This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] VirutIK and some others

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:51:03 AM, on 6/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Program Files\RemoteObserverClient\roclient.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lexmark 350 Series\ezprint.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\TweetDeck\TweetDeck.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\ShellLess\ShellLess.exe
C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2guard.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\A2START.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Brother Technology\AptEdit Pro 4.6 for Giveaway\aptedit.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080209
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080209
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080209
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 350 Series\ezprint.exe"
O4 - HKLM\..\Run: [LXCVCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCVtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: lxcv_device - Unknown owner - C:\WINDOWS\system32\lxcvcoms.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: roclient - Unknown owner - C:\Program Files\RemoteObserverClient\roclient.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

–
End of file - 11452 bytes
Hi,

Can you advise what program detected VirutlK and in what file was it detected?


Please do the following:

I would like you to upload a file to be scanned
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    C:\WINDOWS\system32\services.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Then please do the same for the following files:

c:\windows\system32\userinit.exe
c:\windows\system32\svchost.exe
c:\windows\explorer.exe



NEXT


STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT



Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.


Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
Thanks - was suing A-Squared

ok, here are the first set of thinsg you asked me for


VirSCAN.org Scanned Report :
Scanned time : 2009/06/21 10:23:46 (EDT)
Scanner results: All Scanners reported not find malware!
File Name : services.exe
File Size : 110592 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 65df52f5b8b6e9bbd183505225c37315
SHA1 : de3701d2c03d9ae29b2d87eccafbbcadf1bfb7e3
Online report : http://virscan.org/report/b2d6f27d9920b899…c06a66260e.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090621192326 2009-06-21 40.13 -
AhnLab V3 2009.06.21.00 2009.06.21 2009-06-21 0.75 -
AntiVir 8.2.0.193 7.1.4.119 2009-06-21 0.16 -
Antiy 2.0.18 20090621.2563876 2009-06-21 0.12 -
Arcavir 2009 200906210742 2009-06-21 0.06 -
Authentium 5.1.1 200906201725 2009-06-20 1.40 -
AVAST! 4.7.4 090620-0 2009-06-20 0.01 -
AVG 8.5.286 270.12.83/2191 2009-06-21 3.42 -
BitDefender 7.81008.3439753 7.26105 2009-06-21 3.08 -
CA (VET) 9.0.0.143 31.6.6569 2009-06-20 7.59 -
ClamAV 0.95.1 9490 2009-06-20 0.03 -
Comodo 3.9 1385 2009-06-21 0.74 -
CP Secure 1.1.0.715 2009.06.21 2009-06-21 10.48 -
Dr.Web 4.44.0.9170 2009.06.21 2009-06-21 4.95 -
F-Prot 4.4.4.56 20090620 2009-06-20 1.36 -
F-Secure 5.51.6100 2009.06.19.02 2009-06-19 5.93 -
Fortinet 2.81-3.117 10.518 2009-06-21 0.23 -
GData 19.5964/19.371 20090621 2009-06-21 4.35 -
ViRobot 20090619 2009.06.19 2009-06-19 0.41 -
Ikarus T3.1.01.59 2009.06.21.72900 2009-06-21 3.31 -
JiangMin 11.0.706 2009.06.21 2009-06-21 2.04 -
Kaspersky 5.5.10 2009.06.21 2009-06-21 0.05 -
KingSoft 2009.2.5.15 2009.6.21.21 2009-06-21 0.49 -
McAfee 5.3.00 5652 2009-06-20 3.07 -
Microsoft 1.4803 2009.06.21 2009-06-21 4.84 -
mks_vir 2.01 2009.06.19 2009-06-19 3.18 -
Norman 6.01.09 6.01.00 2009-06-19 4.01 -
Panda 9.05.01 2009.06.21 2009-06-21 1.77 -
Trend Micro 8.700-1004 6.210.12 2009-06-21 0.03 -
Quick Heal 10.00 2009.06.19 2009-06-19 1.20 -
Rising 20.0 21.34.62.00 2009-06-21 0.77 -
Sophos 2.87.1 4.42 2009-06-21 2.56 -
Sunbelt 5200 5200 2009-06-20 0.95 -
Symantec 1.3.0.24 20090620.025 2009-06-20 0.05 -
nProtect 20090621.01 4379863 2009-06-21 5.57 -
The Hacker 6.3.4.3 v00350 2009-06-20 0.64 -
VBA32 3.12.10.7 20090620.1443 2009-06-20 2.12 -
VirusBuster 4.5.11.10 10.107.19/1648057 2009-06-21 2.04 -


VirSCAN.org Scanned Report :
Scanned time : 2009/06/21 10:15:23 (EDT)
Scanner results: All Scanners reported not find malware!
File Name : svchost.exe
File Size : 14336 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 27c6d03bcdb8cfeb96b716f3d8be3e18
SHA1 : 49083ae3725a0488e0a8fbbe1335c745f70c4667
Online report : http://virscan.org/report/cdde38d4efab4f90…4c417039b5.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090621192326 2009-06-21 2.60 -
AhnLab V3 2009.06.21.00 2009.06.21 2009-06-21 0.84 -
AntiVir 8.2.0.193 7.1.4.119 2009-06-21 0.40 -
Antiy 2.0.18 20090621.2563876 2009-06-21 0.12 -
Arcavir 2009 200906210742 2009-06-21 0.04 -
Authentium 5.1.1 200906201725 2009-06-20 1.24 -
AVAST! 4.7.4 090620-0 2009-06-20 0.01 -
AVG 8.5.286 270.12.83/2191 2009-06-21 3.57 -
BitDefender 7.81008.3439753 7.26105 2009-06-21 3.15 -
CA (VET) 9.0.0.143 31.6.6569 2009-06-20 6.97 -
ClamAV 0.95.1 9490 2009-06-20 0.01 -
Comodo 3.9 1385 2009-06-21 0.77 -
CP Secure 1.1.0.715 2009.06.21 2009-06-21 10.51 -
Dr.Web 4.44.0.9170 2009.06.21 2009-06-21 5.11 -
F-Prot 4.4.4.56 20090620 2009-06-20 1.15 -
F-Secure 5.51.6100 2009.06.19.02 2009-06-19 0.07 -
Fortinet 2.81-3.117 10.518 2009-06-21 0.26 -
GData 19.5964/19.371 20090621 2009-06-21 4.70 -
ViRobot 20090619 2009.06.19 2009-06-19 0.44 -
Ikarus T3.1.01.59 2009.06.21.72900 2009-06-21 3.33 -
JiangMin 11.0.706 2009.06.21 2009-06-21 2.16 -
Kaspersky 5.5.10 2009.06.21 2009-06-21 0.05 -
KingSoft 2009.2.5.15 2009.6.21.21 2009-06-21 0.51 -
McAfee 5.3.00 5652 2009-06-20 3.11 -
Microsoft 1.4803 2009.06.21 2009-06-21 4.97 -
mks_vir 2.01 2009.06.19 2009-06-19 3.20 -
Norman 6.01.09 6.01.00 2009-06-19 4.01 -
Panda 9.05.01 2009.06.21 2009-06-21 1.66 -
Trend Micro 8.700-1004 6.210.12 2009-06-21 0.03 -
Quick Heal 10.00 2009.06.19 2009-06-19 1.19 -
Rising 20.0 21.34.62.00 2009-06-21 0.79 -
Sophos 2.87.1 4.42 2009-06-21 2.54 -
Sunbelt 5200 5200 2009-06-20 0.86 -
Symantec 1.3.0.24 20090620.025 2009-06-20 0.07 -
nProtect 20090621.01 4379863 2009-06-21 5.95 -
The Hacker 6.3.4.3 v00350 2009-06-20 0.73 -
VBA32 3.12.10.7 20090620.1443 2009-06-20 2.02 -
VirusBuster 4.5.11.10 10.107.19/1648057 2009-06-21 2.98 -


VirSCAN.org Scanned Report :
Scanned time : 2009/06/21 10:11:04 (EDT)
Scanner results: All Scanners reported not find malware!
File Name : explorer.exe
File Size : 1033728 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 12896823fb95bfb3dc9b46bcaedc9923
SHA1 : 9d2bf84874abc5b6e9a2744b7865c193c08d362f
Online report : http://virscan.org/report/b5320cb55faaa002…b6d8d0cf91.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090621192326 2009-06-21 40.13 -
AhnLab V3 2009.06.21.00 2009.06.21 2009-06-21 0.84 -
AntiVir 8.2.0.193 7.1.4.119 2009-06-21 0.28 -
Antiy 2.0.18 20090621.2563876 2009-06-21 0.13 -
Arcavir 2009 200906210742 2009-06-21 0.08 -
Authentium 5.1.1 200906201725 2009-06-20 2.13 -
AVAST! 4.7.4 090620-0 2009-06-20 0.05 -
AVG 8.5.286 270.12.83/2191 2009-06-21 3.43 -
BitDefender 7.81008.3439753 7.26105 2009-06-21 3.12 -
CA (VET) 9.0.0.143 31.6.6569 2009-06-20 4.05 -
ClamAV 0.95.1 9490 2009-06-20 0.16 -
Comodo 3.9 1385 2009-06-21 0.85 -
CP Secure 1.1.0.715 2009.06.21 2009-06-21 10.48 -
Dr.Web 4.44.0.9170 2009.06.21 2009-06-21 5.01 -
F-Prot 4.4.4.56 20090620 2009-06-20 2.12 -
F-Secure 5.51.6100 2009.06.19.02 2009-06-19 5.83 -
Fortinet 2.81-3.117 10.518 2009-06-21 0.28 -
GData 19.5964/19.371 20090621 2009-06-21 4.57 -
ViRobot 20090619 2009.06.19 2009-06-19 0.42 -
Ikarus T3.1.01.59 2009.06.21.72900 2009-06-21 3.36 -
JiangMin 11.0.706 2009.06.21 2009-06-21 2.12 -
Kaspersky 5.5.10 2009.06.21 2009-06-21 0.06 -
KingSoft 2009.2.5.15 2009.6.21.21 2009-06-21 0.89 -
McAfee 5.3.00 5652 2009-06-20 3.31 -
Microsoft 1.4803 2009.06.21 2009-06-21 5.01 -
mks_vir 2.01 2009.06.19 2009-06-19 3.26 -
Norman 6.01.09 6.01.00 2009-06-19 4.01 -
Panda 9.05.01 2009.06.21 2009-06-21 1.69 -
Trend Micro 8.700-1004 6.210.12 2009-06-21 0.03 -
Quick Heal 10.00 2009.06.19 2009-06-19 1.60 -
Rising 20.0 21.34.62.00 2009-06-21 0.99 -
Sophos 2.87.1 4.42 2009-06-21 2.58 -
Sunbelt 5200 5200 2009-06-20 0.85 -
Symantec 1.3.0.24 20090620.025 2009-06-20 0.07 -
nProtect 20090621.01 4379863 2009-06-21 6.01 -
The Hacker 6.3.4.3 v00350 2009-06-20 0.71 -
VBA32 3.12.10.7 20090620.1443 2009-06-20 2.12 -
VirusBuster 4.5.11.10 10.107.19/1648057 2009-06-21 2.26 -


VirSCAN.org Scanned Report :
Scanned time : 2009/06/21 10:27:41 (EDT)
Scanner results: All Scanners reported not find malware!
File Name : userinit.exe
File Size : 26112 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : a93aee1928a9d7ce3e16d24ec7380f89
SHA1 : 513f8bdf67a5a9e09803cfb61f590b39f2683853
Online report : http://virscan.org/report/c687f54266a84e99…1d2e453974.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090621192326 2009-06-21 2.97 -
AhnLab V3 2009.06.21.00 2009.06.21 2009-06-21 0.83 -
AntiVir 8.2.0.193 7.1.4.119 2009-06-21 0.17 -
Antiy 2.0.18 20090621.2563876 2009-06-21 0.12 -
Arcavir 2009 200906210742 2009-06-21 0.01 -
Authentium 5.1.1 200906201725 2009-06-20 1.14 -
AVAST! 4.7.4 090620-0 2009-06-20 0.01 -
AVG 8.5.286 270.12.83/2191 2009-06-21 3.75 -
BitDefender 7.81008.3439753 7.26105 2009-06-21 3.22 -
CA (VET) 9.0.0.143 31.6.6569 2009-06-20 5.68 -
ClamAV 0.95.1 9490 2009-06-20 0.01 -
Comodo 3.9 1385 2009-06-21 0.80 -
CP Secure 1.1.0.715 2009.06.21 2009-06-21 10.57 -
Dr.Web 4.44.0.9170 2009.06.21 2009-06-21 4.73 -
F-Prot 4.4.4.56 20090620 2009-06-20 1.12 -
F-Secure 5.51.6100 2009.06.19.02 2009-06-19 0.10 -
Fortinet 2.81-3.117 10.518 2009-06-21 0.21 -
GData 19.5964/19.371 20090621 2009-06-21 4.76 -
ViRobot 20090619 2009.06.19 2009-06-19 0.43 -
Ikarus T3.1.01.59 2009.06.21.72900 2009-06-21 3.31 -
JiangMin 11.0.706 2009.06.21 2009-06-21 2.08 -
Kaspersky 5.5.10 2009.06.21 2009-06-21 0.09 -
KingSoft 2009.2.5.15 2009.6.21.21 2009-06-21 0.87 -
McAfee 5.3.00 5652 2009-06-20 5.75 -
Microsoft 1.4803 2009.06.21 2009-06-21 4.94 -
mks_vir 2.01 2009.06.19 2009-06-19 3.17 -
Norman 6.01.09 6.01.00 2009-06-19 4.01 -
Panda 9.05.01 2009.06.21 2009-06-21 2.37 -
Trend Micro 8.700-1004 6.210.12 2009-06-21 0.03 -
Quick Heal 10.00 2009.06.19 2009-06-19 1.23 -
Rising 20.0 21.34.62.00 2009-06-21 0.78 -
Sophos 2.87.1 4.42 2009-06-21 2.57 -
Sunbelt 5200 5200 2009-06-20 0.85 -
Symantec 1.3.0.24 20090620.025 2009-06-20 0.07 -
nProtect 20090621.01 4379863 2009-06-21 6.22 -
The Hacker 6.3.4.3 v00350 2009-06-20 0.67 -
VBA32 3.12.10.7 20090620.1443 2009-06-20 2.10 -
VirusBuster 4.5.11.10 10.107.19/1648057 2009-06-21 2.00 -
DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 14:28:00.39 on Sun 06/21/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3061.1906 [GMT -4:00] AV: a-squared Anti-Malware *On-access scanning enabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\a-squared Anti-Malware\a2service.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\PrevxCSI\prevxcsi.exe C:\Program Files\RemoteObserverClient\roclient.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe c:\WINDOWS\system32\ZuneBusEnum.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\Program Files\PrevxCSI\prevxcsi.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Lexmark 350 Series\ezprint.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\a-squared Anti-Malware\a2guard.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\TweetDeck\TweetDeck.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\SearchFilterHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Misterdad\Desktop\dds.pif C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080209 uStart Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080209 uInternet Connection Wizard,ShellNext = iexplore mWinlogon: UIHost=c:\documents and settings\all users\application data\tuneup software\tuneup utilities\winstyler\tu_logonui.exe BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll BHO: {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - No File BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll EB: Groove Folder Synchronization: {2a541ae1-5bf6-4665-a8a3-cfa9672e4291} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [BuildBU] c:\dell\bldbubg.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [EzPrint] "c:\program files\lexmark 350 series\ezprint.exe" mRun: [LXCVCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCVtime.dll,_RunDLLEntry@16 mRun: [Motive SmartBridge] c:\progra~1\sbcsel~1\smartb~1\MotiveSB.exe mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [a-squared] "c:\program files\a-squared anti-malware\a2guard.exe" /d=60 mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [] mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime StartupFolder: c:\docume~1\mister~2\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\at&tse~1.lnk - c:\program files\sbc self support tool\bin\matcli.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe mPolicies-system: EnableLUA = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000 IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Trusted Zone: turbotax.com DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll SEH: CRXShellExecuteHook Object: {1214fbe7-4464-4a7e-9958-b5851a7a30a3} - c:\program files\conceptworld\recentx\RXShell.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\mister~2\applic~1\mozilla\firefox\profiles\e35dewup.default\ FF - plugin: c:\documents and settings\misterdad\application data\mozilla\firefox\profiles\e35dewup.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdivx32.dll FF - plugin: c:\program files\mozilla firefox\plugins\npDivxPlayerPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npnul32.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPOFF12.DLL FF - plugin: c:\program files\mozilla firefox\plugins\nppdf32.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin3.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin4.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin5.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin6.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin7.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox 3.1 beta 3\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox 3.1 beta 3\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox 3.1 beta 3\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox 3.1 beta 3\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox 3.1 beta 3\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox 3.1 beta 3\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox 3.1 beta 3\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox 3.1 beta 3\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox 3.1 beta 3\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2008-5-20 15328] R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-3-26 22024] R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [2008-8-5 95592] R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared anti-malware\a2service.exe [2008-8-2 718880] R2 CSIScanner;CSIScanner;c:\program files\prevxcsi\prevxcsi.exe [2009-1-28 4414008] R2 roclient;roclient;c:\program files\remoteobserverclient\roclient.exe [2008-11-29 20480] R3 wsvad_driver;WS Audio Device;c:\windows\system32\drivers\VirtualAudio.sys [2008-11-20 16896] S2 lxcv_device;lxcv_device;c:\windows\system32\lxcvcoms.exe -service –> c:\windows\system32\lxcvcoms.exe -service [?] S2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\nbservice.exe –> c:\program files\common files\nero\nero backitup 4\NBService.exe [?] S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S3 BCASPROT;Advanced System Protector;\??\c:\program files\systweak\advanced system protector\sasprot32.sys –> c:\program files\systweak\advanced system protector\sasprot32.sys [?] S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [2008-6-2 31712] S3 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\macrium\reflect\ReflectService.exe [2008-6-2 216032] S3 wdm_opl3sax;YAMAHA OPL3-SAx Audio Driver (WDM);c:\windows\system32\drivers\opl3sax.sys [2009-3-2 54528] =============== Created Last 30 ================ 2009-06-19 06:27 2,285,056 a——- c:\windows\system32\TUKernel.exe 2009-06-19 06:13 28,416 a——- c:\windows\system32\uxtuneup.dll 2009-06-19 06:13 355,584 a——- c:\windows\system32\TuneUpDefragService.exe 2009-06-19 06:13 –d—– c:\docume~1\mister~2\applic~1\TuneUp Software 2009-06-19 06:12 –d—– c:\docume~1\alluse~1\applic~1\TuneUp Software 2009-06-19 06:12 –d—– c:\program files\TuneUp Utilities 2008 2009-06-19 06:12 –d—– c:\program files\common files\Wise Installation Wizard 2009-06-17 05:55 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll 2009-06-17 05:55 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll 2009-06-16 21:19 –d—– c:\program files\drweb 2009-06-13 13:10 –d—– c:\program files\EvilLyrics 2009-06-13 08:01 –d—– c:\docume~1\alluse~1\applic~1\MediaMonkey 2009-05-30 01:17 –d—– c:\docume~1\mister~2\applic~1\StarBurn 2009-05-30 01:15 –d—– c:\program files\Give Away Of The Day 2009-05-26 22:26 –d—– c:\docume~1\mister~2\applic~1\.freeciv 2009-05-26 22:25 –d—– c:\program files\Freeciv-2.1.9-gtk2 2009-05-24 00:35 –d—– c:\docume~1\mister~2\applic~1\Gold Wave Editor Pro 2009-05-24 00:35 –d—– c:\program files\Gold Wave Editor Pro 2009-05-22 19:58 –d—– C:\pebuilder313 2009-05-22 19:54 –d—– c:\program files\XP Recovery CD ==================== Find3M ==================== 2009-05-30 01:15 721,904 a——- c:\windows\system32\drivers\sptd.sys 2009-05-13 01:15 915,456 a——- c:\windows\system32\wininet.dll 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll 2009-04-17 08:26 1,847,168 a——- c:\windows\system32\win32k.sys 2009-04-15 10:51 585,216 a——- c:\windows\system32\rpcrt4.dll 2009-03-25 07:27 256 a——- c:\documents and settings\misterdad\pool.bin 2008-09-20 09:22 39,777,000 a——- c:\program files\EPMProSetup.exe 2008-06-30 07:52 49,384,056 a——- c:\program files\avg_free_stf_all_8_100a1323.exe 2008-06-17 00:10 105,761,704 a——- c:\program files\DAZStudio_2.2.2.15_win.exe 2008-06-01 22:14 3,558,791 a——- c:\program files\youtubedownloader.exe 2007-04-05 11:49 5,392,859 a——- c:\program files\DRWSetup.exe 2008-11-15 09:20 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008111520081116\index.dat ============= FINISH: 14:30:09.67 =============== DDS (Ver_09-05-14.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 7/8/2008 11:46:53 PM System Uptime: 6/21/2009 1:36:10 PM (1 hours ago) Motherboard: Dell Inc. | | 0RY007 Processor: Intel® Core™2 Duo CPU E6550 @ 2.33GHz | Socket 775 | 2327/333mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 462 GiB total, 137.015 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable I: is Removable K: is CDROM (CDFS) L: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318} Description: YAMAHA OPL3-SAx WDM Driver Device ID: ROOT\MEDIA\0000 Manufacturer: Yamaha Name: YAMAHA OPL3-SAx WDM Driver PNP Device ID: ROOT\MEDIA\0000 Service: wdm_opl3sax ==== System Restore Points =================== RP333: 3/23/2009 10:30:22 PM - System Checkpoint RP334: 3/27/2009 12:00:38 AM - System Checkpoint RP335: 3/29/2009 10:56:18 AM - System Checkpoint RP336: 4/3/2009 7:43:54 AM - System Checkpoint RP337: 4/3/2009 8:27:48 PM - Installed Nero 9 Trial 2.0.0.1 RP338: 4/3/2009 8:28:06 PM - Installed DirectX RP339: 4/4/2009 8:37:21 PM - System Checkpoint RP340: 4/5/2009 12:50:31 AM - Software Distribution Service 3.0 RP341: 4/6/2009 3:22:35 AM - System Checkpoint RP342: 4/7/2009 6:14:25 AM - Software Distribution Service 3.0 RP343: 4/7/2009 8:53:01 PM - Installed Windows Internet Explorer 8. RP344: 4/7/2009 8:54:10 PM - Software Distribution Service 3.0 RP345: 4/8/2009 9:06:36 PM - System Checkpoint RP346: 4/9/2009 6:29:22 PM - Uniblue RegistryBooster 2009 RP347: 4/10/2009 6:30:42 PM - System Checkpoint RP348: 4/11/2009 9:35:24 PM - System Checkpoint RP349: 4/12/2009 7:31:23 PM - testing RP350: 4/15/2009 6:59:27 PM - Installed TurboTax Deluxe 2007 RP351: 4/15/2009 7:01:19 PM - Installed AnswerWorks 4.0 Runtime - English RP352: 4/15/2009 8:53:38 PM - Installed TurboTax Deluxe 2007 RP353: 4/15/2009 8:55:38 PM - Installed AnswerWorks 4.0 Runtime - English RP354: 4/17/2009 8:28:55 PM - System Checkpoint RP355: 4/19/2009 8:55:56 AM - System Checkpoint RP356: 4/20/2009 6:31:21 PM - System Checkpoint RP357: 4/21/2009 9:36:23 PM - System Checkpoint RP358: 4/23/2009 9:27:47 PM - System Checkpoint RP359: 4/25/2009 9:32:41 PM - System Checkpoint RP360: 4/28/2009 7:37:16 PM - System Checkpoint RP361: 4/29/2009 8:14:15 PM - System Checkpoint RP362: 4/30/2009 11:30:24 PM - System Checkpoint RP363: 5/2/2009 7:16:41 PM - System Checkpoint RP364: 5/3/2009 9:57:54 AM - Software Distribution Service 3.0 RP365: 5/4/2009 7:27:48 PM - System Checkpoint RP366: 5/5/2009 11:22:49 PM - System Checkpoint RP367: 5/6/2009 5:27:44 AM - Advanced System Protector 5/6/2009 5:27:39 AM RP368: 5/6/2009 5:50:05 AM - Installed Java™ 6 Update 13 RP369: 5/6/2009 6:10:50 AM - Restore Operation RP370: 5/6/2009 10:29:57 PM - Removed Paint.NET v3.36 RP371: 5/6/2009 10:30:56 PM - Removed Nero 9 Trial 2.0.0.1 RP372: 5/9/2009 11:25:50 AM - System Checkpoint RP373: 5/11/2009 8:47:22 PM - System Checkpoint RP374: 5/14/2009 7:54:33 PM - System Checkpoint RP375: 5/14/2009 9:35:48 PM - Uniblue RegistryBooster 2009 RP376: 5/14/2009 9:45:30 PM - Uniblue RegistryBooster 2009 RP377: 5/16/2009 12:35:06 AM - System Checkpoint RP378: 5/17/2009 1:23:39 PM - System Checkpoint RP379: 5/18/2009 3:04:44 PM - System Checkpoint RP380: 5/20/2009 1:04:47 AM - System Checkpoint RP381: 5/21/2009 7:31:29 PM - System Checkpoint RP382: 5/22/2009 9:44:41 PM - System Checkpoint RP383: 5/23/2009 11:06:03 PM - System Checkpoint RP384: 5/25/2009 1:21:51 PM - System Checkpoint RP385: 5/27/2009 10:00:53 PM - System Checkpoint RP386: 5/29/2009 8:25:58 PM - System Checkpoint RP387: 5/30/2009 1:15:39 AM - SPTD setup V1.59 RP388: 5/31/2009 5:55:22 PM - System Checkpoint RP389: 6/1/2009 2:05:17 AM - Software Distribution Service 3.0 RP390: 6/2/2009 7:54:37 PM - System Checkpoint RP391: 6/3/2009 9:19:19 PM - System Checkpoint RP392: 6/4/2009 10:29:30 PM - System Checkpoint RP393: 6/6/2009 12:55:38 PM - System Checkpoint RP394: 6/7/2009 1:02:58 PM - System Checkpoint RP395: 6/9/2009 12:50:46 AM - System Checkpoint RP396: 6/10/2009 10:05:21 PM - System Checkpoint RP397: 6/11/2009 10:21:44 PM - System Checkpoint RP398: 6/12/2009 11:38:48 PM - System Checkpoint RP399: 6/14/2009 7:47:22 AM - System Checkpoint RP400: 6/15/2009 10:02:13 PM - System Checkpoint RP401: 6/17/2009 6:23:11 AM - Software Distribution Service 3.0 RP402: 6/18/2009 10:48:46 PM - System Checkpoint RP403: 6/19/2009 11:08:32 PM - System Checkpoint RP404: 6/21/2009 12:19:57 AM - System Checkpoint ==== Installed Programs ====================== 2007 Microsoft Office Suite Service Pack 1 (SP1) a-squared Anti-Malware 3.5 Acoolsoft PPT2Video Converter 1.6.1.13 Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.1.3 Advanced Audio Recorder v6.0.1 Advanced Font Viewer 4.2 All My Movies 4.9 GAOTD Almeza MultiSet Professional 6.3 AnswerWorks 4.0 Runtime - English Anvil Studio AnVir Task Manager AOLIcon Apple Mobile Device Support Apple Software Update AptEdit Pro 4.6 for Giveaway Ask Toolbar AT&T Self Support Tool Audacity 1.2.6 Audio Comparer Audio Editor Deluxe v9.5.1 AVS Video Editor 4 AVS4YOU Software Navigator 1.2 BlackBerry Desktop Software 4.3 BlackBerry Media Sync BlackBerry® Media Sync Bonjour Browser Address Error Redirector BusinessCardsMX 3.92 Conexant D850 56K V.9x DFVc Modem Coupon Printer for Windows Critical Update for Windows Media Player 11 (KB959772) Daniusoft Media Converter Pro(Build 2.3.1.0) Daniusoft Media Converter(Build [removed]) DebugMode Wax 2.0 DeductionPro 2008 Dell DataSafe Online Dell Driver Reset Tool Dell Support Center (Support Software) Dell System Restore Dexpot 1.4 Digital Line Detect DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Web Player Documentation & Support Launcher Drive Inventory Duplicate File Hunter 2.01 DV Network Software EarthLink Setup Files Edraw Max 4 EPSON Printer Software EPSON Scan ERUNT 1.1j EvilLyrics Extra DVD Ripper Express 4.54 FairStars CD Ripper 1.21 File Name Converter Finale SongWriter 2007 Folder Marker Home v 3.0 foobar2000 v0.9.6.2 beta 2 FreeStar Free DVD Ripper 1.0.3 Games, Music, & Photos Launcher Glary Utilities 2.10.0.622 Gold Wave Editor Pro v10.2.2 Google Desktop HammerHead Rhythm Station HijackThis 2.0.2 Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB952287) ImagXpress InfraRecorder Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers Internet Service Offers Launcher J2SE Runtime Environment 5.0 Update 6 Jane's Hotel Java™ 6 Update 5 JetDraft Document Suite 2008 1.20 KeyHoleTV Learn2 Player (Uninstall Only) Lexmark 350 Series Lexmark Toolbar Liquid Story Binder XE 2.92 Logitech Music Anywhere Settings Macrium Reflect MahJongg Malwarebytes' Anti-Malware MediaMonkey 3.0 Mega Manager Megaupload Toolbar Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft .NET Framework 3.0 Service Pack 1 Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.7 Microsoft Visual C++ 2005 Redistributable Microsoft WinUsb 1.0 Microsoft Works Modem Diagnostic Tool Move Networks Media Player for Internet Explorer Moyea Flash Video MX Std Version: 5.0.4.0 Mozilla Firefox (3.0.11) Mozilla Firefox (3.0.6) Mozilla Firefox (3.5b4) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) MusicBrainz Picard 0.11 neroxml NetWaiting NetZeroInstallers ObjectDock Opera 9.64 Paint.NET v3.36 Palm Outlook Conduits Updater palmOne PC Doc Pro PDF to Word PE Builder v3.1.3 Phantasia 2 1.02 PowerDVD Premium Booster PrimoPDF project dogwaffle Pure Sudoku 1.51 QuickTime RealPlayer Basic Realtek High Definition Audio Driver RecentX 2.0 Recover Keys RemoteObserver RemoteObserverClient reversudoku version 1.0 Rhapsody Rock Legend Roxio Creator Audio Roxio Creator BDAV Plugin Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Drag-to-Disc Roxio Express Labeler Roxio Media Manager Roxio Update Manager SearchAssist Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office OneNote 2007 (KB950130) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB950114) Security Update for Microsoft Office system 2007 (KB954326) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office Word 2007 (KB969604) Security Update for Step By Step Interactive Training (KB923723) Security Update for Visio 2007 (KB947590) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) ShellLess Explorer 1.07 Snood for Windows version 3.52-W Sonic Activation Module Sony ACID Music Studio 5.0 Sony ACID Music Studio 6.0b Sony ACID Music Studio 7.0 Sony Ericsson Media Manager 1.2 Sony Preset Manager 2.0d SopCast 3.0.3 SpeQ Mathematics 3.3 StarBurn(GiveAwayOfTheDay) Version 12 (Build 0x20090527) t@b ZS4 Video Editor v0.958-686 TaxCut Indiana 2008 TaxCut Premium + State + Efile 2008 Total Video Converter 3.12 080325 TuneUp Utilities 2008 TurboTax Deluxe 2007 TweetDeck Uniblue RegistryBooster 2009 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office Outlook 2007 (KB969907) Update for Outlook 2007 Junk Email Filter (kb970012) Update for Windows Internet Explorer 8 (KB968220) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) VC80CRTRedist - 8.0.50727.762 Viewpoint Media Player VST Bridge 1.1 WD Diagnostics WebFldrs XP WIDCOMM Bluetooth Software Windows Defender Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 11 Windows Presentation Foundation Windows XP Service Pack 3 Wondershare Flash Slideshow Builder Giveaway Edition (4.6.0) Wondershare Photo Collage Studio 4.2.8 XML Paper Specification Shared Components Pack 1.0 XP Recovery CD Maker (Trial Version) Zipeg Zune Zune Language Pack (ES) Zune Language Pack (FR) ==== Event Viewer Messages From Past Week ======== 6/21/2009 6:40:45 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001D0984827A. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. 6/19/2009 6:13:16 AM, error: Service Control Manager [7000] - The TuneUp Theme Extension service failed to start due to the following error: The executable program that this service is configured to run in does not implement the service. 6/17/2009 9:09:26 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer MARY that believes that it is the master browser for the domain on transport NetBT_Tcpip_{828D020D-B077-416D-9785. The master browser is stopping or an election is being forced. 6/17/2009 5:31:44 AM, error: Service Control Manager [7000] - The lxcv_device service failed to start due to the following error: The system cannot find the file specified. 6/17/2009 11:34:38 PM, error: PlugPlayManager [10] - Error writing to server side install pipe 6/16/2009 9:51:22 PM, error: Service Control Manager [7031] - The Zune Bus Enumerator service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/16/2009 9:51:13 PM, error: Service Control Manager [7031] - The Zune Bus Enumerator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/16/2009 9:51:04 PM, error: Service Control Manager [7034] - The CSIScanner service terminated unexpectedly. It has done this 1 time(s). 6/16/2009 9:27:53 PM, error: Service Control Manager [7034] - The lxcv_device service terminated unexpectedly. It has done this 1 time(s). 6/16/2009 9:27:44 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/16/2009 8:38:56 PM, error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23). 6/16/2009 8:25:14 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: An instance of the service is already running. 6/16/2009 8:24:44 PM, error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 6/16/2009 8:24:44 PM, error: Service Control Manager [7022] - The Windows Search service hung on starting. 6/15/2009 7:19:57 AM, error: PlugPlayManager [9] - Error writing to surprise removal pipe 6/14/2009 9:41:30 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/14/2009 2:59:14 PM, error: Service Control Manager [7000] - The Nero BackItUp Scheduler 4.0 service failed to start due to the following error: The system cannot find the file specified. 6/14/2009 2:59:14 PM, error: Service Control Manager [7000] - The MCSTRM service failed to start due to the following error: The system cannot find the file specified. ==== End Of File ===========================
Sorry, I've tried to and it has given me the blue screen of death twice saying PFN_LIST_CORRUPT - will try again. i do appreciate your time Thank you
OK,

Leave that for now - I suspect there is a rootkit on board causing havoc


Please do the following:

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
ComboFix 09-06-20.04 - Misterdad 06/21/2009 20:18.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3061.2413 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
.

((((((((((((((((((((((((( Files Created from 2009-05-22 to 2009-06-22 )))))))))))))))))))))))))))))))
.

2009-06-21 21:40 . 2009-04-28 23:05 286208 —-a-w- c:\documents and settings\Misterdad\Application Data\com.zipeg\100042\100043\gmer.exe
2009-06-21 18:39 . 2009-04-28 23:05 286208 ——w- c:\documents and settings\Misterdad\Application Data\com.zipeg\100040\100041\gmer.exe
2009-06-20 04:39 . 2009-06-20 04:39 4352000 —-a-w- c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe
2009-06-19 10:27 . 2009-06-19 10:27 2285056 —-a-w- c:\windows\system32\TUKernel.exe
2009-06-19 10:13 . 2008-05-29 13:28 28416 —-a-w- c:\windows\system32\uxtuneup.dll
2009-06-19 10:13 . 2009-06-19 10:13 355584 —-a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-19 10:13 . 2009-06-19 10:13 ——– d—–w- c:\documents and settings\Misterdad\Application Data\TuneUp Software
2009-06-19 10:12 . 2009-06-19 10:12 ——– d—–w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-06-19 10:12 . 2009-06-19 10:14 ——– d—–w- c:\program files\TuneUp Utilities 2008
2009-06-19 10:12 . 2009-06-19 10:12 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-17 09:55 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-06-17 09:55 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-17 01:19 . 2009-06-17 01:21 ——– d—–w- c:\program files\drweb
2009-06-13 17:10 . 2009-06-13 17:15 ——– d—–w- c:\program files\EvilLyrics
2009-06-13 12:15 . 2009-06-13 12:15 ——– d—–w- c:\documents and settings\Misterdad\Local Settings\Application Data\Apple
2009-06-13 12:01 . 2009-06-13 12:01 ——– d—–w- c:\documents and settings\All Users\Application Data\MediaMonkey
2009-05-30 05:17 . 2009-05-30 05:17 ——– d—–w- c:\documents and settings\Misterdad\Application Data\StarBurn
2009-05-30 05:15 . 2009-05-30 05:15 ——– d—–w- c:\program files\Give Away Of The Day
2009-05-27 02:26 . 2009-05-27 02:29 ——– d—–w- c:\documents and settings\Misterdad\Application Data\.freeciv
2009-05-27 02:25 . 2009-05-27 02:30 ——– d—–w- c:\program files\Freeciv-2.1.9-gtk2
2009-05-27 01:16 . 2009-05-27 01:16 ——– d—–w- c:\documents and settings\Misterdad\Local Settings\Application Data\Opera
2009-05-27 01:16 . 2009-05-27 01:16 ——– d—–w- c:\program files\Opera
2009-05-24 04:35 . 2009-05-24 04:36 ——– d—–w- c:\documents and settings\Misterdad\Application Data\Gold Wave Editor Pro
2009-05-24 04:35 . 2009-05-24 04:35 ——– d—–w- c:\program files\Gold Wave Editor Pro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 21:40 . 2009-01-31 18:48 ——– d—–w- c:\documents and settings\Misterdad\Application Data\com.zipeg
2009-06-21 18:40 . 2009-01-31 18:45 ——– d—–w- c:\documents and settings\Misterdad\Application Data\AptEdit Pro
2009-06-21 18:39 . 2009-01-18 00:41 ——– d—–w- c:\program files\Zipeg
2009-06-21 10:54 . 2008-08-02 10:20 ——– d—–w- c:\program files\a-squared Anti-Malware
2009-06-20 15:56 . 2009-04-19 12:34 ——– d—–w- c:\documents and settings\Misterdad\Application Data\U3
2009-06-17 10:30 . 2008-02-25 11:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-17 10:28 . 2008-02-09 05:11 ——– d—–w- c:\program files\Microsoft Works
2009-06-17 01:13 . 2008-06-30 01:07 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-14 21:03 . 2009-03-21 11:36 ——– d—–w- c:\program files\Mozilla Firefox 3.1 Beta 3
2009-06-13 12:16 . 2008-02-21 00:40 ——– d—–w- c:\program files\Common Files\Apple
2009-05-31 04:08 . 2008-04-06 03:32 ——– d—–w- c:\program files\Lx_cats
2009-05-30 05:15 . 2008-08-05 11:42 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-05-30 05:09 . 2008-08-09 11:12 ——– d—–w- c:\program files\Realore
2009-05-23 08:03 . 2009-04-13 03:27 ——– d—–w- c:\documents and settings\Misterdad\Application Data\foobar2000
2009-05-22 23:56 . 2009-05-22 23:54 ——– d—–w- c:\program files\XP Recovery CD
2009-05-18 00:38 . 2009-05-18 00:38 ——– d—–w- c:\documents and settings\Emma\Application Data\Apple Computer
2009-05-18 00:25 . 2009-05-18 00:25 ——– d—–w- c:\documents and settings\Emma\Application Data\ArcticLine
2009-05-18 00:25 . 2009-05-18 00:24 83760 —-a-w- c:\documents and settings\Emma\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-18 00:25 . 2009-05-18 00:25 ——– d—–w- c:\documents and settings\Emma\Application Data\Windows Desktop Search
2009-05-18 00:24 . 2009-05-18 00:24 ——– d—–w- c:\documents and settings\Emma\Application Data\InstallShield
2009-05-17 12:17 . 2009-05-17 12:17 ——– d—–w- c:\program files\MusicBrainz Picard
2009-05-15 22:25 . 2009-05-15 22:21 ——– d—–w- c:\documents and settings\Misterdad\Application Data\InfraRecorder
2009-05-15 22:07 . 2009-05-15 22:07 ——– d—–w- c:\program files\InfraRecorder
2009-05-15 01:43 . 2009-01-17 14:57 ——– d—–w- c:\documents and settings\Dad.GIPPER\Application Data\MegauploadToolbar
2009-05-13 05:15 . 2006-03-04 03:33 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-12 02:06 . 2009-05-12 02:06 ——– d—–w- c:\program files\t@b
2009-05-10 05:06 . 2008-06-22 22:42 ——– d—–w- c:\program files\DivX
2009-05-10 05:06 . 2009-05-10 05:05 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-05-10 04:35 . 2009-05-10 04:35 ——– d—–w- c:\program files\DebugMode
2009-05-07 15:32 . 2004-08-04 10:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-07 02:47 . 2009-04-04 00:28 ——– d—–w- c:\program files\Common Files\Nero
2009-05-07 02:47 . 2009-04-04 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2009-05-07 02:38 . 2009-04-04 00:28 ——– d—–w- c:\program files\Nero
2009-05-07 02:21 . 2008-06-02 02:14 ——– d—–w- c:\program files\YouTube Downloader
2009-05-06 10:20 . 2009-05-05 02:18 ——– d—–w- c:\documents and settings\Misterdad\Application Data\Systweak
2009-05-06 10:20 . 2009-05-05 02:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Systweak
2009-05-05 00:38 . 2009-05-05 00:38 ——– d—–w- c:\documents and settings\Mom.GIPPER\Application Data\Template
2009-05-05 00:38 . 2009-05-05 00:38 0 —-a-w- c:\documents and settings\Mom.GIPPER\Application Data\wklnhst.dat
2009-05-05 00:17 . 2009-05-05 00:17 ——– d—–w- c:\documents and settings\Mom.GIPPER\Application Data\Intuit
2009-05-05 00:06 . 2009-04-13 00:47 ——– d—–w- c:\documents and settings\Mom.GIPPER\Application Data\MEGAUPLOADTOOLBAR
2009-04-25 02:37 . 2009-04-25 02:37 ——– d—–w- c:\documents and settings\Misterdad\Application Data\CyberLink
2009-04-17 12:26 . 2004-08-04 10:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 10:00 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-15 10:44 . 2009-04-15 10:41 29813256 —-a-w- c:\documents and settings\All Users\Application Data\TaxCut\2008\Update\US68017101cupd.exe
2009-04-13 00:47 . 2009-04-13 00:47 1059112 —-a-w- c:\documents and settings\Mom.GIPPER\Application Data\MEGAUPLOADTOOLBAR\megauper.exe
2009-04-13 00:47 . 2008-03-02 23:41 83760 —-a-w- c:\documents and settings\Mom.GIPPER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-26 11:12 . 2009-03-26 11:12 22024 —-a-w- c:\windows\system32\drivers\pxscan.sys
2009-03-26 11:12 . 2009-03-26 11:12 1016888 —-a-w- c:\documents and settings\All Users\Application Data\PrevxCSI\~PrevxCSIUpdate.exe
2009-03-25 11:27 . 2009-03-25 11:27 256 —-a-w- c:\documents and settings\Misterdad\pool.bin
2008-09-20 13:22 . 2008-09-27 04:02 39777000 —-a-w- c:\program files\EPMProSetup.exe
2008-06-30 11:52 . 2008-06-30 11:52 49384056 —-a-w- c:\program files\avg_free_stf_all_8_100a1323.exe
2008-06-17 04:10 . 2008-06-17 04:09 105761704 —-a-w- c:\program files\DAZStudio_2.2.2.15_win.exe
2008-06-02 02:14 . 2008-06-02 02:13 3558791 —-a-w- c:\program files\youtubedownloader.exe
2007-04-05 15:49 . 2008-06-18 22:04 5392859 —-a-w- c:\program files\DRWSetup.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 22:20 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"BuildBU"="c:\dell\bldbubg.exe" [2004-02-19 61440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"EzPrint"="c:\program files\Lexmark 350 Series\ezprint.exe" [2006-06-07 98304]
"LXCVCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCVtime.dll" [2006-06-07 106496]
"Motive SmartBridge"="c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008]
"a-squared"="c:\program files\a-squared Anti-Malware\a2guard.exe" [2009-06-08 3207824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-07-17 16132608]

c:\documents and settings\Mom.GIPPER\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-7-12 3450608]

c:\documents and settings\Dad.GIPPER\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-7-12 3450608]

c:\documents and settings\Misterdad\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AT&T Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2008-4-9 217088]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-12 581693]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-2-9 24576]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
"{1214FBE7-4464-4A7E-9958-B5851A7A30A3}"= "c:\program files\Conceptworld\RecentX\RXShell.dll" [2008-06-12 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Music Anywhere Settings.lnk]
backup=c:\windows\pss\Logitech Music Anywhere Settings.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\KeyHoleTV\\KeyHoleTV.exe"=
"c:\\Program Files\\MusicBrainz Picard\\picard.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020

R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [5/20/2008 9:32 AM 15328]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [3/26/2009 7:12 AM 22024]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [8/5/2008 7:41 AM 95592]
R2 CSIScanner;CSIScanner;c:\program files\PrevxCSI\prevxcsi.exe [1/28/2009 6:26 PM 4414008]
R2 roclient;roclient;c:\program files\RemoteObserverClient\roclient.exe [11/29/2008 4:25 AM 20480]
R3 wsvad_driver;WS Audio Device;c:\windows\system32\drivers\VirtualAudio.sys [11/20/2008 8:19 AM 16896]
S2 lxcv_device;lxcv_device;c:\windows\system32\lxcvcoms.exe -service –> c:\windows\system32\lxcvcoms.exe -service [?]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 BCASPROT;Advanced System Protector;\??\c:\program files\Systweak\Advanced System Protector\sasprot32.sys –> c:\program files\Systweak\Advanced System Protector\sasprot32.sys [?]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [6/2/2008 3:18 PM 31712]
S3 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [6/2/2008 3:18 PM 216032]
S3 wdm_opl3sax;YAMAHA OPL3-SAx Audio Driver (WDM);c:\windows\system32\drivers\opl3sax.sys [3/2/2009 3:44 PM 54528]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-21 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 13:09]

2009-06-21 c:\windows\Tasks\User_Feed_Synchronization-{BAD218A1-28FB-4D17-BC55-F112DF0B4F14}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]

2009-06-22 c:\windows\Tasks\User_Feed_Synchronization-{BFC5CEED-823F-4CBD-BE53-150548429D0E}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]

2008-02-14 c:\windows\Tasks\Windows Media Player.job
- c:\progra~1\WINDOW~2\wmplayer.exe [2004-08-10 20:27]
.
- - - - ORPHANS REMOVED - - - -

BHO-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080209
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
Trusted Zone: turbotax.com
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath -

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-21 20:30
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCVCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCVtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Setup"="0208710-033E-7DA2-C704-4032"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3272)
c:\windows\system32\WININET.dll
c:\progra~1\SBCSEL~1\SMARTB~1\SBHook.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\a-squared Anti-Malware\a2service.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\SBC Self Support Tool\bin\mpbtn.exe
c:\program files\Common Files\InstallShield\UpdateService\agent.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Completion time: 2009-06-22 20:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-22 00:38

Pre-Run: 148,996,300,800 bytes free
Post-Run: 155,531,051,008 bytes free

301 — E O F — 2009-06-17 10:31
Hi,

Please do the following:

please do the following
Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Malwarebytes' Anti-Malware 1.38 Database version: 2319 Windows 5.1.2600 Service Pack 3 6/21/2009 9:43:25 PM mbam-log-2009-06-21 (21-43-25).txt Scan type: Quick Scan Objects scanned: 137621 Time elapsed: 3 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\END (Trojan.FakeAlert) -> Quarantined and deleted successfully. about to run kapersky - thank you for your help
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Monday, June 22, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Monday, June 22, 2009 03:31:15 Records in database: 2375814 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ Scan statistics: Files scanned: 944157 Threat name: 4 Infected objects: 5 Suspicious objects: 0 Duration of the scan: 06:42:31 File name / Threat name / Threats count C:\Documents and Settings\Dad.GIPPER\Desktop\Installers\ATT_SST_Installer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b 2 C:\Documents and Settings\Misterdad\Desktop\old t\perfect keylogger lite\bpk.exe Infected: not-a-virus:Monitor.Win32.Perflogger.a 1 C:\Documents and Settings\Misterdad\Desktop\old t\perfect keylogger lite\bsdhooks.dll Infected: Trojan.Win32.Agent.bmd 1 C:\Program Files\AnVir Task Manager\AnVir.exe Infected: Backdoor.Win32.Hupigon.gnnw 1 The selected area was scanned.
Hi,

using windows explorer (windows key +E) navigate to the following file and delete it (right click > delete)

C:\Program Files\AnVir Task Manager\AnVir.exe


Then remove the perfect keylogger lite program from Add/Remove programs and delete any leftover "perfect keylogger lite" folder from your Program Files.

Then Post a fresh HJT log and advise how your computer is running now.
Things seem to be going well - here is the HJT file. Thank you


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:10:20 PM, on 6/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Program Files\RemoteObserverClient\roclient.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lexmark 350 Series\ezprint.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080209
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080209
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 350 Series\ezprint.exe"
O4 - HKLM\..\Run: [LXCVCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCVtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: lxcv_device - Unknown owner - C:\WINDOWS\system32\lxcvcoms.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: roclient - Unknown owner - C:\Program Files\RemoteObserverClient\roclient.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

–
End of file - 10761 bytes
Hi,

The log is clean, just a couple of housekeeping items left to do:


Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

NEXT

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer. (version 6, update 14)


NEXT

Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT


Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Thank you very much - this can be considered closed, and my computer better protected thanks to the time you've taken. have a great day

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI