This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] "Your System Is Infected" Wallpaper that won

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been hit with something that attacked my system when I went to open and fill out a "User Survey" for the HP Online Support website.

"Your System is Infected!
System has been stopped due to a serious malfunction.
Spyware activity has been detected."

It is recomended to use spyware removal tool to prevent data loss.
Do not use the computer before all spyware removed."

This is the same poor spelling Exactly as it appears in the immovable wallpaper.

I started a thread in the "Windows Help" area, and have now moved over here for more in-depth assistance.

Symptoms"
- Wallpaper, as quoted above
- Internet Connection Options that get changed to "Use Proxy Server" when none is needed, thus severing internet access for MSIE and many updates
- Random, "numbers-based" install files trying to start up, that WinPatrol helps me to prevent.

I'm running a HJT log (with AVG and Windows Defender disabled). Posting here:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:32:03, on 09-Jul-09
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskswitch.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Accessories\WinPatrol\winpatrol.exe
C:\Program Files\Accessories\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
C:\PROGRAM FILES\NORTON GHOST\AGENT\VPROTRAY.EXE
C:\PROGRAM FILES\JAVA\JRE6\BIN\JUSCHED.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5656
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program

Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common

Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program

Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\Accessories\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\Accessories\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Accessories\WinCustomize\BootSkin\BootSkin.exe"

/StartupJobs
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User

'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User

'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User

'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User

'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User

'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User

'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/…b?1245900804640
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/microsoftupdat…b?1245941092593
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) -

http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. -

C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common

Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program

Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program

Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program

Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company

- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe

–
End of file - 7955 bytes

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

MalwareBytes Anti-Malware Scan Log as follows:

Malwarebytes' Anti-Malware 1.38
Database version: 2397
Windows 5.1.2600 Service Pack 3

09-Jul-09 09:14:04
mbam-log-2009-07-09 (09-14-04).txt

Scan type: Full Scan (C:\|)
Objects scanned: 307029
Time elapsed: 38 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files\accessories\playalldvd\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
c:\system volume information\_restore{09d640ac-ecd2-4adc-87a3-fa2a4f8f2039}\RP40\A0012956.exe (Malware.Packer) -> Quarantined and deleted successfully.

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=


This is TLoATDaE, Awaiting Further Instructions :wacko:
Hi,

Please open notepad, click Format and make sure Word Wrap is unchecked.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Right-click gmer.exe and select Run As Administrator. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Ok, here goes…

DDS.txt file as follows:
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 12:25:17.29 on 12-Jul-09
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2125 [GMT -4:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Accessories\WinPatrol\winpatrol.exe
C:\Program Files\Accessories\PowerISO\PWRISOVM.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
C:\PROGRAM FILES\NORTON GHOST\AGENT\VPROTRAY.EXE
C:\PROGRAM FILES\JAVA\JRE6\BIN\JUSCHED.EXE
C:\Documents and Settings\Val\Desktop\06 - dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.ca/
uSearch Page = hxxp://search.live.com
uInternet Settings,ProxyServer = http=127.0.0.1:5656
uInternet Settings,ProxyOverride = local
mSearchAssistant = hxxp://search.live.com/sphome.aspx
mWinlogon: UIHost=c:\program files\accessories\logon loader\logons\wciiibycerb\logonui.exe
mWinlogon: Taskman=c:\recycler\s-1-5-21-8418694959-2512096416-938368230-9084\rundll32.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [CoolSwitch] c:\windows\system32\taskswitch.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [WinPatrol] c:\program files\accessories\winpatrol\winpatrol.exe -expressboot
mRun: [PWRISOVM.EXE] c:\program files\accessories\poweriso\PWRISOVM.EXE
mRun: []
mRun: [BootSkin Startup Jobs] "c:\program files\accessories\wincustomize\bootskin\BootSkin.exe" /StartupJobs
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
uPolicies-explorer: NoSMMyPictures = 1 (0x1)
mPolicies-system: DisableCAD = 1 (0x1)
mPolicies-system: DisableStatusMessages = 1 (0x1)
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
dPolicies-explorer: NoSMMyPictures = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245900804640
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1245941092593
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\val\applic~1\mozilla\firefox\profiles\qpxlqojl.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\documents and settings\val\application data\mozilla\firefox\profiles\qpxlqojl.default\extensions\{fcab6fdd-5585-425b-95c1-5ed856f3fd08}\components\nsCatcher.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-24 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-24 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-24 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-24 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-24 298776]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2008-4-14 5120]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDAud.sys [2007-10-4 651776]
R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2007-12-20 1558000]
S0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys –> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?]

=============== Created Last 30 ================

2009-07-09 08:15 –d—– c:\program files\Trend Micro
2009-07-08 19:51 –d—– c:\documents and settings\all users\lx_Cats
2009-07-08 19:11 –d—– c:\docume~1\val\applic~1\Malwarebytes
2009-07-08 19:11 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-08 19:11 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-08 19:11 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-08 19:11 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-06 08:40 221,184 a——- c:\windows\system32\wmpns.dll
2009-07-05 22:31 –d—– c:\documents and settings\val\dwhelper
2009-06-29 23:51 42,240 a—-r– c:\windows\system32\drivers\ser2plms.sys
2009-06-29 23:47 –d—– c:\windows\RegisteredPackages
2009-06-29 23:47 –d—– c:\program files\Microsoft Streets & Trips
2009-06-29 23:47 –d—– c:\program files\Microsoft Location Finder
2009-06-29 23:12 –d—– c:\program files\HP
2009-06-29 23:03 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-06-29 23:03 0 a—h— c:\windows\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2009-06-29 23:02 1,560,576 a——- c:\windows\system32\BttnCmns_64.dll
2009-06-29 23:02 1,560,576 a——- c:\windows\system32\BttnCmns.dll
2009-06-29 23:02 1,419,232 a——- c:\windows\system32\wdfcoinstaller01005.dll
2009-06-29 23:02 987,136 a——- c:\windows\system32\BttnCmn.dll
2009-06-29 23:02 16,768 a——- c:\windows\system32\drivers\HpqKbFiltr.sys
2009-06-29 23:02 –d—– C:\SWSetup
2009-06-29 15:06 7,168 a–sh— c:\windows\Thumbs.db
2009-06-28 20:14 –d—– c:\program files\common files\Stardock
2009-06-28 20:14 163,712 a——- c:\windows\system32\drivers\vidstub.sys
2009-06-28 19:25 24 a——- c:\windows\LogonStudio.ini
2009-06-28 19:25 187,392 a——- c:\windows\system32\JPGUtils.dll
2009-06-28 19:24 –d—– c:\program files\WinCustomize
2009-06-28 16:04 –d—– c:\docume~1\val\applic~1\Marine Aquarium 3
2009-06-28 16:04 6,545,408 a——- c:\windows\system32\MarineAquarium3.scr
2009-06-28 15:23 –d—– c:\program files\Sonique
2009-06-28 09:56 445 a——- c:\windows\EntPack.dat
2009-06-27 21:23 –d—– c:\program files\common files\Macrovision Shared
2009-06-27 18:58 –d—– C:\logs
2009-06-27 18:12 –d—– C:\Animé
2009-06-27 11:33 –dsh— C:\$RECYCLE.BIN
2009-06-27 10:25 –ds—- C:\Images
2009-06-27 08:27 –d-hr– C:\VProRecovery
2009-06-26 15:07 –d-hr– c:\windows\system32\VProRecovery
2009-06-26 09:17 215,144 a—-r– c:\windows\patchw32.dll
2009-06-26 09:15 215,144 a—-r– c:\windows\pw32a.dll
2009-06-26 09:15 –d—– c:\docume~1\val\applic~1\Symantec
2009-06-26 09:10 1,060,864 a——- c:\windows\system32\MFC71.DLL
2009-06-26 09:10 503,808 a——- c:\windows\system32\MSVCP71.DLL
2009-06-26 09:10 –d—– c:\program files\Symantec
2009-06-26 09:09 107,368 a——- c:\windows\system32\GEARAspi.dll
2009-06-26 09:09 16,168 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-26 09:09 128,104 a——- c:\windows\system32\drivers\WimFltr.sys
2009-06-26 09:09 38,112 a——- c:\windows\system32\drivers\v2imount.sys
2009-06-26 09:09 15,088 a——- c:\windows\system32\drivers\vproeventmonitor.sys
2009-06-26 09:09 137,952 a——- c:\windows\system32\drivers\symsnap.sys
2009-06-26 09:09 –d—– c:\program files\common files\Symantec Shared
2009-06-26 09:09 –d—– c:\program files\Norton Ghost
2009-06-26 09:09 –d—– c:\docume~1\alluse~1\applic~1\Symantec
2009-06-26 08:28 410,984 a——- c:\windows\system32\deploytk.dll
2009-06-26 07:51 268,648 a——- c:\windows\system32\mucltui.dll
2009-06-26 07:51 27,496 a——- c:\windows\system32\mucltui.dll.mui
2009-06-26 03:11 –d-h— C:\$AVG8.VAULT$
2009-06-26 00:54 228,112 a——- c:\docume~1\val\applic~1\GDIPFONTCACHEV1.DAT
2009-06-25 23:27 –d—– C:\Torrent Drop-Zone
2009-06-25 23:16 –d—– c:\docume~1\alluse~1\applic~1\7Wonders2
2009-06-25 23:14 –d—– c:\docume~1\val\applic~1\7Wonders
2009-06-25 22:50 73,728 a——- c:\windows\system32\javacpl.cpl
2009-06-25 22:39 –dsh— c:\documents and settings\val\PrivacIE
2009-06-25 22:39 839,680 a——- c:\windows\system32\lameACM.acm
2009-06-25 22:39 168,448 a——- c:\windows\system32\unrar.dll
2009-06-25 22:39 414 a——- c:\windows\system32\lame_acm.xml
2009-06-25 22:39 38 a——- c:\windows\avisplitter.ini
2009-06-25 22:39 881,664 a——- c:\windows\system32\xvidcore.dll
2009-06-25 22:39 217,088 a——- c:\windows\system32\yv12vfw.dll
2009-06-25 22:39 118,784 a——- c:\windows\system32\ac3acm.acm
2009-06-25 22:38 3,596,288 a——- c:\windows\system32\qt-dx331.dll
2009-06-25 22:38 685,056 a——- c:\windows\system32\divx.dll
2009-06-25 22:38 205,824 a——- c:\windows\system32\xvidvfw.dll
2009-06-25 22:38 90,112 a——- c:\windows\system32\dpl100.dll
2009-06-25 22:38 85,504 a——- c:\windows\system32\ff_vfw.dll
2009-06-25 22:38 547 a——- c:\windows\system32\ff_vfw.dll.manifest
2009-06-25 22:38 348,160 a——- c:\windows\system32\MSVCR71.DLL
2009-06-25 22:38 –d—– c:\program files\K-Lite Codec Pack
2009-06-25 22:30 124 a——- c:\windows\entpack.ini
2009-06-25 21:32 –d—– c:\temp\New Folder
2009-06-25 21:12 –ds—- C:\Games
2009-06-25 17:44 –d—– c:\docume~1\val\applic~1\WinPatrol
2009-06-25 15:02 –dsh— c:\documents and settings\val\IETldCache
2009-06-25 14:57 102,912 -c—— c:\windows\system32\dllcache\iecompat.dll
2009-06-25 14:57 –d—– c:\windows\ie8updates
2009-06-25 14:57 11,064,832 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-06-25 14:57 1,985,024 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-06-25 14:57 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2009-06-25 14:57 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2009-06-25 14:56 -cd-h— c:\windows\ie8
2009-06-25 13:43 3,426,072 a——- c:\windows\system32\d3dx9_32.dll
2009-06-25 13:43 –d—– c:\program files\Microsoft SQL Server Compact Edition
2009-06-25 13:42 –d—– c:\program files\Microsoft
2009-06-25 13:42 –d—– c:\program files\Windows Live SkyDrive
2009-06-25 13:13 –d—– c:\program files\common files\Windows Live
2009-06-25 12:49 –d—– c:\windows\system32\XPSViewer
2009-06-25 12:48 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2009-06-25 12:48 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-25 12:48 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-25 12:48 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-25 12:48 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-06-25 12:48 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-06-25 12:48 117,760 ——– c:\windows\system32\prntvpt.dll
2009-06-25 12:45 –d—– c:\windows\system32\URTTemp
2009-06-25 12:32 873,374 a——- c:\windows\system32\oem17.inf
2009-06-25 12:32 14,592 ac—— c:\windows\system32\dllcache\kbdhid.sys
2009-06-25 12:32 14,592 a——- c:\windows\system32\drivers\kbdhid.sys
2009-06-25 12:13 376 a——- c:\windows\ODBC.INI
2009-06-25 12:12 –d—– c:\program files\Microsoft ActiveSync
2009-06-25 12:11 –d—– c:\windows\ShellNew
2009-06-25 12:11 –d—– c:\program files\common files\L&H
2009-06-25 10:58 146,048 ac—— c:\windows\system32\dllcache\portcls.sys
2009-06-25 10:53 272,128 -c—— c:\windows\system32\dllcache\bthport.sys
2009-06-25 10:53 272,128 ——– c:\windows\system32\drivers\bthport.sys
2009-06-25 10:53 2,189,056 -c—— c:\windows\system32\dllcache\ntoskrnl.exe
2009-06-25 10:53 2,145,280 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-06-25 10:53 2,023,936 -c—— c:\windows\system32\dllcache\ntkrpamp.exe
2009-06-25 10:52 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2009-06-25 10:50 2,560 ——– c:\windows\system32\xpsp4res.dll
2009-06-25 10:44 26,144 a——- c:\windows\system32\spupdsvc.exe
2009-06-25 10:44 –d—– c:\windows\system32\PreInstall
2009-06-25 10:44 –d-h— c:\windows\$hf_mig$
2009-06-25 01:11 –d—– c:\windows\system32\SoftwareDistribution
2009-06-25 01:03 –d—– c:\docume~1\val\applic~1\uTorrent
2009-06-25 00:20 –d—– c:\program files\Accessories
2009-06-24 23:24 –d–r– C:\My Music
2009-06-24 22:18 –d—– c:\windows\Icon Resources
2009-06-24 22:07 –d—– C:\Temp
2009-06-24 22:02 –d—– c:\windows\system32\appmgmt
2009-06-24 21:59 1,391,104 a——- c:\windows\system32\drivers\BCMWL5.SYS
2009-06-24 21:59 –d—– c:\program files\Broadcom
2009-06-24 20:43 110,592 ——– c:\windows\system32\SmartAudio.cpl
2009-06-24 20:43 –d—– c:\program files\CONEXANT
2009-06-24 20:38 213,696 a——- c:\windows\system32\drivers\SynTP.sys
2009-06-24 20:38 196,608 a——- c:\windows\system32\SynCtrl.dll
2009-06-24 20:38 163,840 a——- c:\windows\system32\SynCOM.dll
2009-06-24 20:38 147,456 a——- c:\windows\system32\SynTPAPI.dll
2009-06-24 20:38 110,592 a——- c:\windows\system32\SynTPCo4.dll
2009-06-24 20:38 –d—– c:\program files\Synaptics
2009-06-24 20:28 126,976 a——- c:\windows\system32\Imsmudlg.exe
2009-06-24 20:28 –d—– c:\windows\system32\ENU
2009-06-24 20:23 –dsh— c:\documents and settings\val\UserData
2009-06-24 20:08 12,540 a——- c:\windows\system32\wpa.bak
2009-06-24 20:02 130,432 a——- c:\windows\system32\drivers\Rtnicxp.sys
2009-06-24 20:02 73,728 a——- c:\windows\system32\RtNicProp32.dll
2009-06-24 19:54 –d—– c:\windows\OPTIONS
2009-06-24 19:43 –d—– c:\windows\system32\ReinstallBackups
2009-06-24 19:43 –d—– C:\Intel
2009-06-24 16:08 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-06-24 16:08 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-06-24 16:07 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-06-24 16:07 –d—– c:\windows\system32\drivers\Avg
2009-06-24 16:07 –d—– c:\program files\AVG
2009-06-24 16:07 –d—– c:\docume~1\alluse~1\applic~1\avg8
2009-06-24 16:04 –d—– c:\windows\Downloaded Installations
2009-06-24 16:03 266,360 a——- c:\windows\system32\TweakUI.exe
2009-06-24 16:03 160,217 a——- c:\windows\system32\PowerToysLicense.rtf
2009-06-24 15:11 –d—– C:\Drop-Zone
2009-06-24 15:11 –d—– C:\Archive
2009-06-24 15:11 –d—– C:\Shared
2009-06-24 15:10 –d—– C:\Zztemp
2009-06-24 15:08 –d—– c:\documents and settings\Val
2009-06-24 15:07 –d—– c:\windows\IIS Temporary Compressed Files
2009-06-24 15:07 8,192 a——- c:\windows\REGLOCS.OLD
2009-06-24 15:05 65,536 ac—— c:\windows\system32\dllcache\EXCH_mailmsg.dll
2009-06-24 15:05 –d—– c:\program files\msn gaming zone
2009-06-24 15:04 –dsh— c:\documents and settings\all users\DRM
2009-06-24 15:04 –d-h— c:\program files\WindowsUpdate
2009-06-24 15:04 –d—– c:\program files\Online Services
2009-06-24 15:03 –d—– c:\program files\common files\MSSoap
2009-06-24 15:01 –d—– c:\program files\Windows NT
2009-06-24 10:59 –d—– c:\program files\common files\ODBC
2009-06-24 10:59 –d—– c:\program files\common files\SpeechEngines
2009-06-24 10:58 –d–r– c:\documents and settings\all users\Documents

==================== Find3M ====================

2009-06-28 19:43 3,979,264 a——- c:\windows\system32\logonuiX.exe
2009-06-24 15:31 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-06-24 15:02 21,640 a——- c:\windows\system32\emptyregdb.dat
2009-06-24 14:35 1,614,848 a——- c:\windows\system32\sfcfiles.dll
2009-06-24 13:31 55,296 a——- c:\windows\system32\dvdplay.exe
2009-06-24 13:31 21,376 a——- c:\windows\system32\drivers\tsbvcap.sys
2009-06-24 13:31 18,688 a——- c:\windows\system32\drivers\cdaudio.sys
2009-06-24 13:31 12,160 a——- c:\windows\system32\drivers\mouhid.sys
2009-06-24 13:31 12,160 a——- c:\windows\system32\drivers\fsvga.sys
2009-06-24 13:31 8,192 a——- c:\windows\system32\tsbyuv.dll
2009-06-24 13:31 8,192 a——- c:\windows\system32\streamci.dll
2009-06-24 13:30 218,624 a——- c:\windows\system32\uxtheme.dll
2009-06-24 13:30 990,208 a——- c:\windows\system32\syssetup.dll
2009-05-13 01:15 915,456 a——- c:\windows\system32\wininet.dll
2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll
2009-04-17 08:26 1,847,168 a——- c:\windows\system32\win32k.sys
2009-04-15 10:51 585,216 a——- c:\windows\system32\rpcrt4.dll

============= FINISH: 12:25:33.20 ===============



Attached File Uploaded as per instructions

GMER Log as follows:
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-12 14:32:58
Windows 5.1.2600 Service Pack 3


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

I hope this helps.

As a status report: I have been able to mchange my wallpeper, but there was no signs of it being something I did to fix it.
There are still "random" number files trying to execute, which WinPatrol helps stop, but AVG 8.5 come up with a few files that need to be dealt with, but when I do so, it tells me one of the files can't be found! Its a reference to a file "bacon(1).exe"

Here's hoping this will all help fix this poor 'puter!

As I wander the Continental US, I will await further instructions as I can get internet …

Attachments:

Hi,

Click Start >> Control Panel >> Add/Remove Programs. Find and Remove the following old Java version:
Java™ 6 Update 5

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:Processes
explorer.exe

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WinLogon]
"Taskman"=-

:files
c:\recycler\s-1-5-21-8418694959-2512096416-938368230-9084\rundll32.exe

:Commands
[emptytemp]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


After your machine reboots, run this scan.

Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Also, let me know how the computer is running now.
Greetings :) Uninstalled the old Java, downloadd the OTM.exe, and ran it with thew code provided. In the Green box, it said "All Processes Killed" right before I lost the GUI (went to Desktop with cursor and no Icons or start.menu). There is no log generated, and the folder(s) were empty, so there's nothing to copy/paste from there. Kapersky Online log is as follows: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Tuesday, July 14, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Tuesday, July 14, 2009 04:26:20 Records in database: 2466845 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ R:\ Scan statistics: Files scanned: 229114 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 03:09:19 No malware has been detected. The scan area is clean. The selected area was scanned. =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= My machine is running OK, but I feel rather "naked" as there's no AVG, Winpatrol, Windows Defender running. I'm going to see if I can get them running again ASAP. Here's hoping I am FINALLY free of whatever has been plaguing me! Thanks thus far! I feel like we've actually made a bit of progress, jpshortstuff! Awaiting further instructions…
Hi, Please run DDS again and post the first log it gives (DDS.txt) so we can check whether the OTM fix worked or not. Are you experiencing any more problems?
Other than the OTM crash, and it causing everything that usually runs to be gone until I manually start them up again, all seems to be going well. Is there something I missed that might cause that particular crash, or is it my system? At any rate, here's the latest DDS Logfile: =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 22:39:28.62 on 14-Jul-09 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2558 [GMT -4:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\ctfmon.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Norton Ghost\Agent\VProSvc.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Val\Desktop\06 - dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ uSearch Page = hxxp://search.live.com uInternet Settings,ProxyServer = http=127.0.0.1:5656 uInternet Settings,ProxyOverride = local mSearchAssistant = hxxp://search.live.com/sphome.aspx mWinlogon: UIHost=c:\program files\accessories\logon loader\logons\wciiibycerb\logonui.exe mWinlogon: Taskman=c:\recycler\s-1-5-21-8418694959-2512096416-938368230-9084\rundll32.exe BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [CoolSwitch] c:\windows\system32\taskswitch.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe" mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRun: [WinPatrol] c:\program files\accessories\winpatrol\winpatrol.exe -expressboot mRun: [PWRISOVM.EXE] c:\program files\accessories\poweriso\PWRISOVM.EXE mRun: [] mRun: [BootSkin Startup Jobs] "c:\program files\accessories\wincustomize\bootskin\BootSkin.exe" /StartupJobs mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N uPolicies-explorer: NoSMMyPictures = 1 (0x1) mPolicies-system: DisableCAD = 1 (0x1) mPolicies-system: DisableStatusMessages = 1 (0x1) dPolicies-explorer: ForceClassicControlPanel = 1 (0x1) dPolicies-explorer: NoSMMyPictures = 1 (0x1) IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245900804640 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1245941092593 DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\val\applic~1\mozilla\firefox\profiles\qpxlqojl.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;= FF - prefs.js: browser.search.selectedEngine - Live Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;= FF - component: c:\documents and settings\val\application data\mozilla\firefox\profiles\qpxlqojl.default\extensions\{fcab6fdd-5585-425b-95c1-5ed856f3fd08}\components\nsCatcher.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-24 335752] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-24 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-24 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-24 907032] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-24 298776] R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2008-4-14 5120] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808] R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDAud.sys [2007-10-4 651776] R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2007-12-20 1558000] S0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys –> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?] =============== Created Last 30 ================ 2009-07-13 20:43 –d—– C:\_OTM 2009-07-09 08:15 –d—– c:\program files\Trend Micro 2009-07-08 19:51 –d—– c:\documents and settings\all users\lx_Cats 2009-07-08 19:11 –d—– c:\docume~1\val\applic~1\Malwarebytes 2009-07-08 19:11 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-08 19:11 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-08 19:11 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-08 19:11 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-06 08:40 221,184 a——- c:\windows\system32\wmpns.dll 2009-07-05 22:31 –d—– c:\documents and settings\val\dwhelper 2009-06-29 23:51 42,240 a—-r– c:\windows\system32\drivers\ser2plms.sys 2009-06-29 23:47 –d—– c:\windows\RegisteredPackages 2009-06-29 23:47 –d—– c:\program files\Microsoft Streets & Trips 2009-06-29 23:47 –d—– c:\program files\Microsoft Location Finder 2009-06-29 23:12 –d—– c:\program files\HP 2009-06-29 23:03 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2009-06-29 23:03 0 a—h— c:\windows\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf 2009-06-29 23:02 1,560,576 a——- c:\windows\system32\BttnCmns_64.dll 2009-06-29 23:02 1,560,576 a——- c:\windows\system32\BttnCmns.dll 2009-06-29 23:02 1,419,232 a——- c:\windows\system32\wdfcoinstaller01005.dll 2009-06-29 23:02 987,136 a——- c:\windows\system32\BttnCmn.dll 2009-06-29 23:02 16,768 a——- c:\windows\system32\drivers\HpqKbFiltr.sys 2009-06-29 23:02 –d—– C:\SWSetup 2009-06-29 15:06 7,168 a–sh— c:\windows\Thumbs.db 2009-06-28 20:14 –d—– c:\program files\common files\Stardock 2009-06-28 20:14 163,712 a——- c:\windows\system32\drivers\vidstub.sys 2009-06-28 19:25 24 a——- c:\windows\LogonStudio.ini 2009-06-28 19:25 187,392 a——- c:\windows\system32\JPGUtils.dll 2009-06-28 19:24 –d—– c:\program files\WinCustomize 2009-06-28 16:04 –d—– c:\docume~1\val\applic~1\Marine Aquarium 3 2009-06-28 16:04 6,545,408 a——- c:\windows\system32\MarineAquarium3.scr 2009-06-28 15:23 –d—– c:\program files\Sonique 2009-06-28 09:56 445 a——- c:\windows\EntPack.dat 2009-06-27 21:23 –d—– c:\program files\common files\Macrovision Shared 2009-06-27 18:58 –d—– C:\logs 2009-06-27 18:12 –d—– C:\Animé 2009-06-27 11:33 –dsh— C:\$RECYCLE.BIN 2009-06-27 10:25 –ds—- C:\Images 2009-06-27 08:27 –d-hr– C:\VProRecovery 2009-06-26 15:07 –d-hr– c:\windows\system32\VProRecovery 2009-06-26 09:17 215,144 a—-r– c:\windows\patchw32.dll 2009-06-26 09:15 215,144 a—-r– c:\windows\pw32a.dll 2009-06-26 09:15 –d—– c:\docume~1\val\applic~1\Symantec 2009-06-26 09:10 1,060,864 a——- c:\windows\system32\MFC71.DLL 2009-06-26 09:10 503,808 a——- c:\windows\system32\MSVCP71.DLL 2009-06-26 09:10 –d—– c:\program files\Symantec 2009-06-26 09:09 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-06-26 09:09 16,168 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-06-26 09:09 128,104 a——- c:\windows\system32\drivers\WimFltr.sys 2009-06-26 09:09 38,112 a——- c:\windows\system32\drivers\v2imount.sys 2009-06-26 09:09 15,088 a——- c:\windows\system32\drivers\vproeventmonitor.sys 2009-06-26 09:09 137,952 a——- c:\windows\system32\drivers\symsnap.sys 2009-06-26 09:09 –d—– c:\program files\common files\Symantec Shared 2009-06-26 09:09 –d—– c:\program files\Norton Ghost 2009-06-26 09:09 –d—– c:\docume~1\alluse~1\applic~1\Symantec 2009-06-26 08:28 410,984 a——- c:\windows\system32\deploytk.dll 2009-06-26 07:51 268,648 a——- c:\windows\system32\mucltui.dll 2009-06-26 07:51 27,496 a——- c:\windows\system32\mucltui.dll.mui 2009-06-26 03:11 –d-h— C:\$AVG8.VAULT$ 2009-06-26 00:54 228,112 a——- c:\docume~1\val\applic~1\GDIPFONTCACHEV1.DAT 2009-06-25 23:27 –d—– C:\Torrent Drop-Zone 2009-06-25 23:16 –d—– c:\docume~1\alluse~1\applic~1\7Wonders2 2009-06-25 23:14 –d—– c:\docume~1\val\applic~1\7Wonders 2009-06-25 22:50 73,728 a——- c:\windows\system32\javacpl.cpl 2009-06-25 22:39 –dsh— c:\documents and settings\val\PrivacIE 2009-06-25 22:39 839,680 a——- c:\windows\system32\lameACM.acm 2009-06-25 22:39 168,448 a——- c:\windows\system32\unrar.dll 2009-06-25 22:39 414 a——- c:\windows\system32\lame_acm.xml 2009-06-25 22:39 38 a——- c:\windows\avisplitter.ini 2009-06-25 22:39 881,664 a——- c:\windows\system32\xvidcore.dll 2009-06-25 22:39 217,088 a——- c:\windows\system32\yv12vfw.dll 2009-06-25 22:39 118,784 a——- c:\windows\system32\ac3acm.acm 2009-06-25 22:38 3,596,288 a——- c:\windows\system32\qt-dx331.dll 2009-06-25 22:38 685,056 a——- c:\windows\system32\divx.dll 2009-06-25 22:38 205,824 a——- c:\windows\system32\xvidvfw.dll 2009-06-25 22:38 90,112 a——- c:\windows\system32\dpl100.dll 2009-06-25 22:38 85,504 a——- c:\windows\system32\ff_vfw.dll 2009-06-25 22:38 547 a——- c:\windows\system32\ff_vfw.dll.manifest 2009-06-25 22:38 348,160 a——- c:\windows\system32\MSVCR71.DLL 2009-06-25 22:38 –d—– c:\program files\K-Lite Codec Pack 2009-06-25 22:30 124 a——- c:\windows\entpack.ini 2009-06-25 21:12 –ds—- C:\Games 2009-06-25 17:44 –d—– c:\docume~1\val\applic~1\WinPatrol 2009-06-25 15:02 –dsh— c:\documents and settings\val\IETldCache 2009-06-25 14:57 102,912 -c—— c:\windows\system32\dllcache\iecompat.dll 2009-06-25 14:57 –d—– c:\windows\ie8updates 2009-06-25 14:57 11,064,832 -c—— c:\windows\system32\dllcache\ieframe.dll 2009-06-25 14:57 1,985,024 -c—— c:\windows\system32\dllcache\iertutil.dll 2009-06-25 14:57 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll 2009-06-25 14:57 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll 2009-06-25 14:56 -cd-h— c:\windows\ie8 2009-06-25 13:43 3,426,072 a——- c:\windows\system32\d3dx9_32.dll 2009-06-25 13:43 –d—– c:\program files\Microsoft SQL Server Compact Edition 2009-06-25 13:42 –d—– c:\program files\Microsoft 2009-06-25 13:42 –d—– c:\program files\Windows Live SkyDrive 2009-06-25 13:13 –d—– c:\program files\common files\Windows Live 2009-06-25 12:49 –d—– c:\windows\system32\XPSViewer 2009-06-25 12:48 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-06-25 12:48 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-06-25 12:48 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-06-25 12:48 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-06-25 12:48 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-06-25 12:48 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-06-25 12:48 117,760 ——– c:\windows\system32\prntvpt.dll 2009-06-25 12:45 –d—– c:\windows\system32\URTTemp 2009-06-25 12:32 873,374 a——- c:\windows\system32\oem17.inf 2009-06-25 12:32 14,592 ac—— c:\windows\system32\dllcache\kbdhid.sys 2009-06-25 12:32 14,592 a——- c:\windows\system32\drivers\kbdhid.sys 2009-06-25 12:13 376 a——- c:\windows\ODBC.INI 2009-06-25 12:12 –d—– c:\program files\Microsoft ActiveSync 2009-06-25 12:11 –d—– c:\windows\ShellNew 2009-06-25 12:11 –d—– c:\program files\common files\L&H; 2009-06-25 10:58 146,048 ac—— c:\windows\system32\dllcache\portcls.sys 2009-06-25 10:53 272,128 -c—— c:\windows\system32\dllcache\bthport.sys 2009-06-25 10:53 272,128 ——– c:\windows\system32\drivers\bthport.sys 2009-06-25 10:53 2,189,056 -c—— c:\windows\system32\dllcache\ntoskrnl.exe 2009-06-25 10:53 2,145,280 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe 2009-06-25 10:53 2,023,936 -c—— c:\windows\system32\dllcache\ntkrpamp.exe 2009-06-25 10:52 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys 2009-06-25 10:50 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-06-25 10:44 26,144 a——- c:\windows\system32\spupdsvc.exe 2009-06-25 10:44 –d—– c:\windows\system32\PreInstall 2009-06-25 10:44 –d-h— c:\windows\$hf_mig$ 2009-06-25 01:11 –d—– c:\windows\system32\SoftwareDistribution 2009-06-25 01:03 –d—– c:\docume~1\val\applic~1\uTorrent 2009-06-25 00:20 –d—– c:\program files\Accessories 2009-06-24 23:24 –d–r– C:\My Music 2009-06-24 22:18 –d—– c:\windows\Icon Resources 2009-06-24 22:07 –d—– C:\Temp 2009-06-24 22:02 –d—– c:\windows\system32\appmgmt 2009-06-24 21:59 1,391,104 a——- c:\windows\system32\drivers\BCMWL5.SYS 2009-06-24 21:59 –d—– c:\program files\Broadcom 2009-06-24 20:43 110,592 ——– c:\windows\system32\SmartAudio.cpl 2009-06-24 20:43 –d—– c:\program files\CONEXANT 2009-06-24 20:38 213,696 a——- c:\windows\system32\drivers\SynTP.sys 2009-06-24 20:38 196,608 a——- c:\windows\system32\SynCtrl.dll 2009-06-24 20:38 163,840 a——- c:\windows\system32\SynCOM.dll 2009-06-24 20:38 147,456 a——- c:\windows\system32\SynTPAPI.dll 2009-06-24 20:38 110,592 a——- c:\windows\system32\SynTPCo4.dll 2009-06-24 20:38 –d—– c:\program files\Synaptics 2009-06-24 20:28 126,976 a——- c:\windows\system32\Imsmudlg.exe 2009-06-24 20:28 –d—– c:\windows\system32\ENU 2009-06-24 20:23 –dsh— c:\documents and settings\val\UserData 2009-06-24 20:08 12,540 a——- c:\windows\system32\wpa.bak 2009-06-24 20:02 130,432 a——- c:\windows\system32\drivers\Rtnicxp.sys 2009-06-24 20:02 73,728 a——- c:\windows\system32\RtNicProp32.dll 2009-06-24 19:54 –d—– c:\windows\OPTIONS 2009-06-24 19:43 –d—– c:\windows\system32\ReinstallBackups 2009-06-24 19:43 –d—– C:\Intel 2009-06-24 16:08 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-06-24 16:08 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-06-24 16:07 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-24 16:07 –d—– c:\windows\system32\drivers\Avg 2009-06-24 16:07 –d—– c:\program files\AVG 2009-06-24 16:07 –d—– c:\docume~1\alluse~1\applic~1\avg8 2009-06-24 16:04 –d—– c:\windows\Downloaded Installations 2009-06-24 16:03 266,360 a——- c:\windows\system32\TweakUI.exe 2009-06-24 16:03 160,217 a——- c:\windows\system32\PowerToysLicense.rtf 2009-06-24 15:11 –d—– C:\Drop-Zone 2009-06-24 15:11 –d—– C:\Archive 2009-06-24 15:11 –d—– C:\Shared 2009-06-24 15:10 –d—– C:\Zztemp 2009-06-24 15:08 –d—– c:\documents and settings\Val 2009-06-24 15:07 –d—– c:\windows\IIS Temporary Compressed Files 2009-06-24 15:07 8,192 a——- c:\windows\REGLOCS.OLD 2009-06-24 15:05 65,536 ac—— c:\windows\system32\dllcache\EXCH_mailmsg.dll 2009-06-24 15:05 –d—– c:\program files\msn gaming zone 2009-06-24 15:04 –dsh— c:\documents and settings\all users\DRM 2009-06-24 15:04 –d-h— c:\program files\WindowsUpdate 2009-06-24 15:04 –d—– c:\program files\Online Services 2009-06-24 15:03 –d—– c:\program files\common files\MSSoap 2009-06-24 15:01 –d—– c:\program files\Windows NT 2009-06-24 10:59 –d—– c:\program files\common files\ODBC 2009-06-24 10:59 –d—– c:\program files\common files\SpeechEngines 2009-06-24 10:58 –d–r– c:\documents and settings\all users\Documents ==================== Find3M ==================== 2009-06-28 19:43 3,979,264 a——- c:\windows\system32\logonuiX.exe 2009-06-24 15:31 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-06-24 15:02 21,640 a——- c:\windows\system32\emptyregdb.dat 2009-06-24 14:35 1,614,848 a——- c:\windows\system32\sfcfiles.dll 2009-06-24 13:31 55,296 a——- c:\windows\system32\dvdplay.exe 2009-06-24 13:31 21,376 a——- c:\windows\system32\drivers\tsbvcap.sys 2009-06-24 13:31 18,688 a——- c:\windows\system32\drivers\cdaudio.sys 2009-06-24 13:31 12,160 a——- c:\windows\system32\drivers\mouhid.sys 2009-06-24 13:31 12,160 a——- c:\windows\system32\drivers\fsvga.sys 2009-06-24 13:31 8,192 a——- c:\windows\system32\tsbyuv.dll 2009-06-24 13:31 8,192 a——- c:\windows\system32\streamci.dll 2009-06-24 13:30 218,624 a——- c:\windows\system32\uxtheme.dll 2009-06-24 13:30 990,208 a——- c:\windows\system32\syssetup.dll 2009-05-13 01:15 915,456 a——- c:\windows\system32\wininet.dll 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll 2009-04-17 08:26 1,847,168 a——- c:\windows\system32\win32k.sys ============= FINISH: 22:39:44.51 =============== Hopefully, that will be it… We can always be Hopeful, right? ;)
Hi,

The OTM didn't run by the looks of things. Let's change things slightly and try again. Please copy the following script into OTM as before. Close everything else before hitting the MoveIt button.
:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WinLogon]
"Taskman"=-

:files
c:\recycler\s-1-5-21-8418694959-2512096416-938368230-9084\rundll32.exe

:Commands
[emptytemp]
[Reboot]
Let me know how that goes, and post a new DDS log afterwards. If the OTM fix works, please post the OTM log as well.
Alas, the OTM had the same response as last attempt, so no log, I'm afraid. DDS log as follows: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 0:17:43.37 on 16-Jul-09 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2497 [GMT -4:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\ctfmon.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Norton Ghost\Agent\VProSvc.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Val\Desktop\06 - dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ uSearch Page = hxxp://search.live.com uInternet Settings,ProxyServer = http=127.0.0.1:5656 uInternet Settings,ProxyOverride = local mSearchAssistant = hxxp://search.live.com/sphome.aspx mWinlogon: UIHost=c:\program files\accessories\logon loader\logons\wciiibycerb\logonui.exe mWinlogon: Taskman=c:\recycler\s-1-5-21-8418694959-2512096416-938368230-9084\rundll32.exe BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [CoolSwitch] c:\windows\system32\taskswitch.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe" mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRun: [WinPatrol] c:\program files\accessories\winpatrol\winpatrol.exe -expressboot mRun: [PWRISOVM.EXE] c:\program files\accessories\poweriso\PWRISOVM.EXE mRun: [] mRun: [BootSkin Startup Jobs] "c:\program files\accessories\wincustomize\bootskin\BootSkin.exe" /StartupJobs mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N uPolicies-explorer: NoSMMyPictures = 1 (0x1) mPolicies-system: DisableCAD = 1 (0x1) mPolicies-system: DisableStatusMessages = 1 (0x1) dPolicies-explorer: ForceClassicControlPanel = 1 (0x1) dPolicies-explorer: NoSMMyPictures = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245900804640 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1245941092593 DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\val\applic~1\mozilla\firefox\profiles\qpxlqojl.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q= FF - prefs.js: browser.search.selectedEngine - Live Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q= FF - component: c:\documents and settings\val\application data\mozilla\firefox\profiles\qpxlqojl.default\extensions\{fcab6fdd-5585-425b-95c1-5ed856f3fd08}\components\nsCatcher.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-24 335752] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-24 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-24 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-24 907032] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-24 298776] R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2008-4-14 5120] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808] R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDAud.sys [2007-10-4 651776] R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2007-12-20 1558000] S0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys –> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?] =============== Created Last 30 ================ 2009-07-13 20:43 –d—– C:\_OTM 2009-07-09 08:15 –d—– c:\program files\Trend Micro 2009-07-08 19:51 –d—– c:\documents and settings\all users\lx_Cats 2009-07-08 19:11 –d—– c:\docume~1\val\applic~1\Malwarebytes 2009-07-08 19:11 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-08 19:11 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-08 19:11 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-08 19:11 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-06 08:40 221,184 a——- c:\windows\system32\wmpns.dll 2009-07-05 22:31 –d—– c:\documents and settings\val\dwhelper 2009-06-29 23:51 42,240 a—-r– c:\windows\system32\drivers\ser2plms.sys 2009-06-29 23:47 –d—– c:\windows\RegisteredPackages 2009-06-29 23:47 –d—– c:\program files\Microsoft Streets & Trips 2009-06-29 23:47 –d—– c:\program files\Microsoft Location Finder 2009-06-29 23:12 –d—– c:\program files\HP 2009-06-29 23:03 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2009-06-29 23:03 0 a—h— c:\windows\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf 2009-06-29 23:02 1,560,576 a——- c:\windows\system32\BttnCmns_64.dll 2009-06-29 23:02 1,560,576 a——- c:\windows\system32\BttnCmns.dll 2009-06-29 23:02 1,419,232 a——- c:\windows\system32\wdfcoinstaller01005.dll 2009-06-29 23:02 987,136 a——- c:\windows\system32\BttnCmn.dll 2009-06-29 23:02 16,768 a——- c:\windows\system32\drivers\HpqKbFiltr.sys 2009-06-29 23:02 –d—– C:\SWSetup 2009-06-29 15:06 7,168 a–sh— c:\windows\Thumbs.db 2009-06-28 20:14 –d—– c:\program files\common files\Stardock 2009-06-28 20:14 163,712 a——- c:\windows\system32\drivers\vidstub.sys 2009-06-28 19:25 24 a——- c:\windows\LogonStudio.ini 2009-06-28 19:25 187,392 a——- c:\windows\system32\JPGUtils.dll 2009-06-28 19:24 –d—– c:\program files\WinCustomize 2009-06-28 16:04 –d—– c:\docume~1\val\applic~1\Marine Aquarium 3 2009-06-28 16:04 6,545,408 a——- c:\windows\system32\MarineAquarium3.scr 2009-06-28 15:23 –d—– c:\program files\Sonique 2009-06-28 09:56 445 a——- c:\windows\EntPack.dat 2009-06-27 21:23 –d—– c:\program files\common files\Macrovision Shared 2009-06-27 18:58 –d—– C:\logs 2009-06-27 18:12 –d—– C:\Animé 2009-06-27 11:33 –dsh— C:\$RECYCLE.BIN 2009-06-27 10:25 –ds—- C:\Images 2009-06-27 08:27 –d-hr– C:\VProRecovery 2009-06-26 15:07 –d-hr– c:\windows\system32\VProRecovery 2009-06-26 09:17 215,144 a—-r– c:\windows\patchw32.dll 2009-06-26 09:15 215,144 a—-r– c:\windows\pw32a.dll 2009-06-26 09:15 –d—– c:\docume~1\val\applic~1\Symantec 2009-06-26 09:10 1,060,864 a——- c:\windows\system32\MFC71.DLL 2009-06-26 09:10 503,808 a——- c:\windows\system32\MSVCP71.DLL 2009-06-26 09:10 –d—– c:\program files\Symantec 2009-06-26 09:09 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-06-26 09:09 16,168 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-06-26 09:09 128,104 a——- c:\windows\system32\drivers\WimFltr.sys 2009-06-26 09:09 38,112 a——- c:\windows\system32\drivers\v2imount.sys 2009-06-26 09:09 15,088 a——- c:\windows\system32\drivers\vproeventmonitor.sys 2009-06-26 09:09 137,952 a——- c:\windows\system32\drivers\symsnap.sys 2009-06-26 09:09 –d—– c:\program files\common files\Symantec Shared 2009-06-26 09:09 –d—– c:\program files\Norton Ghost 2009-06-26 09:09 –d—– c:\docume~1\alluse~1\applic~1\Symantec 2009-06-26 08:28 410,984 a——- c:\windows\system32\deploytk.dll 2009-06-26 07:51 268,648 a——- c:\windows\system32\mucltui.dll 2009-06-26 07:51 27,496 a——- c:\windows\system32\mucltui.dll.mui 2009-06-26 03:11 –d-h— C:\$AVG8.VAULT$ 2009-06-26 00:54 228,112 a——- c:\docume~1\val\applic~1\GDIPFONTCACHEV1.DAT 2009-06-25 23:27 –d—– C:\Torrent Drop-Zone 2009-06-25 23:16 –d—– c:\docume~1\alluse~1\applic~1\7Wonders2 2009-06-25 23:14 –d—– c:\docume~1\val\applic~1\7Wonders 2009-06-25 22:50 73,728 a——- c:\windows\system32\javacpl.cpl 2009-06-25 22:39 –dsh— c:\documents and settings\val\PrivacIE 2009-06-25 22:39 839,680 a——- c:\windows\system32\lameACM.acm 2009-06-25 22:39 168,448 a——- c:\windows\system32\unrar.dll 2009-06-25 22:39 414 a——- c:\windows\system32\lame_acm.xml 2009-06-25 22:39 38 a——- c:\windows\avisplitter.ini 2009-06-25 22:39 881,664 a——- c:\windows\system32\xvidcore.dll 2009-06-25 22:39 217,088 a——- c:\windows\system32\yv12vfw.dll 2009-06-25 22:39 118,784 a——- c:\windows\system32\ac3acm.acm 2009-06-25 22:38 3,596,288 a——- c:\windows\system32\qt-dx331.dll 2009-06-25 22:38 685,056 a——- c:\windows\system32\divx.dll 2009-06-25 22:38 205,824 a——- c:\windows\system32\xvidvfw.dll 2009-06-25 22:38 90,112 a——- c:\windows\system32\dpl100.dll 2009-06-25 22:38 85,504 a——- c:\windows\system32\ff_vfw.dll 2009-06-25 22:38 547 a——- c:\windows\system32\ff_vfw.dll.manifest 2009-06-25 22:38 348,160 a——- c:\windows\system32\MSVCR71.DLL 2009-06-25 22:38 –d—– c:\program files\K-Lite Codec Pack 2009-06-25 22:30 124 a——- c:\windows\entpack.ini 2009-06-25 21:12 –ds—- C:\Games 2009-06-25 17:44 –d—– c:\docume~1\val\applic~1\WinPatrol 2009-06-25 15:02 –dsh— c:\documents and settings\val\IETldCache 2009-06-25 14:57 102,912 -c—— c:\windows\system32\dllcache\iecompat.dll 2009-06-25 14:57 –d—– c:\windows\ie8updates 2009-06-25 14:57 11,064,832 -c—— c:\windows\system32\dllcache\ieframe.dll 2009-06-25 14:57 1,985,024 -c—— c:\windows\system32\dllcache\iertutil.dll 2009-06-25 14:57 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll 2009-06-25 14:57 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll 2009-06-25 14:56 -cd-h— c:\windows\ie8 2009-06-25 13:43 3,426,072 a——- c:\windows\system32\d3dx9_32.dll 2009-06-25 13:43 –d—– c:\program files\Microsoft SQL Server Compact Edition 2009-06-25 13:42 –d—– c:\program files\Microsoft 2009-06-25 13:42 –d—– c:\program files\Windows Live SkyDrive 2009-06-25 13:13 –d—– c:\program files\common files\Windows Live 2009-06-25 12:49 –d—– c:\windows\system32\XPSViewer 2009-06-25 12:48 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-06-25 12:48 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-06-25 12:48 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-06-25 12:48 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-06-25 12:48 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-06-25 12:48 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-06-25 12:48 117,760 ——– c:\windows\system32\prntvpt.dll 2009-06-25 12:45 –d—– c:\windows\system32\URTTemp 2009-06-25 12:32 873,374 a——- c:\windows\system32\oem17.inf 2009-06-25 12:32 14,592 ac—— c:\windows\system32\dllcache\kbdhid.sys 2009-06-25 12:32 14,592 a——- c:\windows\system32\drivers\kbdhid.sys 2009-06-25 12:13 376 a——- c:\windows\ODBC.INI 2009-06-25 12:12 –d—– c:\program files\Microsoft ActiveSync 2009-06-25 12:11 –d—– c:\windows\ShellNew 2009-06-25 12:11 –d—– c:\program files\common files\L&H 2009-06-25 10:58 146,048 ac—— c:\windows\system32\dllcache\portcls.sys 2009-06-25 10:53 272,128 -c—— c:\windows\system32\dllcache\bthport.sys 2009-06-25 10:53 272,128 ——– c:\windows\system32\drivers\bthport.sys 2009-06-25 10:53 2,189,056 -c—— c:\windows\system32\dllcache\ntoskrnl.exe 2009-06-25 10:53 2,145,280 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe 2009-06-25 10:53 2,023,936 -c—— c:\windows\system32\dllcache\ntkrpamp.exe 2009-06-25 10:52 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys 2009-06-25 10:50 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-06-25 10:44 26,144 a——- c:\windows\system32\spupdsvc.exe 2009-06-25 10:44 –d—– c:\windows\system32\PreInstall 2009-06-25 10:44 –d-h— c:\windows\$hf_mig$ 2009-06-25 01:11 –d—– c:\windows\system32\SoftwareDistribution 2009-06-25 01:03 –d—– c:\docume~1\val\applic~1\uTorrent 2009-06-25 00:20 –d—– c:\program files\Accessories 2009-06-24 23:24 –d–r– C:\My Music 2009-06-24 22:18 –d—– c:\windows\Icon Resources 2009-06-24 22:07 –d—– C:\Temp 2009-06-24 22:02 –d—– c:\windows\system32\appmgmt 2009-06-24 21:59 1,391,104 a——- c:\windows\system32\drivers\BCMWL5.SYS 2009-06-24 21:59 –d—– c:\program files\Broadcom 2009-06-24 20:43 110,592 ——– c:\windows\system32\SmartAudio.cpl 2009-06-24 20:43 –d—– c:\program files\CONEXANT 2009-06-24 20:38 213,696 a——- c:\windows\system32\drivers\SynTP.sys 2009-06-24 20:38 196,608 a——- c:\windows\system32\SynCtrl.dll 2009-06-24 20:38 163,840 a——- c:\windows\system32\SynCOM.dll 2009-06-24 20:38 147,456 a——- c:\windows\system32\SynTPAPI.dll 2009-06-24 20:38 110,592 a——- c:\windows\system32\SynTPCo4.dll 2009-06-24 20:38 –d—– c:\program files\Synaptics 2009-06-24 20:28 126,976 a——- c:\windows\system32\Imsmudlg.exe 2009-06-24 20:28 –d—– c:\windows\system32\ENU 2009-06-24 20:23 –dsh— c:\documents and settings\val\UserData 2009-06-24 20:08 12,540 a——- c:\windows\system32\wpa.bak 2009-06-24 20:02 130,432 a——- c:\windows\system32\drivers\Rtnicxp.sys 2009-06-24 20:02 73,728 a——- c:\windows\system32\RtNicProp32.dll 2009-06-24 19:54 –d—– c:\windows\OPTIONS 2009-06-24 19:43 –d—– c:\windows\system32\ReinstallBackups 2009-06-24 19:43 –d—– C:\Intel 2009-06-24 16:08 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-06-24 16:08 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-06-24 16:07 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-24 16:07 –d—– c:\windows\system32\drivers\Avg 2009-06-24 16:07 –d—– c:\program files\AVG 2009-06-24 16:07 –d—– c:\docume~1\alluse~1\applic~1\avg8 2009-06-24 16:04 –d—– c:\windows\Downloaded Installations 2009-06-24 16:03 266,360 a——- c:\windows\system32\TweakUI.exe 2009-06-24 16:03 160,217 a——- c:\windows\system32\PowerToysLicense.rtf 2009-06-24 15:11 –d—– C:\Drop-Zone 2009-06-24 15:11 –d—– C:\Archive 2009-06-24 15:11 –d—– C:\Shared 2009-06-24 15:10 –d—– C:\Zztemp 2009-06-24 15:08 –d—– c:\documents and settings\Val 2009-06-24 15:07 –d—– c:\windows\IIS Temporary Compressed Files 2009-06-24 15:07 8,192 a——- c:\windows\REGLOCS.OLD 2009-06-24 15:05 65,536 ac—— c:\windows\system32\dllcache\EXCH_mailmsg.dll 2009-06-24 15:05 –d—– c:\program files\msn gaming zone 2009-06-24 15:04 –dsh— c:\documents and settings\all users\DRM 2009-06-24 15:04 –d-h— c:\program files\WindowsUpdate 2009-06-24 15:04 –d—– c:\program files\Online Services 2009-06-24 15:03 –d—– c:\program files\common files\MSSoap 2009-06-24 15:01 –d—– c:\program files\Windows NT 2009-06-24 10:59 –d—– c:\program files\common files\ODBC 2009-06-24 10:59 –d—– c:\program files\common files\SpeechEngines 2009-06-24 10:58 –d–r– c:\documents and settings\all users\Documents ==================== Find3M ==================== 2009-06-28 19:43 3,979,264 a——- c:\windows\system32\logonuiX.exe 2009-06-24 15:31 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-06-24 15:02 21,640 a——- c:\windows\system32\emptyregdb.dat 2009-06-24 14:35 1,614,848 a——- c:\windows\system32\sfcfiles.dll 2009-06-24 13:31 55,296 a——- c:\windows\system32\dvdplay.exe 2009-06-24 13:31 21,376 a——- c:\windows\system32\drivers\tsbvcap.sys 2009-06-24 13:31 18,688 a——- c:\windows\system32\drivers\cdaudio.sys 2009-06-24 13:31 12,160 a——- c:\windows\system32\drivers\mouhid.sys 2009-06-24 13:31 12,160 a——- c:\windows\system32\drivers\fsvga.sys 2009-06-24 13:31 8,192 a——- c:\windows\system32\tsbyuv.dll 2009-06-24 13:31 8,192 a——- c:\windows\system32\streamci.dll 2009-06-24 13:30 218,624 a——- c:\windows\system32\uxtheme.dll 2009-06-24 13:30 990,208 a——- c:\windows\system32\syssetup.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-05-13 01:15 915,456 a——- c:\windows\system32\wininet.dll 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll 2009-04-17 08:26 1,847,168 a——- c:\windows\system32\win32k.sys ============= FINISH: 0:18:01.62 =============== I'm guessing there's Something in my system preventing OTM from doing it's job? Here's hoping! Everything seems to be running well, though. I am just concerned about the OTM sequence of events. I sit something to truly be concerned about? Awaiting the Next Step…
Let's try a different approach.

Disable Windows Defender
  • Click Start > Programs > Windows Defender or launch from the system tray icon.
  • Click on Tools & Settings > Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
  • (When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)
We need to run a batch file.
  • Copy the contents of the Code Box below to Notepad.
  • Name the file as fix.bat
  • Change the Save as Type to All Files
  • and Save it on your Desktop
@echo off
if exist log.txt del /q log.txt
if exist err.txt del /q err.txt
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v "ProxyServer" /f >>log.txt 2>>err.txt
reg delete "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WinLogon" /v "Taskman" /f >>log.txt 2>>err.txt
del /a /q "c:\recycler\s-1-5-21-8418694959-2512096416-938368230-9084\rundll32.exe" >>log.txt 2>>err.txt
type err.txt>>log.txt
del /Q err.txt
notepad log.txt
del /Q %0
Then double-click on the fix.bat file. A log will open, please post the contents of that log in your next reply (unless blank).

Post another new DDS log so we can see if that worked, and then enable Windows Defender.
Ok, here's the log contents of the fix.bat: =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= The operation completed successfully The operation completed successfully Could Not Find c:\recycler\s-1-5-21-8418694959-2512096416-938368230-9084\rundll32.exe =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= Next step: the DSS.log: =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 9:05:39.84 on 16-Jul-09 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2474 [GMT -4:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\taskswitch.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Accessories\WinPatrol\winpatrol.exe C:\Program Files\Accessories\PowerISO\PWRISOVM.EXE C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe svchost.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Norton Ghost\Agent\VProSvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe C:\PROGRAM FILES\NORTON GHOST\AGENT\VPROTRAY.EXE C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Val\Desktop\06 - dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ uSearch Page = hxxp://search.live.com uInternet Settings,ProxyOverride = local mSearchAssistant = hxxp://search.live.com/sphome.aspx mWinlogon: UIHost=c:\program files\accessories\logon loader\logons\wciiibycerb\logonui.exe BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [CoolSwitch] c:\windows\system32\taskswitch.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe" mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRun: [WinPatrol] c:\program files\accessories\winpatrol\winpatrol.exe -expressboot mRun: [PWRISOVM.EXE] c:\program files\accessories\poweriso\PWRISOVM.EXE mRun: [] mRun: [BootSkin Startup Jobs] "c:\program files\accessories\wincustomize\bootskin\BootSkin.exe" /StartupJobs mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N uPolicies-explorer: NoSMMyPictures = 1 (0x1) mPolicies-system: DisableCAD = 1 (0x1) mPolicies-system: DisableStatusMessages = 1 (0x1) dPolicies-explorer: ForceClassicControlPanel = 1 (0x1) dPolicies-explorer: NoSMMyPictures = 1 (0x1) IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245900804640 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1245941092593 DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\val\applic~1\mozilla\firefox\profiles\qpxlqojl.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;= FF - prefs.js: browser.search.selectedEngine - Live Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;= FF - component: c:\documents and settings\val\application data\mozilla\firefox\profiles\qpxlqojl.default\extensions\{fcab6fdd-5585-425b-95c1-5ed856f3fd08}\components\nsCatcher.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-24 335752] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-24 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-24 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-24 907032] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-24 298776] R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2008-4-14 5120] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808] R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDAud.sys [2007-10-4 651776] R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2007-12-20 1558000] S0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys –> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?] S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] =============== Created Last 30 ================ 2009-07-13 20:43 –d—– C:\_OTM 2009-07-09 08:15 –d—– c:\program files\Trend Micro 2009-07-08 19:51 –d—– c:\documents and settings\all users\lx_Cats 2009-07-08 19:11 –d—– c:\docume~1\val\applic~1\Malwarebytes 2009-07-08 19:11 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-08 19:11 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-08 19:11 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-08 19:11 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-06 08:40 221,184 a——- c:\windows\system32\wmpns.dll 2009-07-05 22:31 –d—– c:\documents and settings\val\dwhelper 2009-06-29 23:51 42,240 a—-r– c:\windows\system32\drivers\ser2plms.sys 2009-06-29 23:47 –d—– c:\windows\RegisteredPackages 2009-06-29 23:47 –d—– c:\program files\Microsoft Streets & Trips 2009-06-29 23:47 –d—– c:\program files\Microsoft Location Finder 2009-06-29 23:12 –d—– c:\program files\HP 2009-06-29 23:03 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2009-06-29 23:03 0 a—h— c:\windows\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf 2009-06-29 23:02 1,560,576 a——- c:\windows\system32\BttnCmns_64.dll 2009-06-29 23:02 1,560,576 a——- c:\windows\system32\BttnCmns.dll 2009-06-29 23:02 1,419,232 a——- c:\windows\system32\wdfcoinstaller01005.dll 2009-06-29 23:02 987,136 a——- c:\windows\system32\BttnCmn.dll 2009-06-29 23:02 16,768 a——- c:\windows\system32\drivers\HpqKbFiltr.sys 2009-06-29 23:02 –d—– C:\SWSetup 2009-06-29 15:06 7,168 a–sh— c:\windows\Thumbs.db 2009-06-28 20:14 –d—– c:\program files\common files\Stardock 2009-06-28 20:14 163,712 a——- c:\windows\system32\drivers\vidstub.sys 2009-06-28 19:25 24 a——- c:\windows\LogonStudio.ini 2009-06-28 19:25 187,392 a——- c:\windows\system32\JPGUtils.dll 2009-06-28 19:24 –d—– c:\program files\WinCustomize 2009-06-28 16:04 –d—– c:\docume~1\val\applic~1\Marine Aquarium 3 2009-06-28 16:04 6,545,408 a——- c:\windows\system32\MarineAquarium3.scr 2009-06-28 15:23 –d—– c:\program files\Sonique 2009-06-28 09:56 445 a——- c:\windows\EntPack.dat 2009-06-27 21:23 –d—– c:\program files\common files\Macrovision Shared 2009-06-27 18:58 –d—– C:\logs 2009-06-27 18:12 –d—– C:\Animé 2009-06-27 11:33 –dsh— C:\$RECYCLE.BIN 2009-06-27 10:25 –ds—- C:\Images 2009-06-27 08:27 –d-hr– C:\VProRecovery 2009-06-26 15:07 –d-hr– c:\windows\system32\VProRecovery 2009-06-26 09:17 215,144 a—-r– c:\windows\patchw32.dll 2009-06-26 09:15 215,144 a—-r– c:\windows\pw32a.dll 2009-06-26 09:15 –d—– c:\docume~1\val\applic~1\Symantec 2009-06-26 09:10 1,060,864 a——- c:\windows\system32\MFC71.DLL 2009-06-26 09:10 503,808 a——- c:\windows\system32\MSVCP71.DLL 2009-06-26 09:10 –d—– c:\program files\Symantec 2009-06-26 09:09 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-06-26 09:09 16,168 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-06-26 09:09 128,104 a——- c:\windows\system32\drivers\WimFltr.sys 2009-06-26 09:09 38,112 a——- c:\windows\system32\drivers\v2imount.sys 2009-06-26 09:09 15,088 a——- c:\windows\system32\drivers\vproeventmonitor.sys 2009-06-26 09:09 137,952 a——- c:\windows\system32\drivers\symsnap.sys 2009-06-26 09:09 –d—– c:\program files\common files\Symantec Shared 2009-06-26 09:09 –d—– c:\program files\Norton Ghost 2009-06-26 09:09 –d—– c:\docume~1\alluse~1\applic~1\Symantec 2009-06-26 08:28 410,984 a——- c:\windows\system32\deploytk.dll 2009-06-26 07:51 268,648 a——- c:\windows\system32\mucltui.dll 2009-06-26 07:51 27,496 a——- c:\windows\system32\mucltui.dll.mui 2009-06-26 03:11 –d-h— C:\$AVG8.VAULT$ 2009-06-26 00:54 228,112 a——- c:\docume~1\val\applic~1\GDIPFONTCACHEV1.DAT 2009-06-25 23:27 –d—– C:\Torrent Drop-Zone 2009-06-25 23:16 –d—– c:\docume~1\alluse~1\applic~1\7Wonders2 2009-06-25 23:14 –d—– c:\docume~1\val\applic~1\7Wonders 2009-06-25 22:50 73,728 a——- c:\windows\system32\javacpl.cpl 2009-06-25 22:39 –dsh— c:\documents and settings\val\PrivacIE 2009-06-25 22:39 839,680 a——- c:\windows\system32\lameACM.acm 2009-06-25 22:39 168,448 a——- c:\windows\system32\unrar.dll 2009-06-25 22:39 414 a——- c:\windows\system32\lame_acm.xml 2009-06-25 22:39 38 a——- c:\windows\avisplitter.ini 2009-06-25 22:39 881,664 a——- c:\windows\system32\xvidcore.dll 2009-06-25 22:39 217,088 a——- c:\windows\system32\yv12vfw.dll 2009-06-25 22:39 118,784 a——- c:\windows\system32\ac3acm.acm 2009-06-25 22:38 3,596,288 a——- c:\windows\system32\qt-dx331.dll 2009-06-25 22:38 685,056 a——- c:\windows\system32\divx.dll 2009-06-25 22:38 205,824 a——- c:\windows\system32\xvidvfw.dll 2009-06-25 22:38 90,112 a——- c:\windows\system32\dpl100.dll 2009-06-25 22:38 85,504 a——- c:\windows\system32\ff_vfw.dll 2009-06-25 22:38 547 a——- c:\windows\system32\ff_vfw.dll.manifest 2009-06-25 22:38 348,160 a——- c:\windows\system32\MSVCR71.DLL 2009-06-25 22:38 –d—– c:\program files\K-Lite Codec Pack 2009-06-25 22:30 124 a——- c:\windows\entpack.ini 2009-06-25 21:12 –ds—- C:\Games 2009-06-25 17:44 –d—– c:\docume~1\val\applic~1\WinPatrol 2009-06-25 15:02 –dsh— c:\documents and settings\val\IETldCache 2009-06-25 14:57 102,912 -c—— c:\windows\system32\dllcache\iecompat.dll 2009-06-25 14:57 –d—– c:\windows\ie8updates 2009-06-25 14:57 11,064,832 -c—— c:\windows\system32\dllcache\ieframe.dll 2009-06-25 14:57 1,985,024 -c—— c:\windows\system32\dllcache\iertutil.dll 2009-06-25 14:57 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll 2009-06-25 14:57 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll 2009-06-25 14:56 -cd-h— c:\windows\ie8 2009-06-25 13:43 3,426,072 a——- c:\windows\system32\d3dx9_32.dll 2009-06-25 13:43 –d—– c:\program files\Microsoft SQL Server Compact Edition 2009-06-25 13:42 –d—– c:\program files\Microsoft 2009-06-25 13:42 –d—– c:\program files\Windows Live SkyDrive 2009-06-25 13:13 –d—– c:\program files\common files\Windows Live 2009-06-25 12:49 –d—– c:\windows\system32\XPSViewer 2009-06-25 12:48 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-06-25 12:48 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-06-25 12:48 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-06-25 12:48 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-06-25 12:48 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-06-25 12:48 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-06-25 12:48 117,760 ——– c:\windows\system32\prntvpt.dll 2009-06-25 12:45 –d—– c:\windows\system32\URTTemp 2009-06-25 12:32 873,374 a——- c:\windows\system32\oem17.inf 2009-06-25 12:32 14,592 ac—— c:\windows\system32\dllcache\kbdhid.sys 2009-06-25 12:32 14,592 a——- c:\windows\system32\drivers\kbdhid.sys 2009-06-25 12:13 376 a——- c:\windows\ODBC.INI 2009-06-25 12:12 –d—– c:\program files\Microsoft ActiveSync 2009-06-25 12:11 –d—– c:\windows\ShellNew 2009-06-25 12:11 –d—– c:\program files\common files\L&H; 2009-06-25 10:58 146,048 ac—— c:\windows\system32\dllcache\portcls.sys 2009-06-25 10:53 272,128 -c—— c:\windows\system32\dllcache\bthport.sys 2009-06-25 10:53 272,128 ——– c:\windows\system32\drivers\bthport.sys 2009-06-25 10:53 2,189,056 -c—— c:\windows\system32\dllcache\ntoskrnl.exe 2009-06-25 10:53 2,145,280 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe 2009-06-25 10:53 2,023,936 -c—— c:\windows\system32\dllcache\ntkrpamp.exe 2009-06-25 10:52 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys 2009-06-25 10:50 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-06-25 10:44 26,144 a——- c:\windows\system32\spupdsvc.exe 2009-06-25 10:44 –d—– c:\windows\system32\PreInstall 2009-06-25 10:44 –d-h— c:\windows\$hf_mig$ 2009-06-25 01:11 –d—– c:\windows\system32\SoftwareDistribution 2009-06-25 01:03 –d—– c:\docume~1\val\applic~1\uTorrent 2009-06-25 00:20 –d—– c:\program files\Accessories 2009-06-24 23:24 –d–r– C:\My Music 2009-06-24 22:18 –d—– c:\windows\Icon Resources 2009-06-24 22:07 –d—– C:\Temp 2009-06-24 22:02 –d—– c:\windows\system32\appmgmt 2009-06-24 21:59 1,391,104 a——- c:\windows\system32\drivers\BCMWL5.SYS 2009-06-24 21:59 –d—– c:\program files\Broadcom 2009-06-24 20:43 110,592 ——– c:\windows\system32\SmartAudio.cpl 2009-06-24 20:43 –d—– c:\program files\CONEXANT 2009-06-24 20:38 213,696 a——- c:\windows\system32\drivers\SynTP.sys 2009-06-24 20:38 196,608 a——- c:\windows\system32\SynCtrl.dll 2009-06-24 20:38 163,840 a——- c:\windows\system32\SynCOM.dll 2009-06-24 20:38 147,456 a——- c:\windows\system32\SynTPAPI.dll 2009-06-24 20:38 110,592 a——- c:\windows\system32\SynTPCo4.dll 2009-06-24 20:38 –d—– c:\program files\Synaptics 2009-06-24 20:28 126,976 a——- c:\windows\system32\Imsmudlg.exe 2009-06-24 20:28 –d—– c:\windows\system32\ENU 2009-06-24 20:23 –dsh— c:\documents and settings\val\UserData 2009-06-24 20:08 12,540 a——- c:\windows\system32\wpa.bak 2009-06-24 20:02 130,432 a——- c:\windows\system32\drivers\Rtnicxp.sys 2009-06-24 20:02 73,728 a——- c:\windows\system32\RtNicProp32.dll 2009-06-24 19:54 –d—– c:\windows\OPTIONS 2009-06-24 19:43 –d—– c:\windows\system32\ReinstallBackups 2009-06-24 19:43 –d—– C:\Intel 2009-06-24 16:08 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-06-24 16:08 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-06-24 16:07 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-24 16:07 –d—– c:\windows\system32\drivers\Avg 2009-06-24 16:07 –d—– c:\program files\AVG 2009-06-24 16:07 –d—– c:\docume~1\alluse~1\applic~1\avg8 2009-06-24 16:04 –d—– c:\windows\Downloaded Installations 2009-06-24 16:03 266,360 a——- c:\windows\system32\TweakUI.exe 2009-06-24 16:03 160,217 a——- c:\windows\system32\PowerToysLicense.rtf 2009-06-24 15:11 –d—– C:\Drop-Zone 2009-06-24 15:11 –d—– C:\Archive 2009-06-24 15:11 –d—– C:\Shared 2009-06-24 15:10 –d—– C:\Zztemp 2009-06-24 15:08 –d—– c:\documents and settings\Val 2009-06-24 15:07 –d—– c:\windows\IIS Temporary Compressed Files 2009-06-24 15:07 8,192 a——- c:\windows\REGLOCS.OLD 2009-06-24 15:05 65,536 ac—— c:\windows\system32\dllcache\EXCH_mailmsg.dll 2009-06-24 15:05 –d—– c:\program files\msn gaming zone 2009-06-24 15:04 –dsh— c:\documents and settings\all users\DRM 2009-06-24 15:04 –d-h— c:\program files\WindowsUpdate 2009-06-24 15:04 –d—– c:\program files\Online Services 2009-06-24 15:03 –d—– c:\program files\common files\MSSoap 2009-06-24 15:01 –d—– c:\program files\Windows NT 2009-06-24 10:59 –d—– c:\program files\common files\ODBC 2009-06-24 10:59 –d—– c:\program files\common files\SpeechEngines 2009-06-24 10:58 –d–r– c:\documents and settings\all users\Documents ==================== Find3M ==================== 2009-06-28 19:43 3,979,264 a——- c:\windows\system32\logonuiX.exe 2009-06-24 15:31 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-06-24 15:02 21,640 a——- c:\windows\system32\emptyregdb.dat 2009-06-24 14:35 1,614,848 a——- c:\windows\system32\sfcfiles.dll 2009-06-24 13:31 55,296 a——- c:\windows\system32\dvdplay.exe 2009-06-24 13:31 21,376 a——- c:\windows\system32\drivers\tsbvcap.sys 2009-06-24 13:31 18,688 a——- c:\windows\system32\drivers\cdaudio.sys 2009-06-24 13:31 12,160 a——- c:\windows\system32\drivers\mouhid.sys 2009-06-24 13:31 12,160 a——- c:\windows\system32\drivers\fsvga.sys 2009-06-24 13:31 8,192 a——- c:\windows\system32\tsbyuv.dll 2009-06-24 13:31 8,192 a——- c:\windows\system32\streamci.dll 2009-06-24 13:30 218,624 a——- c:\windows\system32\uxtheme.dll 2009-06-24 13:30 990,208 a——- c:\windows\system32\syssetup.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-05-13 01:15 915,456 a——- c:\windows\system32\wininet.dll 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll ============= FINISH: 9:05:58.93 =============== =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= That was painless enough ;) Next step?
Hi,

Log looks good, looks like it worked :thumbup:

This may not work as before, but it worth a try. If it doesn't work, just delete OTM manually.
Clean up with OTM
  • Double-click OTM.exe to run it.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
You can now delete any other tools I had you download and use, unless you wish to keep them.


Set correct settings for files that should be hidden in Windows Vista
  • Click Start.
  • Open My Computer.
  • Select Folder and Search Options
  • Select the View Tab.
  • Under the Hidden files and folders heading select Hide hidden files and folders.
  • Check Hide file extensions for known file types
  • Check the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.

Now that your system appears to be clean, there's just a few steps I'd like you to take to prevent any future infections.
  • System restore:
    We will now clear your existing system restore points and establish a new clean restore point:
    • Click on the Start button to open your Start Menu.
    • Click on the Control Panel menu option.
    • Click on the System and Maintenance menu option.
    • Click on the System menu option.
    • Click on System Protection in the left-hand task list.
    • Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
    • Type in a title for the manual restore point and press the Create button.
    • Close the System window after you have been advised that the procedure has been successfully completed.
    • Next, go to Start > Run and type in cleanmgr
    • Select the More options tab
    • Choose the option to clean up system restore and OK it.

      This will remove all restore points except the new one you just created.
    Make sure you do this now, as your System Restore currently has infected files in it.

  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Everything looks to be running well, and I get an "All Clean" message from all the assorted scanners I've run this laptop through. By George, I think we Got the Blightah! Thanks for all the timely and useful Help in this issue! I really depend on this system, and it's been rather stressful to have it crippled, even a little bit. Many Thanks, Again! ~TLoATDaE
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI