComboFix 09-06-16.05 - kelly 06/17/2009 11:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1279.613 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\0609 Virus Files\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\NetworkService\Application Data\twain_32
c:\windows\system32\Cache
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\documents and settings\NetworkService\Application Data\twain_32\user.ds
c:\windows\IE4 Error Log.txt
c:\windows\system32\abbnp.dll
c:\windows\system32\bszip.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\Ijl11.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg

Infected copy of c:\windows\system32\ws2_32.dll was found and disinfected
Restored copy from - c:\system volume information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP828\A0403053.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IPRIP
——-\Service_Iprip


((((((((((((((((((((((((( Files Created from 2009-05-17 to 2009-06-17 )))))))))))))))))))))))))))))))
.

2009-06-17 14:45 . 2009-06-17 14:46 ——– dc—-w- C:\32788R22FWJFW
2009-06-17 14:01 . 2009-06-14 13:21 89104 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\NAVENG.SYS
2009-06-17 14:01 . 2009-06-14 13:21 876144 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\NAVEX15.SYS
2009-06-17 14:01 . 2009-06-14 13:21 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\NAVENG32.DLL
2009-06-17 14:01 . 2009-06-14 13:21 1181040 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\NAVEX32A.DLL
2009-06-17 14:00 . 2009-06-14 13:21 101936 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\ERASER.SYS
2009-06-17 14:00 . 2009-06-14 13:21 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\EECTRL.SYS
2009-06-17 14:00 . 2009-06-14 13:20 259368 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\ECMSVR32.DLL
2009-06-17 14:00 . 2009-06-14 13:20 2414128 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\CCERASER.DLL
2009-06-15 18:54 . 2009-06-15 18:54 ——– dc—-w- C:\_OTS
2009-06-15 13:26 . 2009-06-15 13:26 ——– dc—-w- C:\N360_BACKUP
2009-06-14 18:20 . 2009-06-14 13:21 276344 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys
2009-06-14 18:20 . 2009-06-14 13:20 447864 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSxpx86.dll
2009-06-14 18:20 . 2009-03-16 20:03 533880 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\Scxpx86.dll
2009-06-14 18:20 . 2009-06-14 13:21 396848 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSviA64.sys
2009-06-14 18:20 . 2009-06-14 13:21 292912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys
2009-06-14 15:46 . 2009-06-14 15:46 ——– d—–w- c:\documents and settings\kelly\Local Settings\Application Data\Symantec
2009-06-14 13:22 . 2009-01-15 16:19 23848 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-14 13:22 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-06-14 13:22 . 2009-06-14 13:22 ——– d—–w- c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-14 13:20 . 2009-06-14 13:20 447864 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\idsxpx86.dll
2009-06-14 13:20 . 2009-06-14 13:20 259368 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090226.034\ECMSVR32.DLL
2009-06-14 13:20 . 2009-06-14 13:20 796016 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-06-14 13:20 . 2009-06-14 13:20 2414128 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090226.034\CCERASER.DLL
2009-06-14 11:44 . 2009-06-14 11:44 ——– d—–w- c:\documents and settings\kelly\Local Settings\Application Data\Apple Computer
2009-06-14 03:51 . 2009-06-14 03:51 ——– d—–w- c:\windows\system32\drivers\N360
2009-06-14 03:51 . 2009-06-14 16:01 ——– d—–w- c:\program files\Norton 360
2009-06-14 03:51 . 2009-06-14 03:51 ——– d—–w- c:\program files\Windows Sidebar
2009-06-14 02:27 . 2009-06-14 02:27 ——– d—–w- c:\documents and settings\kelly\Application Data\Malwarebytes
2009-06-14 02:27 . 2009-05-26 17:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 02:27 . 2009-06-15 21:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-14 02:27 . 2009-06-14 02:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-14 02:27 . 2009-05-26 17:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-14 02:12 . 2009-06-15 21:50 ——– d—–w- c:\program files\ERUNT
2009-06-14 02:05 . 2009-06-14 02:05 ——– d—–w- c:\program files\Trend Micro
2009-06-13 19:47 . 2009-06-13 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\PCSettings
2009-06-13 19:47 . 2009-06-13 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-06-13 19:46 . 2009-06-14 13:19 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-06-13 19:46 . 2009-06-13 19:46 ——– d—–w- c:\program files\NortonInstaller
2009-06-13 19:08 . 2009-06-13 19:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-06-12 23:57 . 2009-06-12 23:57 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-06-12 23:41 . 2009-06-12 23:41 ——– d—–w- c:\documents and settings\kelly\Application Data\Windows Desktop Search
2009-06-12 22:47 . 2009-06-12 22:50 ——– dc—-w- C:\433f51f4670db33e128b49cb
2009-06-12 21:18 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-06-12 21:18 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-12 21:13 . 2009-06-12 21:16 ——– dc-h–w- c:\windows\ie8
2009-06-10 22:54 . 2009-06-10 22:54 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-05-31 18:56 . 2009-05-31 18:56 ——– d—–w- c:\program files\Dopewars
2009-05-30 21:43 . 2009-05-30 21:43 ——– d—–w- c:\documents and settings\kelly\Local Settings\Application Data\Apple
2009-05-25 19:33 . 2009-05-25 19:37 ——– d—–w- c:\documents and settings\kelly\Application Data\Windows Live Writer
2009-05-25 19:33 . 2009-05-25 19:33 ——– d—–w- c:\documents and settings\kelly\Local Settings\Application Data\Windows Live Writer
2009-05-25 18:06 . 2009-06-14 15:30 ——– d—–w- c:\documents and settings\kelly\Tracing

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-17 15:21 . 2003-12-10 21:54 22 —-a-w- C:\qpmd8376.bin
2009-06-17 15:19 . 2007-05-26 01:24 24 —-a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000007-00001102-00000002-80221102}.dat
2009-06-17 15:19 . 2007-05-26 01:24 24 —-a-w- c:\windows\system32\DVCState-{00000002-00000000-00000007-00001102-00000002-80221102}.dat
2009-06-15 01:10 . 2003-05-31 16:10 ——– d—–w- c:\program files\Trillian
2009-06-14 03:51 . 2003-05-30 02:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-13 20:12 . 2008-07-24 03:32 ——– d—–w- c:\program files\Windows Desktop Search
2009-06-13 19:47 . 2003-05-30 02:56 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-13 19:08 . 2004-08-26 23:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-13 01:07 . 2008-07-27 01:23 ——– d—–w- c:\program files\Microsoft SQL Server
2009-06-12 23:47 . 2006-04-22 00:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-02 21:00 . 2009-06-02 21:00 44173 —-a-w- c:\documents and settings\All Users\Application Data\tmp20.tmp
2009-05-30 21:46 . 2003-06-01 08:27 ——– d—–w- c:\program files\QuickTime
2009-05-30 21:45 . 2007-06-15 05:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-24 17:25 . 2007-06-25 07:25 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-05-17 23:33 . 2004-12-19 02:42 ——– d—–w- c:\program files\Google
2009-05-13 09:21 . 2008-02-17 23:49 ——– d—–w- c:\program files\WinMX
2009-05-13 05:15 . 2004-02-06 22:05 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-11 03:12 . 2009-05-10 05:45 ——– d—–w- c:\program files\Digital Foci PhotoViewer 2.0
2009-05-11 03:12 . 2003-08-23 02:36 ——– d—–w- c:\program files\FinePixViewer
2009-05-11 03:12 . 2007-10-20 02:28 ——– d—–w- c:\program files\Windows Media Connect 2
2009-05-11 03:12 . 2003-06-15 20:25 ——– d—–w- c:\program files\Veo Digital Studio
2009-05-11 03:12 . 2009-04-05 12:11 ——– d—–w- c:\program files\PHP
2009-05-11 03:12 . 2003-05-31 22:32 ——– d—–w- c:\program files\Microsoft Image Composer
2009-05-10 08:53 . 2003-06-15 20:27 ——– d—–w- c:\program files\Common Files\Real
2009-05-07 15:32 . 2001-08-18 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-03 19:40 . 2007-07-10 13:42 78592 -c–a-w- c:\documents and settings\kelly\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-03 19:34 . 2009-05-03 19:28 ——– d—–w- c:\program files\Windows Live
2009-05-03 19:34 . 2009-05-03 19:34 ——– d—–w- c:\program files\Microsoft Sync Framework
2009-05-03 19:32 . 2008-08-05 00:14 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2009-05-03 19:29 . 2009-03-14 04:26 ——– d—–w- c:\program files\Microsoft
2009-05-03 19:29 . 2009-05-03 19:29 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-05-03 03:18 . 2007-07-19 06:21 ——– d—–w- c:\program files\Qualcomm
2009-05-03 03:18 . 2003-05-30 01:34 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-03 00:16 . 2008-06-30 18:41 ——– d—–w- c:\program files\Opera
2009-05-02 22:31 . 2006-05-08 00:06 ——– d—–w- c:\program files\Citrix
2009-05-02 00:08 . 2007-06-09 04:20 ——– d—–w- c:\program files\Common Files\HP
2009-04-29 04:55 . 2009-04-29 04:55 78336 ——w- c:\windows\system32\ieencode.dll
2009-04-24 14:59 . 2009-04-24 14:59 58702 -c–a-w- c:\documents and settings\All Users\Application Data\tmpA1.tmp
2009-04-22 21:21 . 2009-04-22 21:21 ——– d—–w- c:\program files\Common Files\SupportSoft
2009-04-17 15:26 . 2009-04-17 15:25 42014 -c–a-w- c:\documents and settings\All Users\Application Data\tmp25C.tmp
2009-04-17 12:26 . 2001-08-18 12:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-04-21 03:35 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-07 11:01 . 2005-12-12 17:39 95093 —-a-w- c:\program files\Common Files\Engines.lnl
2009-04-07 10:59 . 2009-04-07 10:59 1078 -c–a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{A84D0BEE-2422-4F50-9CC8-83B495A6370E}\_60322c3b.exe
2009-04-07 10:59 . 2009-04-07 10:59 1078 -c–a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{A84D0BEE-2422-4F50-9CC8-83B495A6370E}\_42307eb7.exe
2009-04-07 10:59 . 2009-04-07 10:59 1078 -c–a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{A84D0BEE-2422-4F50-9CC8-83B495A6370E}\_366b66c4.exe
2009-04-06 22:09 . 2009-04-06 22:09 212 —-a-w- c:\windows\ildasmfnt.bin
2001-08-18 12:00 . 2001-08-18 12:00 94784 -csh–w- c:\windows\twain.dll
2008-04-14 00:12 . 2001-08-18 12:00 50688 -csh–w- c:\windows\twain_32.dll
2008-12-24 09:11 . 2008-12-24 09:08 109 -csha-w- c:\windows\system32\14913480.dat
2008-04-14 00:12 . 2001-08-18 12:00 57344 -csha-w- c:\windows\system32\msvcirt.dll
2008-04-14 00:12 . 2003-05-30 03:38 413696 –sha-w- c:\windows\system32\msvcp60.dll
2008-04-14 00:12 . 2001-08-18 12:00 551936 –sh–w- c:\windows\system32\oleaut32.dll
2008-04-14 00:12 . 2001-08-18 12:00 84992 -csha-w- c:\windows\system32\olepro32.dll
2008-04-14 00:12 . 2001-08-18 12:00 11776 -csha-w- c:\windows\system32\regsvr32.exe
.

——- Sigcheck ——-

[-] 2005-05-25 19:07 359936 63FDFEA54EB53DE2D863EE454937CE1E c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2006-01-13 17:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB893066$\tcpip.sys
[-] 2005-05-25 19:04 359808 88763A98A4C26C409741B4AA162720C9 c:\windows\$NtUninstallKB913446$\tcpip.sys
[-] 2006-01-13 02:28 359808 583E063FDC888CA30D05C2724B0D7EF4 c:\windows\$NtUninstallKB917953$\tcpip.sys
[-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB941644$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2008-04-13 19:20 361344 ACCF5A9A1FFAA490F33DBA1C632B95E1 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Live Menu 3.3.lnk]
backup=c:\windows\pss\eFax Live Menu 3.3.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu 3.3.lnk]
backup=c:\windows\pss\eFax Tray Menu 3.3.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax.com Tray Menu.lnk]
backup=c:\windows\pss\eFax.com Tray Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
backup=c:\windows\pss\Exif Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HPAiODevice(hp psc 700 series) - 1.lnk]
backup=c:\windows\pss\HPAiODevice(hp psc 700 series) - 1.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Instant Wireless Configuration Utility.lnk]
backup=c:\windows\pss\Instant Wireless Configuration Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Live Menu.lnk]
backup=c:\windows\pss\Live Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk.disabled
backup=c:\windows\pss\Microsoft Office.lnk.disabledCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^kelly^Start Menu^Programs^Startup^HotSync Manager.LNK]
path=c:\documents and settings\kelly\Start Menu\Programs\Startup\HotSync Manager.LNK
backup=c:\windows\pss\HotSync Manager.LNKStartup

[HKLM\~\startupfolder\C:^Documents and Settings^kelly^Start Menu^Programs^Startup^Palm Registration.lnk]
path=c:\documents and settings\kelly\Start Menu\Programs\Startup\Palm Registration.lnk
backup=c:\windows\pss\Palm Registration.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^kelly^Start Menu^Programs^Startup^SpywareGuard.lnk]
path=c:\documents and settings\kelly\Start Menu\Programs\Startup\SpywareGuard.lnk
backup=c:\windows\pss\SpywareGuard.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^kelly^Start Menu^Programs^Startup^Starter.lnk]
path=c:\documents and settings\kelly\Start Menu\Programs\Startup\Starter.lnk
backup=c:\windows\pss\Starter.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Admanager Controller
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BullsEye Network
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Optimizer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbb
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Si Meter
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebRebates0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Win Comm
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows AdTools

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE"
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinPatrol"=c:\program files\BillP Studios\WinPatrol\winpatrol.exe
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0300000.087\BHDrvx86.sys [6/14/2009 9:21 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0300000.087\cchpx86.sys [6/14/2009 9:21 AM 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys [6/14/2009 2:20 PM 276344]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [5/3/2009 3:34 PM 55152]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/14/2009 9:45 AM 101936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-17 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-23 04:43]

2009-06-16 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - kelly.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-04-25 03:19]

2009-06-17 c:\windows\Tasks\User_Feed_Synchronization-{7AC137BD-8B93-4F53-B158-681DD966BBF5}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-NAV Agent - c:\progra~1\NORTON~1\navapw32.exe
ShellExecuteHooks-{56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = https://secure-ausomxana.crmondemand.com/On…mp;reason=logon
uInternet Settings,ProxyOverride = 127.0.0.1
Trusted Zone: crmondemand.com\sso
DPF: cpcScanner - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {C77FB8C0-8B6D-440E-AC26-2BD39E97E8F2} - hxxp://speedtest.adelphia.net/customerdiag/speedtest/SPEEDTESTACTIVEX.CAB
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-17 11:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"
–

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.0.0.135\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(4948)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
c:\cfusionmx\runtime\bin\jrunsvc.exe
c:\cfusionmx\db\slserver52\bin\swagent.exe
c:\cfusionmx\runtime\bin\jrun.exe
c:\cfusionmx\db\slserver52\bin\swstrtr.exe
c:\cfusionmx\db\slserver52\bin\swsoc.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Mail Enable\Bin\MELSC.exe
c:\program files\Mail Enable\Bin\MEMTA.exe
c:\program files\Mail Enable\Bin\MEPOC.exe
c:\program files\Mail Enable\Bin\MEPOPS.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\program files\Mail Enable\Bin\MESMTPC.exe
c:\windows\system32\msdtc.exe
c:\program files\Microsoft SQL Server\MSSQL.5\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\locator.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\snmp.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\mqsvc.exe
c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-17 11:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-17 15:36

Pre-Run: 11,729,731,584 bytes free
Post-Run: 12,174,315,520 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

371

Infected copy of c:\windows\system32\ws2_32.dll was found and disinfected

That was your problem

What problems are you experiencing now ? I will try to sort the speed problem at the end

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Now big blue shortcut arrows that I've never seen before are appearing on all of my shortcuts (in my files, folders, and desktop). When I launch Norton updates the program opens and closes really fast without ever launching, and I have some processes active in windows task manager that I've never seen before (alg.exe, aawservice.exe, ccsvchst.exe (two of those), csrss.exe, and a couple of PIFSvc.exe files, a rapimgr.exe file, a wmiprvse.exe file, and a wscntfy.exe file)… The computer still hangs between programs. For example Internet explorer window loads, then hangs and hangs and hangs, then eventually loads (after about 30 - 40 seconds)… Here is the log file results from the Malwarebytes scan: Malwarebytes' Anti-Malware 1.38 Database version: 2298 Windows 5.1.2600 Service Pack 3 6/17/2009 1:51:31 PM mbam-log-2009-06-17 (13-51-31).txt Scan type: Quick Scan Objects scanned: 112569 Time elapsed: 9 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Also I can't do a disk cleanup (right click C, select disc clean up). It starts the process and just quits and disappears with no messages or explanations. I can't update Norton, I can't update ad aware, basically the don't crash or provide any messages, they just stop doing what it is they are supposed to do and when I try again it will disappear even quicker. In my local settings / TEMP folder there are now 6 files named ~DF4 something (~DF5079.tmp, ~DF42CA.tmp, ~DF42B1.tmp, ~DF4226.tmp, ~DF42FF4.tmp)…

I have some processes active in windows task manager that I've never seen before (alg.exe, aawservice.exe, ccsvchst.exe (two of those), csrss.exe, and a couple of PIFSvc.exe files, a rapimgr.exe file, a wmiprvse.exe file, and a wscntfy.exe file)…

These are legitimate windows files/Adaware/Norton

Download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit icon to start the program.
  • press start
  • Allow the program to run the initial express scan
  • This will scan the files currently running in memory. If something is found, click the YES button when it asks you if you want to cure it. This is only a short scan.
    Note: A pop up may appear during this phase suggesting you purchase their program - click the X at the top right corner of this pop-up to close it.
  • Once the short scan has finished, check the Complete scan box on the left side, even if nothing was found on the initial scan.
  • Then click the small green arrow button on the right under the Dr.Web Antivirus picture to start the complete scan. (This scan will take several hours)
  • During this complete scan - if Dr.Web finds an infection a window will pop up requesting your attention. Select the Cure button.
    • Note:(If the file cannot be cured, Dr.Web will automatically delete the file)
  • Once the scan is complete, on the menu bar, click file and choose report list.
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report will need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Close Dr.Web Cureit.
  • Please post the Dr.Web.txt report in your next reply
Wow. That was a nine hour scan… I downloaded Dr. Web Cureit from the link you provided, ran the program to run the express scan and it must have found something because it opened the window to "cure it" I selected yes, then another one popped up and suggested that I run the complete scan and the program flickered and went right into the complete scan. After 8 hours or so the complete scan finished. It generated several pop up window to cure with a cure all (or delete if it can't be cured) and I selected ok. The program eventually generated the results and viruses found = 20 (I think). I wne to the menu bar and clivked file, report list and saved the DrWeb.cvs to my desktop. I then opend the file and saved as DrWeb.txt. I pasted the DrWeb.txt results below: DR. WEB COMPLETE SCAN RESULTS… FileManager.ascx.vb;C:\Documents and Settings\kelly\My Documents\My Webs\VWD #2\DotNetNuke501\htdocs\DesktopModules\Admin\FileManager;Probably SCRIPT.Virus;Incurable.Deleted.; dw22.exe\data061;C:\Documents and Settings\kelly\My Documents\Treo Pro 2009\Downloads\dw22.exe;Adware.Gator;; dw22.exe;C:\Documents and Settings\kelly\My Documents\Treo Pro 2009\Downloads;Archive contains infected objects;Moved.; Process.exe;C:\Documents and Settings\kelly\My Documents\Virus and Recovery Info\Virus Programs Downloads and Info\SmitfraudFix;Tool.Prockill;Incurable.Deleted.; restart.exe;C:\Documents and Settings\kelly\My Documents\Virus and Recovery Info\Virus Programs Downloads and Info\SmitfraudFix;Tool.ShutDown.14;Incurable.Deleted.; SmitfraudFix.exe\SmitfraudFix\Process.exe;C:\Documents and Settings\kelly\My Documents\Virus and Recovery Info\Virus Programs Downloads and Info\SmitfraudFix\Smitfraud;Tool.Prockill;; SmitfraudFix.exe\SmitfraudFix\restart.exe;C:\Documents and Settings\kelly\My Documents\Virus and Recovery Info\Virus Programs Downloads and Info\SmitfraudFix\Smitfraud;Tool.ShutDown.14;; SmitfraudFix.exe;C:\Documents and Settings\kelly\My Documents\Virus and Recovery Info\Virus Programs Downloads and Info\SmitfraudFix;Archive contains infected objects;Moved.; LIU_UPD.DLL;C:\Program Files\SpotLife\SpotLife;Probably DLOADER.Trojan;Incurable.Deleted.; webmail.msi/stream000\lv_LV.po1779.B21FAFCB_3BAB_4B90_9A4B_29B810569F9C;C:\Program Files\SWsoft_Plesk\Install\071225.14\webmail.msi/stream000;Modification of IRC.Linda;; stream000;C:\Program Files\SWsoft_Plesk\Install\071225.14;Archive contains infected objects;; webmail.msi;C:\Program Files\SWsoft_Plesk\Install\071225.14;Archive contains infected objects;Moved.; Process.exe.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Tool.Prockill;Incurable.Deleted.; A0413814.bat;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP835;Probably BATCH.Virus;Incurable.Deleted.; A0413881.bat;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP835;Probably BATCH.Virus;Incurable.Deleted.; A0414998.bat;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP835;Probably BATCH.Virus;Incurable.Deleted.; A0420004.bat;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP835;Probably BATCH.Virus;Incurable.Deleted.; A0420070.bat;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP835;Probably BATCH.Virus;Incurable.Deleted.; A0420134.bat;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP835;Probably BATCH.Virus;Incurable.Deleted.; A0420192.exe;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP836;Tool.Prockill;Incurable.Deleted.; A0420247.bat;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP836;Probably BATCH.Virus;Incurable.Deleted.; A0421387.msi/stream000\lv_LV.po1779.B21FAFCB_3BAB_4B90_9A4B_29B810569F9C;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP836\A0421387.msi/stream000;Modification of IRC.Linda;; stream000;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP836;Archive contains infected objects;; A0421387.msi;C:\System Volume Information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP836;Archive contains infected objects;Moved.; ExpressDigital Darkroom Web Edition V8.8.msi\stream004;C:\WINDOWS\Downloaded Installations\{CC33686B-397D-44BA-ADAA-DEB1B4DC5935}\ExpressDigital Darkroom Web Edition V8.8.msi;Dialer.Accessor.origin;; ExpressDigital Darkroom Web Edition V8.8.msi\stream008;C:\WINDOWS\Downloaded Installations\{CC33686B-397D-44BA-ADAA-DEB1B4DC5935}\ExpressDigital Darkroom Web Edition V8.8.msi;Dialer.Accessor.origin;; ExpressDigital Darkroom Web Edition V8.8.msi;C:\WINDOWS\Downloaded Installations\{CC33686B-397D-44BA-ADAA-DEB1B4DC5935};Archive contains infected objects;Moved.; Lemme know what you think and thanks again for your support…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI