This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Registry problems

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

6 wks ago I accepted an Adobe Reader update. 2-3 days later the computer started acting abnormally, though no viruses showed up. I downloaded a "Eusing Registry Mechanic" (free) and ran it, it ID'd 298 problems and fixed them. However, I then ran Disk Cleanup, and it wiped out every last bit of data & documents I had. Our IT guy at work was able to do a Restore and gave me a newer version of Office, though my data was still lost. I then changed my antivirus software from AVG & Malwarebytes to PC Tools Anti-Virus and PC Tools FIrewall ("Threatfire"). However, these programs kept producing error messages and wiped out email attachments, so I went back to AVG/Malware. 2 days ago I downloaded and installed Vista SP!, and attempted to reboot after installation. I got a black screen with the following: "!! oxcolaoold !! 9396/98775 (c\Registry\Machine\Components)" I tried again and got the same message, but with the numbers 37391/98775 instead. When I rebooted with "Startup Repair," it allowed me to do a restore. Currently am operating normally, but I still think my registry is messed up. HijackThis log file is attached. Thanks very much. (I did not reboot due to AVG: please advise if I should run another log)
Hi MearsMan,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
      O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
      O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
      O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
      O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Tomk,

Many thanks for your help. Couple of observations before I post your requested info: 1. "Attach" shows Ad-Aware as installed, but I uninstalled it a long time ago. 2. "DDS" shows Trend Microvirus and Lavasoft at top: both uninstalled a long time ago. 3. The Windows Defender disable instructions did not match my Windows Defender options, I hope I turned it off correctly.

Here is the DDS.txt report:


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:43:45.34 on Mon 07/06/2009
Internet Explorer: 7.0.6000.16851 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1918.1225 [GMT -4:00]

AV: Trend Micro AntiVirus - Virus Protection *On-access scanning enabled* (Updated) {9596F8E6-38C3-4C51-80B9-8C94D2E25B07}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Trend Micro AntiVirus - Spyware Protection *enabled* (Updated) {7241C815-3D0F-4059-9AF4-BF225B1D78B9}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\hp\kbd\kbd.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\Tomas de Torquemada\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://broadband.zoomtown.com
mStart Page = hxxp://broadband.zoomtown.com
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\tomasd~1\appdata\roaming\mozilla\firefox\profiles\6ar7u071.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.catholicculture.org/culture/liturgicalyear/
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-21 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-22 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-22 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-22 298776]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\AAWService.exe [?]

=============== Created Last 30 ================

2009-06-30 17:55 –d—– c:\program files\Trend Micro
2009-06-28 01:44 –d—– C:\PerfLogs
2009-06-27 22:24 –d—– C:\b144cf093e9e7c9bcf1b
2009-06-25 17:32 –d—– c:\program files\Microsoft
2009-06-24 22:55 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-24 22:55 97,800 a——- c:\windows\system32\infocardapi.dll
2009-06-24 22:55 622,080 a——- c:\windows\system32\icardagt.exe
2009-06-24 22:55 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2009-06-24 22:55 37,384 a——- c:\windows\system32\infocardcpl.cpl
2009-06-24 22:55 11,264 a——- c:\windows\system32\icardres.dll
2009-06-24 22:55 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2009-06-24 22:55 326,160 a——- c:\windows\system32\PresentationHost.exe
2009-06-24 22:44 96,760 a——- c:\windows\system32\dfshim.dll
2009-06-24 22:44 282,112 a——- c:\windows\system32\mscoree.dll
2009-06-24 22:43 41,984 a——- c:\windows\system32\netfxperf.dll
2009-06-24 22:43 158,720 a——- c:\windows\system32\mscorier.dll
2009-06-24 22:43 83,968 a——- c:\windows\system32\mscories.dll
2009-06-24 22:36 696,832 a——- c:\windows\system32\localspl.dll
2009-06-24 22:36 2,028,032 a——- c:\windows\system32\win32k.sys
2009-06-24 22:35 788,992 a——- c:\windows\system32\rpcrt4.dll
2009-06-23 08:44 –d-h— C:\$AVG8.VAULT$
2009-06-22 09:30 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-06-22 09:30 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-06-22 09:30 327,688 a——- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 09:30 –d—– c:\windows\system32\drivers\Avg
2009-06-22 09:30 –d—– c:\programdata\AVG Security Toolbar
2009-06-22 09:30 –d—– c:\progra~2\AVG Security Toolbar
2009-06-22 09:29 –d—– c:\program files\AVG
2009-06-17 21:55 –d—– c:\users\tomas de torquemada\{f3ac81ae-0593-4ff7-90fc-fce7e128dee5}
2009-06-13 21:14 428,032 a——- c:\windows\system32\EncDec.dll
2009-06-13 21:14 217,088 a——- c:\windows\system32\psisrndr.ax
2009-06-13 21:14 292,352 a——- c:\windows\system32\psisdecd.dll
2009-06-13 21:14 1,244,672 a——- c:\windows\system32\mcmde.dll
2009-06-13 21:14 177,152 a——- c:\windows\system32\mpg2splt.ax
2009-06-13 21:14 68,608 a——- c:\windows\system32\Mpeg2Data.ax
2009-06-13 21:14 80,896 a——- c:\windows\system32\MSNP.ax
2009-06-13 21:14 57,856 a——- c:\windows\system32\MSDvbNP.ax
2009-06-10 15:26 –d—– c:\users\tomasd~1\appdata\roaming\PCToolsFirewallPlus
2009-06-10 15:21 –d—– c:\program files\ThreatFire
2009-06-09 22:19 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-09 22:19 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-09 22:19 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-09 18:17 a-d—– c:\programdata\TEMP
2009-06-09 18:17 –d—– c:\program files\common files\PC Tools
2009-06-06 14:30 213 a——- c:\windows\Quicken.ini
2009-06-06 14:30 –d—– c:\program files\common files\Palo Alto Software
2009-06-06 14:30 –d—– c:\program files\common files\Intuit

==================== Find3M ====================

2009-06-25 17:35 86,016 a——- c:\windows\inf\infstrng.dat
2009-06-25 17:35 51,200 a——- c:\windows\inf\infpub.dat
2009-06-25 17:34 86,016 a——- c:\windows\inf\infstor.dat
2009-04-24 12:22 827,392 a——- c:\windows\system32\wininet.dll
2009-04-24 12:14 56,320 a——- c:\windows\system32\iesetup.dll
2009-04-24 12:14 78,336 a——- c:\windows\system32\ieencode.dll
2009-04-24 12:14 52,736 a——- c:\windows\apppatch\iebrshim.dll
2009-04-24 12:11 72,704 a——- c:\windows\system32\admparse.dll
2009-04-24 09:53 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-04-24 08:25 48,128 a——- c:\windows\system32\mshtmler.dll
2009-04-11 17:49 410,984 a——- c:\windows\system32\deploytk.dll
2008-12-11 07:32 174 a–sh— c:\program files\desktop.ini
2008-06-12 07:53 665,600 a——- c:\windows\inf\drvindex.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2007-08-25 15:37 22 a–sh— c:\windows\sminst\HPCD.sys

============= FINISH: 10:44:23.37 ===============

The Attach.txt file is uploaded. Thanks.

Attachments:

MearsMan,

Ad-Aware still shows in your uninstall list.

Please go to Add or Remove programs in your control panel. Select Ad-Aware and uninstall it.

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
Tomk Am unable to uninstall Ad-Aware. I get this message: "Ad-Aware Installation package has stopped working." Then it gives me 2 options: check on-line for a solution and close the program, or close the program. Checking on-line yields no response. Should I go ahead and proceed with the rest of your instructions anyway, or try to uninstall some other way? (please advise what other way - e.g. REVO Uninstaller?)
Tomk Results of GooredFix: GooredFix by jpshortstuff (03.07.09) Log created at 12:31 on 06/07/2009 (Tomas de Torquemada) Firefox version 3.0.11 (en-US) ========== GooredScan ========== Results of Rooter: Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully … . Windows Vista Home Edition (6.0.6000) [32_bits] - x86 Family 15 Model 107 Stepping 1, AuthenticAMD . [wscsvc] (Security Center) RUNNING (state:4) [MpsSvc] RUNNING (state:4) Windows Firewall -> Enabled Windows Defender -> Enabled User Account Control (UAC) -> Disabled ! . Internet Explorer 7.0.6000.16851 Mozilla Firefox 3.0.11 (en-US) . C:\ [Fixed-NTFS] .. ( Total:289 Go - Free:261 Go ) D:\ [Fixed-NTFS] .. ( Total:8 Go - Free:0 Go ) E:\ [CD_Rom] F:\ [Removable] G:\ [Removable] H:\ [Removable] I:\ [Removable] J:\ [Removable] . Scan : 12:33.50 Path : C:\Users\Tomas de Torquemada\Desktop\Rooter.exe User : Tomas de Torquemada ( Administrator -> YES ) . ———————-\\ Processes . Locked [System Process] (0) Locked System (4) ______ \SystemRoot\System32\smss.exe (472) ______ C:\Windows\system32\csrss.exe (548) ______ C:\Windows\system32\wininit.exe (596) ______ C:\Windows\system32\csrss.exe (608) ______ C:\Windows\system32\services.exe (648) ______ C:\Windows\system32\lsass.exe (660) ______ C:\Windows\system32\lsm.exe (672) ______ C:\Windows\system32\winlogon.exe (796) ______ C:\Windows\system32\svchost.exe (856) ______ C:\Windows\system32\nvvsvc.exe (896) ______ C:\Windows\system32\svchost.exe (924) ______ C:\Windows\System32\svchost.exe (972) ______ C:\Windows\System32\svchost.exe (1048) ______ C:\Windows\System32\svchost.exe (1072) ______ C:\Windows\system32\svchost.exe (1104) Locked audiodg.exe (1260) ______ C:\Windows\system32\SLsvc.exe (1292) ______ C:\Windows\system32\svchost.exe (1336) ______ C:\Windows\system32\rundll32.exe (1400) ______ C:\Windows\system32\svchost.exe (1516) ______ C:\Windows\System32\spoolsv.exe (1688) ______ C:\Windows\system32\svchost.exe (1712) ______ C:\Windows\system32\taskeng.exe (396) ______ C:\Windows\system32\Dwm.exe (392) ______ C:\Windows\Explorer.EXE (616) ______ C:\Program Files\Windows Defender\MSASCui.exe (1452) ______ C:\hp\support\hpsysdrv.exe (720) ______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (1892) ______ C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (1796) ______ C:\Windows\RtHDVCpl.exe (2076) ______ c:\Program Files\Common Files\LightScribe\LSSrvc.exe (2096) ______ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (2196) ______ C:\Windows\system32\svchost.exe (2292) ______ C:\Windows\system32\svchost.exe (2344) ______ C:\Program Files\Java\jre6\bin\jusched.exe (2380) ______ C:\Windows\System32\svchost.exe (2424) ______ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2468) ______ C:\Windows\system32\SearchIndexer.exe (2540) ______ C:\Program Files\AVG\AVG8\avgtray.exe (2548) ______ C:\Windows\system32\DRIVERS\xaudio.exe (2612) ______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (2700) ______ C:\PROGRA~1\AVG\AVG8\avgnsx.exe (2716) ______ C:\Program Files\AVG\AVG8\avgcsrvx.exe (2772) ______ C:\Windows\system32\WUDFHost.exe (3244) ______ C:\Windows\system32\taskeng.exe (3260) ______ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (3428) ______ C:\Windows\system32\wbem\unsecapp.exe (3736) ______ C:\Windows\system32\wbem\wmiprvse.exe (3800) ______ C:\hp\kbd\kbd.exe (2808) ______ C:\Users\Tomas de Torquemada\Desktop\GooredFix.exe (2128) ______ C:\Windows\system32\SearchProtocolHost.exe (2744) ______ C:\Windows\system32\SearchFilterHost.exe (3856) ______ C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE (2020) ______ C:\Program Files\AVG\AVG8\avgcsrvx.exe (2216) ______ C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE (1704) ______ C:\Windows\system32\SearchProtocolHost.exe (2484) ______ C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe (3372) ______ C:\Windows\system32\wbem\wmiprvse.exe (1468) ______ C:\Windows\servicing\TrustedInstaller.exe (3948) ______ C:\Users\Tomas de Torquemada\Desktop\Rooter.exe (3148) . ———————-\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:32256 | Length:310640730624) \Device\Harddisk0\Partition2 (Start_Offset:310640762880 | Length:9429073920) . ———————-\\ Scheduled Tasks . C:\Windows\Tasks\Ad-Aware Update (Weekly).job C:\Windows\Tasks\SA.DAT C:\Windows\Tasks\SCHEDLGU.TXT . ———————-\\ Registry . . ———————-\\ Files & Folders . ———————-\\ Scan completed at 12:33.50 . C:\Rooter$\Rooter_1.txt - (06/07/2009 | 12:33.50)
That was it. I just tried to run it again but it said the program stopped working. Should I download again and run again?
Tomk DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:55:22.65 on Mon 07/06/2009 Internet Explorer: 7.0.6000.16851 BrowserJavaVersion: 1.6.0_13 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1918.1232 [GMT -4:00] AV: Trend Micro AntiVirus - Virus Protection *On-access scanning enabled* (Updated) {9596F8E6-38C3-4C51-80B9-8C94D2E25B07} AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: Trend Micro AntiVirus - Spyware Protection *enabled* (Updated) {7241C815-3D0F-4059-9AF4-BF225B1D78B9} ============== Running Processes =============== And I've uploaded the Attach report. Thanks again. C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\hp\support\hpsysdrv.exe C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\mobsync.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\hp\kbd\kbd.exe C:\Users\Tomas de Torquemada\Desktop\Anti-Virus\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://broadband.zoomtown.com mStart Page = hxxp://broadband.zoomtown.com mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [KBD] c:\hp\kbd\KbdStub.EXE mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe" mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-system: EnableLUA = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll AppInit_DLLs: avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\tomasd~1\appdata\roaming\mozilla\firefox\profiles\6ar7u071.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.catholicculture.org/culture/liturgicalyear/ FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-21 64160] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-22 327688] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-22 108552] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-22 298776] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808] =============== Created Last 30 ================ 2009-07-06 12:43 –d—– c:\program files\VS Revo Group 2009-07-06 12:33 –d—– C:\Rooter$ 2009-06-30 17:55 –d—– c:\program files\Trend Micro 2009-06-28 01:44 –d—– C:\PerfLogs 2009-06-27 22:24 –d—– C:\b144cf093e9e7c9bcf1b 2009-06-25 17:32 –d—– c:\program files\Microsoft 2009-06-24 22:55 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2009-06-24 22:55 97,800 a——- c:\windows\system32\infocardapi.dll 2009-06-24 22:55 622,080 a——- c:\windows\system32\icardagt.exe 2009-06-24 22:55 43,544 a——- c:\windows\system32\PresentationHostProxy.dll 2009-06-24 22:55 37,384 a——- c:\windows\system32\infocardcpl.cpl 2009-06-24 22:55 11,264 a——- c:\windows\system32\icardres.dll 2009-06-24 22:55 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll 2009-06-24 22:55 326,160 a——- c:\windows\system32\PresentationHost.exe 2009-06-24 22:44 96,760 a——- c:\windows\system32\dfshim.dll 2009-06-24 22:44 282,112 a——- c:\windows\system32\mscoree.dll 2009-06-24 22:43 41,984 a——- c:\windows\system32\netfxperf.dll 2009-06-24 22:43 158,720 a——- c:\windows\system32\mscorier.dll 2009-06-24 22:43 83,968 a——- c:\windows\system32\mscories.dll 2009-06-24 22:36 696,832 a——- c:\windows\system32\localspl.dll 2009-06-24 22:36 2,028,032 a——- c:\windows\system32\win32k.sys 2009-06-24 22:35 788,992 a——- c:\windows\system32\rpcrt4.dll 2009-06-23 08:44 –d-h— C:\$AVG8.VAULT$ 2009-06-22 09:30 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-06-22 09:30 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-06-22 09:30 327,688 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-22 09:30 –d—– c:\windows\system32\drivers\Avg 2009-06-22 09:30 –d—– c:\programdata\AVG Security Toolbar 2009-06-22 09:30 –d—– c:\progra~2\AVG Security Toolbar 2009-06-22 09:29 –d—– c:\program files\AVG 2009-06-17 21:55 –d—– c:\users\tomas de torquemada\{f3ac81ae-0593-4ff7-90fc-fce7e128dee5} 2009-06-13 21:14 428,032 a——- c:\windows\system32\EncDec.dll 2009-06-13 21:14 217,088 a——- c:\windows\system32\psisrndr.ax 2009-06-13 21:14 292,352 a——- c:\windows\system32\psisdecd.dll 2009-06-13 21:14 1,244,672 a——- c:\windows\system32\mcmde.dll 2009-06-13 21:14 177,152 a——- c:\windows\system32\mpg2splt.ax 2009-06-13 21:14 68,608 a——- c:\windows\system32\Mpeg2Data.ax 2009-06-13 21:14 80,896 a——- c:\windows\system32\MSNP.ax 2009-06-13 21:14 57,856 a——- c:\windows\system32\MSDvbNP.ax 2009-06-10 15:26 –d—– c:\users\tomasd~1\appdata\roaming\PCToolsFirewallPlus 2009-06-09 22:19 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-09 22:19 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-09 22:19 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-06-09 18:17 a-d—– c:\programdata\TEMP 2009-06-09 18:17 –d—– c:\program files\common files\PC Tools ==================== Find3M ==================== 2009-06-25 17:35 86,016 a——- c:\windows\inf\infstrng.dat 2009-06-25 17:35 51,200 a——- c:\windows\inf\infpub.dat 2009-06-25 17:34 86,016 a——- c:\windows\inf\infstor.dat 2009-04-24 12:22 827,392 a——- c:\windows\system32\wininet.dll 2009-04-24 12:14 56,320 a——- c:\windows\system32\iesetup.dll 2009-04-24 12:14 78,336 a——- c:\windows\system32\ieencode.dll 2009-04-24 12:14 52,736 a——- c:\windows\apppatch\iebrshim.dll 2009-04-24 12:11 72,704 a——- c:\windows\system32\admparse.dll 2009-04-24 09:53 26,624 a——- c:\windows\system32\ieUnatt.exe 2009-04-24 08:25 48,128 a——- c:\windows\system32\mshtmler.dll 2009-04-11 17:49 410,984 a——- c:\windows\system32\deploytk.dll 2008-12-11 07:32 174 a–sh— c:\program files\desktop.ini 2008-06-12 07:53 665,600 a——- c:\windows\inf\drvindex.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2007-08-25 15:37 22 a–sh— c:\windows\sminst\HPCD.sys ============= FINISH: 17:56:14.00 ===============

Attachments:

MearsMan,

OK. Let's run one more tool.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
TomK, ComboFix opened and immediately gave me this dialogue box: "ComboFix has detected the following real time scanners to be active: antivirus: Trend MicroAntivirus - Virus Protection antispyware: AVG Anti-Virus Free " " " : Lavasoft Ad-Watch Live " " " : Trend Micro Antivirus - Spyware Protection." Then there is a warning about potential damage to my machine if I continue without disabling these scanners, ending with "Please disable these scanners before checking OK." Unfortunately, I uninstalled Trend (both) almost a year ago; I uninstalled Lavasoft, which would not uninstall in the Control Panel, with REVO uninstaller (or so I thought) a couple of days ago, and I've turned off the AVG Resident Shield as instructed. What now? Thanks!
MearsMan,

We will run it in a special way to bypass those security programs.


Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Tomk, Before I try your latest instruction, another glitch occurred with combofix. I attempted to close the dialogue box without checking OK, so it wouldn't run (since it implied it might damage my machine with the scanner programs still running). It told me that it would go ahead and run, at my own risk, so rather than do that, I deleted the icon and restarted the computer. After restart, when my desktop reappeared, the desktop picture I had was gone, and the background was/is solid black. I have since attempted to re-establish the desktop image I had before, but the image shows as a blank in the "Change Desktop Appearance" box, and does not change the black desktop when I select the "blank" picture. However, if I select Preview, the picture shows. I've tried to re-establish the desktop image using both the image I have stored on my machine, as well as the same image stored on a data stick - no luck. How do I get my desktop image back? Second question: shouldn't I try to find out why Trend Microvirus and Ad-Aware Ad Watch are still running, when they've been uninstalled? Could this be the cause of all the weird problems I've been having? Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI