This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] TR.Redol.C

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am not sure what I did to deserve this but I have some nasty malware that I cannot remove. I will post my logs for further assistance. ANY assistance would be greatly appreciated. EDIT: I realize I was not specific enough, I am having a massive amount of annoying popup windows that are being blocked by Avira Antivirus. I ran SUPER Antispyware and Malwarebytes' numerous times and they say I am all free and clear but it continues to happen. My computer also does some weird blue screen memory dump on occasion and restarts itself. I do not have this problem in safe mode but I'm still stumped as to where it could be hiding.

Malwarebytes' Anti-Malware 1.39
Database version: 2433
Windows 6.0.6001 Service Pack 1

7/15/2009 7:11:47 PM
mbam-log-2009-07-15 (19-11-47).txt

Scan type: Quick Scan
Objects scanned: 84634
Time elapsed: 3 minute(s), 48 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 5

Memory Processes Infected:
C:\Windows\system32\sdra64.exe (Trojan.FakeAlert) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Userinit (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\sdra64.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\sdra64.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\userinit.exe,C:\Windows\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\Windows\system32\lowsec (Stolen.data) -> Delete on reboot.

Files Infected:
c:\windows\system32\lowsec\local.ds (Stolen.data) -> Delete on reboot.
c:\windows\system32\lowsec\user.ds (Stolen.data) -> Delete on reboot.
c:\windows\system32\lowsec\user.ds.lll (Stolen.data) -> Quarantined and deleted successfully.
C:\Windows\system32\sdra64.exe (Trojan.FakeAlert) -> Delete on reboot.
C:\Users\Symphonyj\AppData\Roaming\sdra64.exe (Trojan.Agent) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:26:09 PM, on 7/15/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [googletalk] C:\Users\Symphonyj\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 9868 bytes
[external image: Posted Image]

Hi Aaron, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I will be back to you shortly with instructions. :)
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • If you don't know or understand something, please don't hesitate to say or ask! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Please do not use any tools such as Combofix, Vundofix, or HijackThis fixes without instruction to do so!
  • Finally, stay with this topic until I give you the final 'All clear' post! :thumbup:

As you are running Vista, please run all of our tools by right clicking on them and selecting Run As Administrator.

I hate to the bearer of bad news but, your log shows a very dangerous Trojan is residing on your PC.

Trojan-Spy.Zbot.YETH is a rootkit trojan which steals online banking information and downloads other malware as well.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or it if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable and it would be wise to contact those same financial institutions to apprise them of your situation.

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?


1) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

2) GMER
Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop.

3) What You Will Need To Post:
  • DDS logs
  • GMER log
Well that is terrible news! But I have working around the clock to get some of the stuff off my computer and it is not as annoying as it used to be but I know something is lurking there still. Also, the only positive thing is that I do not have any credit cards on this machine that I online bank with, I do have my regular account with my bank and quicken but I have not used those since the virus…I think. The identify theft part scares me though and I need to stay ahead of everything as you said.
Anyways here are my logs. I attached and posted the "attach" file with DDS.

NOTE:I DID NOT receive a notice about a possible rootkit activity on the Rootkit/Malware tab when I ran GMER & the 'Show All' button is unticked. However I will run a scan just in case. Thanks again.

6:43 AM 7/17/2009
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 6:36:30.95 on Fri 07/17/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1014.126 [GMT -7:00]

AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: AntiVir Desktop *enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TVersity\Media Server\MediaServer.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Symphonyj\Desktop\dds.com
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.yahoo.com/
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit=c:\windows\system32\userinit.exe,userinit.exe,
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [googletalk] c:\users\symphonyj\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [OrderReminder] c:\program files\hewlett-packard\orderreminder\OrderReminder.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\users\sympho~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\users\sympho~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\sympho~1\appdata\roaming\mozilla\firefox\profiles\ovhuj0fc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\users\symphonyj\appdata\roaming\mozilla\firefox\profiles\ovhuj0fc.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071301000019.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-7-16 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-4-28 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-4-28 72944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-7 108289]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-7-16 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-7-16 51792]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-3-23 24652]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-4-28 7408]

=============== Created Last 30 ================

2009-07-16 15:46 91 a——- c:\windows\system32\hjgruixlsiwmld.dat
2009-07-16 15:38 1,702 a——- c:\windows\system32\hjgruiprfcbpdp.dat
2009-07-16 15:34 51,792 a——- c:\windows\system32\drivers\aswMonFlt.sys
2009-07-15 21:53 –d—– c:\program files\Panda Security
2009-07-15 21:22 –d—– c:\users\sympho~1\appdata\roaming\Uniblue
2009-07-15 19:25 –d—– c:\program files\Trend Micro
2009-07-15 18:58 –dsh— c:\users\sympho~1\appdata\roaming\lowsec
2009-07-15 18:54 –d—– c:\programdata\Windows Genuine Advantage
2009-07-15 15:46 289,792 a——- c:\windows\system32\atmfd.dll
2009-07-15 15:46 156,672 a——- c:\windows\system32\t2embed.dll
2009-07-15 15:46 72,704 a——- c:\windows\system32\fontsub.dll
2009-07-15 15:46 10,240 a——- c:\windows\system32\dciman32.dll
2009-07-14 23:00 –d—– c:\users\symphonyj\DoctorWeb
2009-07-14 22:58 –d—– c:\program files\Security Stronghold
2009-07-14 20:30 –d—– c:\users\sympho~1\appdata\roaming\Malwarebytes
2009-07-14 20:30 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-14 20:30 –d—– c:\programdata\Malwarebytes
2009-07-14 20:30 –d—– c:\progra~2\Malwarebytes
2009-07-14 20:30 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-14 20:30 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-14 20:20 –d—– c:\program files\True Sword 5
2009-07-13 10:25 91 a——- c:\windows\system32\hjgruiecwbjxxi.dat
2009-07-13 09:47 56,649 a——- c:\windows\system32\hjgruicsywspqq.dat
2009-07-05 12:46 60,273 a——- c:\windows\system32\pthreadGC2.dll
2009-07-05 12:46 7,680 a——- c:\windows\system32\ff_vfw.dll
2009-07-05 12:46 547 a——- c:\windows\system32\ff_vfw.dll.manifest
2009-07-05 12:46 –d—– c:\program files\ffdshow
2009-07-05 12:45 –d—– c:\program files\TVersity Codec Pack
2009-07-05 12:42 –d—– c:\program files\TVersity
2009-07-05 09:44 –d—– c:\program files\dayam NFO Viewer
2009-07-04 15:22 107,368 a——- c:\windows\system32\GEARAspi.dll
2009-07-04 15:22 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-04 15:22 –d—– c:\program files\iPod
2009-07-04 15:22 –d—– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-04 15:22 –d—– c:\program files\iTunes
2009-07-04 15:22 –d—– c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-04 15:12 –d—– c:\program files\Bonjour

==================== Find3M ====================

2009-07-04 15:19 143,360 a——- c:\windows\inf\infstrng.dat
2009-07-04 15:19 86,016 a——- c:\windows\inf\infstor.dat
2009-07-04 15:19 51,200 a——- c:\windows\inf\infpub.dat
2009-06-05 08:36 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-05-14 12:01 0 a——- c:\users\sympho~1\appdata\roaming\wklnhst.dat
2009-05-07 09:51 174 a–sh— c:\program files\desktop.ini
2009-05-07 09:32 665,600 a——- c:\windows\inf\drvindex.dat
2009-05-07 08:55 101,888 a——- c:\windows\system32\ifxcardm.dll
2009-05-07 08:54 82,432 a——- c:\windows\system32\axaltocm.dll
2009-05-05 21:17 604,416 a——- c:\windows\system32\TUProgSt.exe
2009-05-05 20:23 81,920 a——- c:\users\sympho~1\appdata\roaming\ezpinst.exe
2009-05-05 20:23 47,360 a——- c:\users\sympho~1\appdata\roaming\pcouffin.sys
2009-05-05 20:02 87,608 a——- c:\users\sympho~1\appdata\roaming\inst.exe
2009-05-02 02:57 17,466,368 a——- c:\windows\TU2009TrialEN-US.exe
2009-05-01 11:30 3,366,912 a——- c:\windows\system32\GPhotos.scr
2009-04-30 05:37 293,376 a——- c:\windows\system32\psisdecd.dll
2009-04-30 05:37 428,544 a——- c:\windows\system32\EncDec.dll
2009-04-24 09:05 827,904 a——- c:\windows\system32\wininet.dll
2009-04-24 09:02 78,336 a——- c:\windows\system32\ieencode.dll
2009-04-24 06:44 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-04-23 05:43 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 05:42 636,928 a——- c:\windows\system32\localspl.dll
2009-04-21 04:55 2,033,152 a——- c:\windows\system32\win32k.sys
2008-03-23 21:13 32 a——- c:\programdata\ezsid.dat
2008-03-23 21:13 32 a——- c:\progra~2\ezsid.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 6:37:25.78 ===============

Attachments:

1) Too Many Antivirus Programs
avast! Antivirus
Avira AntiVir
Norton Internet Security (Symantec Corporation)


It is only advisable to run one antivirus program at one time. We need to keep one, and uninstall the rest. I believe you use AntiVir mainly - but DDS reports that it isn't up to date. What do you want to do?

2) Combofix
Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Right click on Combo-Fix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

3) What You Will Need To Post:
  • Combofix log
  • The contents of C:\QooBox\Add-Remove Programs.txt
  • How your computer is performing now
I am not sure if I am doing this all right but here goes nothing! My computer no longer has those annoying popups and seems to be functioning well. I also opted to uninstall all my anti-viruses and download AVG and will update the software for better protection. Here are my logs. ALSO included is my GMER Log which finished earlier,.

abgx360 v1.0.1
Activation Assistant for the 2007 Microsoft Office suites
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 8
AnswerWorks 5.0 English Runtime
Apple Mobile Device Support
Apple Software Update
Ashampoo Burning Studio 8.04
AVG Free 8.5
Bonjour
CCleaner (remove only)
CloneDVD2
DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.2.5.0
ESU for Microsoft Vista
ffdshow [rev 1723] [2007-12-24]
Google Talk (remove only)
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Active Support Library 32 bit components
HP Customer Experience Enhancements
HP Doc Viewer
HP Easy Setup - Frontend
HP Help and Support
HP OrderReminder
HP Photosmart Essential 2.0
HP Photosmart Essential2.5
HP Quick Launch Buttons 6.20 B1
HP QuickPlay 3.2
HP Total Care Advisor
HP Update
HP User Guides 0057
HP Wireless Assistant
HPNetworkAssistant
ImgBurn
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes
Java™ SE Runtime Environment 6
LaserJet 1018
LightScribe 1.4.136.1
Malwarebytes' Anti-Malware
Microsoft .NET Framework 3.5 SP1
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
Motorola SM56 Data Fax Modem
Move Networks Media Player for Internet Explorer
Mozilla Firefox (3.5.1)
MSCU for Microsoft Vista
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
muvee autoProducer 6.0
My HP Games
NewsBin Pro
Norton Internet Security (Symantec Corporation)
Picasa 3
Plants vs. Zombies 1.0.0.1051
PSSWCORE
Quicken 2009
QuickPar 0.9
QuickTime
Realtek High Definition Audio Driver
Rhapsody
Rhapsody Player Engine
Roxio Activation Module
Roxio Creator Audio
Roxio Creator Basic v9
Roxio Creator Copy
Roxio Creator Data
Roxio Creator EasyArchive
Roxio Creator Tools
Roxio Express Labeler 3
Roxio MyDVD Basic v9
Skype™ 3.6
SUPERAntiSpyware Free Edition
Synaptics Pointing Device Driver
TVersity Codec Pack 1.2
TVersity Media Server 1.6 Beta
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Viewpoint Media Player
VLC media player 0.9.9
Windows Media Player Firefox Plugin
WinRAR archiver
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger

ComboFix 09-07-14.08 - Symphonyj 07/17/2009 21:06.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1014.158 [GMT -7:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-3156202997-2437307568-1721409413-500
c:\$recycle.bin\S-1-5-21-4055113683-2864743704-3741799464-500
c:\users\Symphonyj\AppData\Roaming\inst.exe
c:\windows\system32\hjgruicsywspqq.dat
c:\windows\system32\hjgruiecwbjxxi.dat
c:\windows\system32\hjgruiprfcbpdp.dat
c:\windows\system32\hjgruixlsiwmld.dat

.
((((((((((((((((((((((((( Files Created from 2009-06-18 to 2009-07-18 )))))))))))))))))))))))))))))))
.

2009-07-18 03:51 . 2009-07-18 03:51 ——– d—–w- c:\users\Symphonyj\AppData\Local\AVG Security Toolbar
2009-07-18 03:48 . 2009-07-18 03:48 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-07-18 03:48 . 2009-07-18 03:48 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-07-18 03:48 . 2009-07-18 03:48 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-18 03:48 . 2009-07-18 03:48 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-18 03:48 . 2009-07-18 03:50 ——– d—–w- c:\windows\system32\drivers\Avg
2009-07-18 03:48 . 2009-07-18 03:48 ——– d—–w- c:\programdata\AVG Security Toolbar
2009-07-18 03:48 . 2009-07-18 03:48 ——– d—–w- c:\program files\AVG
2009-07-18 03:48 . 2009-07-18 03:48 ——– d—–w- c:\programdata\avg8
2009-07-16 22:34 . 2009-07-16 22:34 ——– d—–w- c:\program files\Alwil Software
2009-07-16 21:23 . 2009-07-16 21:23 ——– d—–w- c:\users\Symphonyj\AppData\Local\Apple
2009-07-16 21:22 . 2009-07-16 21:22 ——– d—–w- c:\users\Symphonyj\AppData\Local\Apple Computer
2009-07-16 04:53 . 2009-07-16 21:37 ——– d—–w- c:\program files\Panda Security
2009-07-16 04:22 . 2009-07-16 04:22 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Uniblue
2009-07-16 02:25 . 2009-07-16 02:25 ——– d—–w- c:\program files\Trend Micro
2009-07-16 01:58 . 2009-07-16 01:58 ——– d-sh–w- c:\users\Symphonyj\AppData\Roaming\lowsec
2009-07-15 22:46 . 2009-06-15 15:24 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-07-15 22:46 . 2009-06-15 15:20 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-07-15 22:46 . 2009-06-15 15:20 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-07-15 22:46 . 2009-06-15 12:52 289792 —-a-w- c:\windows\system32\atmfd.dll
2009-07-15 06:00 . 2009-07-15 06:00 ——– d—–w- c:\users\Symphonyj\DoctorWeb
2009-07-15 05:58 . 2009-07-15 05:58 ——– d—–w- c:\program files\Security Stronghold
2009-07-15 03:30 . 2009-07-15 03:30 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Malwarebytes
2009-07-15 03:30 . 2009-07-13 20:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-15 03:30 . 2009-07-15 03:30 ——– d—–w- c:\programdata\Malwarebytes
2009-07-15 03:30 . 2009-07-15 03:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-15 03:30 . 2009-07-13 20:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-15 03:20 . 2009-07-16 03:36 ——– d—–w- c:\program files\True Sword 5
2009-07-05 19:46 . 2007-12-24 20:47 7680 —-a-w- c:\windows\system32\ff_vfw.dll
2009-07-05 19:46 . 2007-11-29 19:52 60273 —-a-w- c:\windows\system32\pthreadGC2.dll
2009-07-05 19:46 . 2009-07-05 19:46 ——– d—–w- c:\program files\ffdshow
2009-07-05 19:45 . 2009-07-15 05:59 ——– d—–w- c:\program files\TVersity Codec Pack
2009-07-05 19:42 . 2009-07-05 19:42 ——– d—–w- c:\program files\TVersity
2009-07-05 16:44 . 2009-07-05 16:44 ——– d—–w- c:\program files\dayam NFO Viewer
2009-07-04 22:22 . 2009-03-19 23:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-04 22:22 . 2008-04-17 19:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-07-04 22:22 . 2009-07-04 22:22 ——– d—–w- c:\program files\iPod
2009-07-04 22:22 . 2009-07-04 22:22 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-04 22:22 . 2009-07-04 22:22 ——– d—–w- c:\program files\iTunes
2009-07-04 22:21 . 2009-07-04 22:21 ——– d—–w- c:\program files\QuickTime
2009-07-04 22:14 . 2009-07-04 22:14 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-07-04 22:12 . 2009-07-04 22:12 ——– d—–w- c:\program files\Bonjour
2009-06-28 19:09 . 2009-06-28 19:09 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-18 04:00 . 2009-05-09 14:43 117760 —-a-w- c:\users\Symphonyj\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-17 04:21 . 2007-05-14 12:02 ——– d—–w- c:\program files\Yahoo!
2009-07-15 10:02 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-07-15 05:59 . 2009-05-09 14:38 ——– d—–w- c:\program files\CCleaner
2009-07-15 05:59 . 2009-05-10 01:38 ——– d—–w- c:\program files\QuickPar
2009-07-15 05:59 . 2009-05-10 00:59 ——– d—–w- c:\program files\NewsBin
2009-07-15 02:07 . 2008-04-01 23:08 1356 —-a-w- c:\users\Symphonyj\AppData\Local\d3d9caps.dat
2009-07-04 22:22 . 2008-12-22 01:57 ——– d—–w- c:\program files\Common Files\Apple
2009-07-04 22:22 . 2008-12-22 01:58 ——– d—–w- c:\programdata\Apple Computer
2009-06-26 05:45 . 2009-05-10 03:16 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\dvdcss
2009-06-24 20:21 . 2009-05-09 14:42 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-06-23 14:59 . 2008-09-01 22:27 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Yahoo!
2009-06-17 14:23 . 2009-06-16 02:11 ——– d—–w- c:\program files\Quicken
2009-06-17 14:22 . 2009-06-17 14:22 3616768 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181311-181414.dll
2009-06-17 14:22 . 2009-06-17 14:22 2904064 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\18154-181625.dll
2009-06-17 14:22 . 2009-06-17 14:22 1007616 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181129-181212.dll
2009-06-17 14:22 . 2009-06-17 14:22 1536000 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181414-18154.dll
2009-06-17 14:22 . 2009-06-17 14:22 242976 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2009-06-17 14:22 . 2009-06-17 14:22 811008 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181212-181311.dll
2009-06-17 14:22 . 2009-06-17 14:22 223584 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\patchw32.dll
2009-06-17 14:22 . 2009-06-17 14:22 997 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\rebase.cmd
2009-06-16 02:12 . 2009-06-16 02:12 ——– d—–w- c:\program files\Common Files\AnswerWorks 5.0
2009-06-16 02:12 . 2007-05-14 11:10 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-16 02:12 . 2009-06-16 02:12 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Intuit
2009-06-16 02:11 . 2009-06-16 02:11 ——– d—–w- c:\program files\Common Files\Intuit
2009-06-16 02:11 . 2009-06-16 02:11 ——– d—–w- c:\programdata\Intuit
2009-06-16 02:09 . 2009-06-16 02:08 ——– d—–w- c:\program files\MagicDisc
2009-06-05 15:36 . 2009-06-05 15:36 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-06-04 02:10 . 2008-03-21 23:41 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Hewlett-Packard
2009-06-03 03:10 . 2007-05-14 11:07 ——– d—–w- c:\program files\Hewlett-Packard
2009-06-03 03:10 . 2009-06-03 03:10 ——– d–h–w- c:\program files\Zenographics
2009-05-30 23:27 . 2009-05-30 23:27 ——– d—–w- c:\programdata\Elaborate Bytes
2009-05-25 17:44 . 2009-05-25 17:44 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\InstallShield
2009-05-24 23:07 . 2009-05-24 23:07 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Ashampoo
2009-05-24 23:06 . 2009-05-24 23:06 ——– d—–w- c:\programdata\ashampoo
2009-05-24 23:06 . 2009-05-24 23:06 ——– d—–w- c:\program files\Ashampoo
2009-05-15 22:29 . 2009-05-15 22:29 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-14 19:01 . 2009-05-14 19:01 0 —-a-w- c:\users\Symphonyj\AppData\Roaming\wklnhst.dat
2009-05-08 03:29 . 2009-05-08 03:29 79367 —-a-w- c:\users\Symphonyj\AppData\Roaming\Google\Google Talk\uninstall.exe
2009-05-07 16:32 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-05-07 15:55 . 2006-11-02 10:32 101888 —-a-w- c:\windows\system32\ifxcardm.dll
2009-05-07 15:54 . 2006-11-02 10:32 82432 —-a-w- c:\windows\system32\axaltocm.dll
2009-05-06 04:17 . 2009-05-06 04:17 604416 —-a-w- c:\windows\system32\TUProgSt.exe
2009-05-06 03:23 . 2009-05-06 02:43 81920 —-a-w- c:\users\Symphonyj\AppData\Roaming\ezpinst.exe
2009-05-06 03:23 . 2009-05-06 02:43 81920 —-a-w- c:\users\Symphonyj\AppData\Roaming\ezpinst.exe
2009-05-06 03:23 . 2009-05-06 02:43 47360 —-a-w- c:\users\Symphonyj\AppData\Roaming\pcouffin.sys
2009-05-06 03:23 . 2009-05-06 02:43 47360 —-a-w- c:\users\Symphonyj\AppData\Roaming\pcouffin.sys
2009-05-06 03:02 . 2009-05-06 02:43 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-05-02 09:57 . 2009-05-06 04:00 17466368 —-a-w- c:\windows\TU2009TrialEN-US.exe
2009-05-01 18:30 . 2009-05-01 18:30 3366912 —-a-w- c:\windows\system32\GPhotos.scr
2009-04-30 12:37 . 2009-06-13 13:32 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-04-30 12:37 . 2009-06-13 13:32 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-04-24 16:05 . 2009-06-10 16:11 827904 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-10 16:11 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-10 16:11 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-23 12:43 . 2009-06-10 16:11 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 16:11 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-10 16:11 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-07-17 16:59 . 2009-05-07 14:55 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 23:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"googletalk"="c:\users\Symphonyj\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-24 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 729088]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-24 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 133656]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-18 1948440]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-09 4390912]

c:\users\Symphonyj\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-6-15 576000]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Health Check Scheduler"=c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe"
"HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EA0C20ED-50D6-4998-AACA-C0D310A80BE5}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8EA343CA-D542-4005-95AE-932D1888BE3F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{718A99E6-21DE-424D-B6A4-5E2CD182C414}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{24D44D86-8E9D-49F2-A8BB-544C4D43499C}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{93BF56AB-3C6F-4CA6-8B06-D524AC1EA4BA}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{62EA0F59-EFA4-4B82-A406-03A4ECFA8083}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{E233FE72-FC8A-4994-811C-52BB58F69624}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{611E3E15-27D0-4CB2-872C-07D31887E8B2}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4EC59A9F-069E-47CA-9058-1BBC5ACC7A0D}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{619B8FDD-DDB0-4CEE-8FD0-FAD8995907C6}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{CE823274-DF58-4894-9AE5-CECCBF2AC440}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{D8D497C9-3829-43AE-914B-94037DFBC13E}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{00EC4F89-A172-4BB3-935C-3632E035EFAE}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B03708E1-D5DB-43FE-BC51-A777FBE087F5}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{274D9A44-2E25-4DE6-94FF-6849C116BBBA}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{40F979D9-50E5-402E-B984-CA4B925AF4B4}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FC7274B6-A1CA-49F3-981E-E96DC96B79BA}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{13DC6BD9-C42E-4FFE-A7AF-EF23C80665FC}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{79BF3829-79B0-4EDA-AFA1-FB521B37CC09}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{87CC50A0-8548-4A41-AF6C-25F9BE313D26}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D977FB8D-2B61-4CC2-9A00-D331D6893C50}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{1D4323B3-8F34-41CD-A6F9-EB40AB0784DB}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{A9ED4B1F-83EF-4BC8-B020-589B8696B044}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{5BAB2A87-62CF-4432-8230-FE52521EDE1D}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"{5BC84662-3125-4A32-8ACF-F68DCDDF14FC}"= UDP:c:\program files\NewsBin\nbpro.exe:NewsBin Pro
"{8A489F20-9FF4-4FB9-9BD3-77E92BAF5CA1}"= TCP:c:\program files\NewsBin\nbpro.exe:NewsBin Pro
"{8BF5904E-8593-4643-860B-8E1745170023}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{479DBA54-76BA-4691-B95E-DBF2C0E97E5B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{F3E1F9C5-0098-4787-90E7-E74363C56A7D}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{59BE1BD1-DA8E-41E8-ACEB-1B4930632E18}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{ADD6F2AA-293C-4C4F-A8F8-E2B64803510C}"= UDP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server
"{ADC79135-ECFB-468C-982E-6A7D7ECA1EB6}"= TCP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server
"{5C7A0703-8481-4443-8E41-54F25ECAA0DA}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{C6D8EDA4-275E-437D-AAAE-30A209D408AA}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{49EBE5D4-1851-4792-8EB6-C4AC21EB105A}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-07-18 327688]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-07-18 108552]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-28 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-04-28 72944]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-07-18 906520]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-07-18 298776]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-04-28 7408]

.
Contents of the 'Scheduled Tasks' folder

2009-07-18 c:\windows\Tasks\User_Feed_Synchronization-{68917C52-2748-4C51-A219-E6D9C3FAF19C}.job
- c:\windows\system32\msfeedssync.exe [2008-08-30 07:33]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\uniblue\registrybooster\StartRegistryBooster.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Symphonyj\AppData\Roaming\Mozilla\Firefox\Profiles\ovhuj0fc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\users\Symphonyj\AppData\Roaming\Mozilla\Firefox\Profiles\ovhuj0fc.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071301000019.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-17 21:14
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-07-18 21:18
ComboFix-quarantined-files.txt 2009-07-18 04:18

Pre-Run: 79,487,758,336 bytes free
Post-Run: 79,543,521,280 bytes free

356 — E O F — 2009-07-17 09:29

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-17 08:53:14
Windows 6.0.6001 Service Pack 1


—- System - GMER 1.0.15 —-

SSDT A91236EC ZwCreateThread
SSDT A91236D8 ZwOpenProcess
SSDT A91236DD ZwOpenThread
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys ZwTerminateProcess [0x8D091DF0]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetTimerEx + 454 81F04A18 4 Bytes [EC, 36, 12, A9]
.text ntkrnlpa.exe!KeSetTimerEx + 624 81F04BE8 4 Bytes [D8, 36, 12, A9]
.text ntkrnlpa.exe!KeSetTimerEx + 640 81F04C04 4 Bytes [DD, 36, 12, A9]
.text ntkrnlpa.exe!KeSetTimerEx + 854 81F04E18 4 Bytes [F0, 1D, 09, 8D]
? system32\drivers\ryaud.sys The system cannot find the path specified. !

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Windows\system32\services.exe[636] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00060002
IAT C:\Windows\system32\services.exe[636] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 00060000

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Sorry for the unexpected delay, Aaron.

1) Uninstall Some Programs
It looks like Norton Internet Security is still hiding in there.
Please uninstall Norton Internet Security (Symantec Corporation). If you have any problems with this, let me know, as there are other ways to remove it if it is too stubborn.

2) Combofix Script
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Folder::
    c:\program files\Panda Security
    c:\users\Symphonyj\AppData\Roaming\lowsec
    c:\users\Symphonyj\AppData\Roaming\Uniblue
    c:\program files\Alwil Software
    c:\program files\True Sword 5
    c:\program files\Security Stronghold
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

3) What You Will Need To Post:
  • The new Combofix log
  • How the machine appears to be performing now :)
Don't worry about the delay, I am sure you are extremely busy and I am extremely grateful for your assistance.

1.) I tried uninstalling symantec completely, but when it gets to the point of a directory.txt file it gets an error and I have to force close.

2.) Here is the ComboFix log:

ComboFix 09-07-19.01 - Symphonyj 07/19/2009 9:31.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1014.165 [GMT -7:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\Symphonyj\Desktop\CFScript.txt
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Alwil Software
c:\program files\Alwil Software\Avast4\DATA\log\Error.log
c:\program files\Alwil Software\Avast4\Setup\setup.ini
c:\program files\Panda Security
c:\program files\Security Stronghold
c:\program files\Security Stronghold\Registry Cleaner\backuped\31\backuped_key.dat
c:\program files\Security Stronghold\Registry Cleaner\backuped\45\backuped_key.dat
c:\program files\Security Stronghold\Registry Cleaner\backups.ini
c:\program files\Security Stronghold\Registry Cleaner\circle-hlra (2).lnk
c:\program files\Security Stronghold\Registry Cleaner\circle-hlra.lnk
c:\program files\Security Stronghold\Registry Cleaner\night.at.the.museum.2.r5.line.xvid-kamera.lnk
c:\program files\Security Stronghold\Registry Cleaner\options.ini
c:\program files\Security Stronghold\Registry Cleaner\Uninstall CCleaner.lnk
c:\program files\Security Stronghold\Registry Cleaner\Uninstall NewsBin Pro.lnk
c:\program files\Security Stronghold\Registry Cleaner\Uninstall.lnk
c:\program files\Security Stronghold\Registry Cleaner\Videos.lnk
c:\program files\True Sword 5
c:\program files\True Sword 5\backuped\0\symphonyj@live365[1].txt
c:\program files\True Sword 5\backuped\2\hkcmd.exe
c:\program files\True Sword 5\backuped\3\backuped_value.dat
c:\program files\True Sword 5\backuped\4\Uninst.exe
c:\program files\True Sword 5\backuped\5\uninst.exe
c:\program files\True Sword 5\backuped\6\uninst.exe
c:\program files\True Sword 5\backuped\7\uninst.exe
c:\program files\True Sword 5\backuped\8\Uninst.exe
c:\program files\True Sword 5\backuped\9\uninst.exe
c:\program files\True Sword 5\backups.ini
c:\program files\True Sword 5\database.db
c:\program files\True Sword 5\options.ini
c:\program files\True Sword 5\RegistrationLog.txt
c:\users\Symphonyj\AppData\Roaming\lowsec
c:\users\Symphonyj\AppData\Roaming\lowsec\local.ds
c:\users\Symphonyj\AppData\Roaming\lowsec\user.ds
c:\users\Symphonyj\AppData\Roaming\Uniblue
c:\users\Symphonyj\AppData\Roaming\Uniblue\Registry Booster2\1247718344.zip
c:\users\Symphonyj\AppData\Roaming\Uniblue\Registry Booster2\F_1247718271.zip
c:\users\Symphonyj\AppData\Roaming\Uniblue\Registry Booster2\ignorelist.dat
c:\users\Symphonyj\AppData\Roaming\Uniblue\Registry Booster2\problems.html
c:\users\Symphonyj\AppData\Roaming\Uniblue\Registry Booster2\RBLog.dat

.
((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 )))))))))))))))))))))))))))))))
.

2009-07-18 20:20 . 2009-07-18 20:20 ——– d—–w- c:\users\Symphonyj\AppData\Local\Apple
2009-07-18 15:35 . 2009-07-18 15:35 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-07-18 05:09 . 2009-07-18 06:14 ——– d–h–w- C:\$AVG8.VAULT$
2009-07-18 04:43 . 2009-07-18 03:48 327688 —-a-w- c:\programdata\avg8\update\backup\avgldx86.sys
2009-07-18 04:43 . 2009-07-18 03:48 692504 —-a-w- c:\programdata\avg8\update\backup\avgcsrvx.exe
2009-07-18 04:43 . 2009-07-18 03:48 417560 —-a-w- c:\programdata\avg8\update\backup\avgcclix.dll
2009-07-18 04:43 . 2009-07-18 03:48 382744 —-a-w- c:\programdata\avg8\update\backup\avgclitx.dll
2009-07-18 04:43 . 2009-07-18 03:48 69912 —-a-w- c:\programdata\avg8\update\backup\avgcrlpx.dll
2009-07-18 04:43 . 2009-07-18 03:48 2301208 —-a-w- c:\programdata\avg8\update\backup\avguiadv.dll
2009-07-18 04:43 . 2009-07-18 03:48 2052888 —-a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-07-18 04:43 . 2009-07-18 03:48 3298072 —-a-w- c:\programdata\avg8\update\backup\setup.exe
2009-07-18 04:43 . 2009-07-18 03:48 3402008 —-a-w- c:\programdata\avg8\update\backup\avgui.exe
2009-07-18 04:43 . 2009-07-18 03:48 1204504 —-a-w- c:\programdata\avg8\update\backup\avgabout.dll
2009-07-18 04:43 . 2009-07-18 03:48 1107224 —-a-w- c:\programdata\avg8\update\backup\avgssie.dll
2009-07-18 04:42 . 2009-07-18 03:48 337176 —-a-w- c:\programdata\avg8\update\backup\avglogx.dll
2009-07-18 04:42 . 2009-07-18 03:48 829208 —-a-w- c:\programdata\avg8\update\backup\avgcfgx.dll
2009-07-18 04:42 . 2009-07-18 03:48 2167576 —-a-w- c:\programdata\avg8\update\backup\avgresf.dll
2009-07-18 04:42 . 2009-07-18 03:48 906520 —-a-w- c:\programdata\avg8\update\backup\avgemc.exe
2009-07-18 04:42 . 2009-07-18 03:48 1454360 —-a-w- c:\programdata\avg8\update\backup\avgupd.dll
2009-07-18 04:42 . 2009-07-18 03:48 1085208 —-a-w- c:\programdata\avg8\update\backup\avgupd.exe
2009-07-18 03:51 . 2009-07-18 03:51 ——– d—–w- c:\users\Symphonyj\AppData\Local\AVG Security Toolbar
2009-07-18 03:48 . 2009-07-18 03:48 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-07-18 03:48 . 2009-07-18 03:48 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-07-18 03:48 . 2009-07-18 04:42 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-18 03:48 . 2009-07-18 03:48 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-18 03:48 . 2009-07-19 16:20 ——– d—–w- c:\windows\system32\drivers\Avg
2009-07-18 03:48 . 2009-07-18 03:48 ——– d—–w- c:\programdata\AVG Security Toolbar
2009-07-18 03:48 . 2009-07-18 03:48 ——– d—–w- c:\program files\AVG
2009-07-18 03:48 . 2009-07-18 03:48 ——– d—–w- c:\programdata\avg8
2009-07-16 02:25 . 2009-07-16 02:25 ——– d—–w- c:\program files\Trend Micro
2009-07-15 22:46 . 2009-06-15 15:24 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-07-15 22:46 . 2009-06-15 15:20 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-07-15 22:46 . 2009-06-15 15:20 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-07-15 22:46 . 2009-06-15 12:52 289792 —-a-w- c:\windows\system32\atmfd.dll
2009-07-15 06:00 . 2009-07-15 06:00 ——– d—–w- c:\users\Symphonyj\DoctorWeb
2009-07-15 03:30 . 2009-07-15 03:30 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Malwarebytes
2009-07-15 03:30 . 2009-07-13 20:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-15 03:30 . 2009-07-15 03:30 ——– d—–w- c:\programdata\Malwarebytes
2009-07-15 03:30 . 2009-07-15 03:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-15 03:30 . 2009-07-13 20:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-05 19:46 . 2007-12-24 20:47 7680 —-a-w- c:\windows\system32\ff_vfw.dll
2009-07-05 19:46 . 2007-11-29 19:52 60273 —-a-w- c:\windows\system32\pthreadGC2.dll
2009-07-05 19:46 . 2009-07-05 19:46 ——– d—–w- c:\program files\ffdshow
2009-07-05 19:45 . 2009-07-15 05:59 ——– d—–w- c:\program files\TVersity Codec Pack
2009-07-05 19:42 . 2009-07-05 19:42 ——– d—–w- c:\program files\TVersity
2009-07-05 16:44 . 2009-07-05 16:44 ——– d—–w- c:\program files\dayam NFO Viewer
2009-07-04 22:22 . 2009-03-19 23:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-04 22:22 . 2008-04-17 19:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-07-04 22:22 . 2009-07-04 22:22 ——– d—–w- c:\program files\iPod
2009-07-04 22:22 . 2009-07-04 22:22 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-04 22:22 . 2009-07-04 22:22 ——– d—–w- c:\program files\iTunes
2009-07-04 22:21 . 2009-07-04 22:21 ——– d—–w- c:\program files\QuickTime
2009-07-04 22:14 . 2009-07-04 22:14 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-07-04 22:12 . 2009-07-04 22:12 ——– d—–w- c:\program files\Bonjour
2009-06-28 19:09 . 2009-06-28 19:09 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 16:07 . 2007-05-14 11:31 ——– d—–w- c:\programdata\Symantec
2009-07-19 06:00 . 2009-05-09 14:43 117760 —-a-w- c:\users\Symphonyj\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-18 15:35 . 2007-05-14 12:30 ——– d—–w- c:\program files\Java
2009-07-17 04:21 . 2007-05-14 12:02 ——– d—–w- c:\program files\Yahoo!
2009-07-15 10:02 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-07-15 05:59 . 2009-05-09 14:38 ——– d—–w- c:\program files\CCleaner
2009-07-15 05:59 . 2009-05-10 01:38 ——– d—–w- c:\program files\QuickPar
2009-07-15 05:59 . 2009-05-10 00:59 ——– d—–w- c:\program files\NewsBin
2009-07-15 02:07 . 2008-04-01 23:08 1356 —-a-w- c:\users\Symphonyj\AppData\Local\d3d9caps.dat
2009-07-04 22:22 . 2008-12-22 01:57 ——– d—–w- c:\program files\Common Files\Apple
2009-07-04 22:22 . 2008-12-22 01:58 ——– d—–w- c:\programdata\Apple Computer
2009-06-26 05:45 . 2009-05-10 03:16 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\dvdcss
2009-06-24 20:21 . 2009-05-09 14:42 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-06-23 14:59 . 2008-09-01 22:27 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Yahoo!
2009-06-17 14:23 . 2009-06-16 02:11 ——– d—–w- c:\program files\Quicken
2009-06-17 14:22 . 2009-06-17 14:22 3616768 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181311-181414.dll
2009-06-17 14:22 . 2009-06-17 14:22 2904064 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\18154-181625.dll
2009-06-17 14:22 . 2009-06-17 14:22 1007616 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181129-181212.dll
2009-06-17 14:22 . 2009-06-17 14:22 1536000 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181414-18154.dll
2009-06-17 14:22 . 2009-06-17 14:22 242976 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2009-06-17 14:22 . 2009-06-17 14:22 811008 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181212-181311.dll
2009-06-17 14:22 . 2009-06-17 14:22 223584 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\patchw32.dll
2009-06-17 14:22 . 2009-06-17 14:22 997 —-a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\rebase.cmd
2009-06-16 02:12 . 2009-06-16 02:12 ——– d—–w- c:\program files\Common Files\AnswerWorks 5.0
2009-06-16 02:12 . 2007-05-14 11:10 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-16 02:12 . 2009-06-16 02:12 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Intuit
2009-06-16 02:11 . 2009-06-16 02:11 ——– d—–w- c:\program files\Common Files\Intuit
2009-06-16 02:11 . 2009-06-16 02:11 ——– d—–w- c:\programdata\Intuit
2009-06-16 02:09 . 2009-06-16 02:08 ——– d—–w- c:\program files\MagicDisc
2009-06-05 15:36 . 2009-06-05 15:36 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-06-04 02:10 . 2008-03-21 23:41 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Hewlett-Packard
2009-06-03 03:10 . 2007-05-14 11:07 ——– d—–w- c:\program files\Hewlett-Packard
2009-06-03 03:10 . 2009-06-03 03:10 ——– d–h–w- c:\program files\Zenographics
2009-05-30 23:27 . 2009-05-30 23:27 ——– d—–w- c:\programdata\Elaborate Bytes
2009-05-25 17:44 . 2009-05-25 17:44 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\InstallShield
2009-05-24 23:07 . 2009-05-24 23:07 ——– d—–w- c:\users\Symphonyj\AppData\Roaming\Ashampoo
2009-05-24 23:06 . 2009-05-24 23:06 ——– d—–w- c:\programdata\ashampoo
2009-05-24 23:06 . 2009-05-24 23:06 ——– d—–w- c:\program files\Ashampoo
2009-05-15 22:29 . 2009-05-15 22:29 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-14 19:01 . 2009-05-14 19:01 0 —-a-w- c:\users\Symphonyj\AppData\Roaming\wklnhst.dat
2009-05-08 03:29 . 2009-05-08 03:29 79367 —-a-w- c:\users\Symphonyj\AppData\Roaming\Google\Google Talk\uninstall.exe
2009-05-07 16:32 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-05-07 15:55 . 2006-11-02 10:32 101888 —-a-w- c:\windows\system32\ifxcardm.dll
2009-05-07 15:54 . 2006-11-02 10:32 82432 —-a-w- c:\windows\system32\axaltocm.dll
2009-05-06 04:17 . 2009-05-06 04:17 604416 —-a-w- c:\windows\system32\TUProgSt.exe
2009-05-06 03:23 . 2009-05-06 02:43 81920 —-a-w- c:\users\Symphonyj\AppData\Roaming\ezpinst.exe
2009-05-06 03:23 . 2009-05-06 02:43 81920 —-a-w- c:\users\Symphonyj\AppData\Roaming\ezpinst.exe
2009-05-06 03:23 . 2009-05-06 02:43 47360 —-a-w- c:\users\Symphonyj\AppData\Roaming\pcouffin.sys
2009-05-06 03:23 . 2009-05-06 02:43 47360 —-a-w- c:\users\Symphonyj\AppData\Roaming\pcouffin.sys
2009-05-06 03:02 . 2009-05-06 02:43 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-05-01 18:30 . 2009-05-01 18:30 3366912 —-a-w- c:\windows\system32\GPhotos.scr
2009-04-30 12:37 . 2009-06-13 13:32 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-04-30 12:37 . 2009-06-13 13:32 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-04-24 16:05 . 2009-06-10 16:11 827904 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-10 16:11 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-10 16:11 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-23 12:43 . 2009-06-10 16:11 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 16:11 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-10 16:11 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-07-17 16:59 . 2009-05-07 14:55 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-07-18_04.14.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-05-14 11:06 . 2009-07-18 13:40 44916 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-07-19 06:01 75476 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-03-21 23:41 . 2009-07-19 06:01 11942 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3156202997-2437307568-1721409413-1000_UserData.bin
+ 2007-11-22 07:23 . 2009-07-19 16:22 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-11-22 07:23 . 2009-07-18 04:03 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-18 17:58 . 2009-07-18 17:58 20480 c:\windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\6baea4fe-5723aa2d-n\jogl_awt.dll
+ 2009-07-18 17:58 . 2009-07-18 17:58 20480 c:\windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\4f710eed-23506e39-n\gluegen-rt.dll
+ 2009-07-18 17:58 . 2009-07-18 17:58 61440 c:\windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-2146a798-n\decora-sse.dll
+ 2009-07-18 17:58 . 2009-07-18 17:58 12800 c:\windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-2146a798-n\decora-d3d.dll
- 2007-11-22 07:23 . 2009-07-18 04:03 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-22 07:23 . 2009-07-19 16:22 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-22 07:23 . 2009-07-19 16:22 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-11-22 07:23 . 2009-07-18 04:03 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-18 03:56 . 2009-07-18 03:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-07-18 13:36 . 2009-07-19 05:58 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-07-18 03:56 . 2009-07-18 03:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-18 13:36 . 2009-07-19 05:58 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-07-18 13:49 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-07-17 04:18 595684 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-07-18 13:49 101350 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-07-17 04:18 101350 c:\windows\System32\perfc009.dat
+ 2009-07-18 15:35 . 2009-07-18 15:35 148888 c:\windows\System32\javaws.exe
+ 2009-07-18 15:35 . 2009-07-18 15:35 144792 c:\windows\System32\javaw.exe
+ 2009-07-18 15:35 . 2009-07-18 15:35 144792 c:\windows\System32\java.exe
+ 2009-07-18 17:58 . 2009-07-18 17:58 114688 c:\windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\6baea4fe-5723aa2d-n\jogl_cg.dll
+ 2009-07-18 17:58 . 2009-07-18 17:58 315392 c:\windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\6baea4fe-5723aa2d-n\jogl.dll
+ 2009-07-18 17:58 . 2009-07-18 17:58 348160 c:\windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-2146a798-n\msvcr71.dll
+ 2009-07-18 17:58 . 2009-07-18 17:58 503808 c:\windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-2146a798-n\msvcp71.dll
+ 2009-07-18 17:58 . 2009-07-18 17:58 499712 c:\windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-2146a798-n\jmc.dll
+ 2009-07-18 15:35 . 2009-07-18 15:35 536576 c:\windows\Installer\6cf021.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 23:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"googletalk"="c:\users\Symphonyj\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-24 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 729088]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-24 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 133656]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-18 1948440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-18 148888]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-09 4390912]

c:\users\Symphonyj\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-6-15 576000]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Health Check Scheduler"=c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe"
"HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EA0C20ED-50D6-4998-AACA-C0D310A80BE5}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8EA343CA-D542-4005-95AE-932D1888BE3F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{718A99E6-21DE-424D-B6A4-5E2CD182C414}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{24D44D86-8E9D-49F2-A8BB-544C4D43499C}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{93BF56AB-3C6F-4CA6-8B06-D524AC1EA4BA}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{62EA0F59-EFA4-4B82-A406-03A4ECFA8083}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{E233FE72-FC8A-4994-811C-52BB58F69624}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{611E3E15-27D0-4CB2-872C-07D31887E8B2}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4EC59A9F-069E-47CA-9058-1BBC5ACC7A0D}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{619B8FDD-DDB0-4CEE-8FD0-FAD8995907C6}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{CE823274-DF58-4894-9AE5-CECCBF2AC440}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{D8D497C9-3829-43AE-914B-94037DFBC13E}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{00EC4F89-A172-4BB3-935C-3632E035EFAE}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B03708E1-D5DB-43FE-BC51-A777FBE087F5}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{274D9A44-2E25-4DE6-94FF-6849C116BBBA}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{40F979D9-50E5-402E-B984-CA4B925AF4B4}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FC7274B6-A1CA-49F3-981E-E96DC96B79BA}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{13DC6BD9-C42E-4FFE-A7AF-EF23C80665FC}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{79BF3829-79B0-4EDA-AFA1-FB521B37CC09}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{87CC50A0-8548-4A41-AF6C-25F9BE313D26}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D977FB8D-2B61-4CC2-9A00-D331D6893C50}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{1D4323B3-8F34-41CD-A6F9-EB40AB0784DB}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{A9ED4B1F-83EF-4BC8-B020-589B8696B044}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{5BAB2A87-62CF-4432-8230-FE52521EDE1D}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"{5BC84662-3125-4A32-8ACF-F68DCDDF14FC}"= UDP:c:\program files\NewsBin\nbpro.exe:NewsBin Pro
"{8A489F20-9FF4-4FB9-9BD3-77E92BAF5CA1}"= TCP:c:\program files\NewsBin\nbpro.exe:NewsBin Pro
"{8BF5904E-8593-4643-860B-8E1745170023}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{479DBA54-76BA-4691-B95E-DBF2C0E97E5B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{F3E1F9C5-0098-4787-90E7-E74363C56A7D}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{59BE1BD1-DA8E-41E8-ACEB-1B4930632E18}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{ADD6F2AA-293C-4C4F-A8F8-E2B64803510C}"= UDP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server
"{ADC79135-ECFB-468C-982E-6A7D7ECA1EB6}"= TCP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server
"{5C7A0703-8481-4443-8E41-54F25ECAA0DA}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{C6D8EDA4-275E-437D-AAAE-30A209D408AA}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{49EBE5D4-1851-4792-8EB6-C4AC21EB105A}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [7/17/2009 8:48 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [7/17/2009 8:48 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/17/2009 8:48 PM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/17/2009 8:48 PM 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/23/2008 8:08 PM 24652]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-07-19 c:\windows\Tasks\User_Feed_Synchronization-{68917C52-2748-4C51-A219-E6D9C3FAF19C}.job
- c:\windows\system32\msfeedssync.exe [2008-08-30 07:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Symphonyj\AppData\Roaming\Mozilla\Firefox\Profiles\ovhuj0fc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\users\Symphonyj\AppData\Roaming\Mozilla\Firefox\Profiles\ovhuj0fc.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071301000019.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-19 09:37
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-07-19 9:40
ComboFix-quarantined-files.txt 2009-07-19 16:40
ComboFix2.txt 2009-07-18 04:18

Pre-Run: 74,873,294,848 bytes free
Post-Run: 74,845,614,080 bytes free

423 — E O F — 2009-07-17 09:29

3.) Overall I haven't had any weird pop-ups or intrusions found by Malwarebytes' or my virus scanner. I check everyday cause I am extremely paranoid due to the severity of the virus. However, my comp seems to be running a bit slow, but it's not that great of a computer anyways. After this is all said and done is AVG the way to go for virus scanning and protection? Thanks again for your assistance.
:thumbup:

We'll get rid of Norton a different way then. Regarding AVG, yes, you can keep it and use it - one up-to-date AV is much better than three or four just sitting around. :)
With your slowness issues, we have a few steps we can do once you're all clean to attempt to get a bit more of a speed increase for you.

1) Norton Removal Tool
Please download the Norton Removal Tool to your desktop.
  • Double-click Norton_Removal_Tool.exe and follow the prompts to remove all traces of Norton products from your system.
  • You may be required to reboot your computer at the end of the process.

2) Kaspersky Online
Please do a scan with the Kaspersky Online Scanner

As you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan. The scan will not work if you do not do this. Please ensure you close your browser after completion.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a long time, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report

To obtain the report:
  • Click on Save Report As
  • In the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar
  • In Save as type, click the drop arrow and select Text file [*.txt]
  • Click Save

(Note for Internet Explorer users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75%. Once the license has been accepted, reset to 100%.)

In your next reply post:
Kaspersky log
New HJT log taken after the above scan has run


3) What You Will Need To Post:
  • Kaspersky log
Here you go! ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Monday, July 20, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Monday, July 20, 2009 14:05:51 Records in database: 2499901 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 167053 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 02:49:40 No malware has been detected. The scan area is clean. The selected area was scanned.
Brilliant. :thumbup: The logs all appear to be clean now.

First, I'll give you my 'all clean' post, and I'll put some advice underneath on a few things you can do that might give you a bit of a speed boost.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • [external image: Posted Image]
The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.

Your current version of Adobe Reader is out of date, and may contain security issues. Please uninstall the version you have now from Add/Remove programs, and then download and install the latest Adobe Reader.

Your version of Java is outdated.

Please download JavaRa to your desktop and unzip it to its own folder

Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

Tool-wise….

DDS - Delete this

GMER - Delete this

Combofix - Will have been uninstalled. This is a powerful tool, and not to be used without supervision.

Norton Removal Tool - Delete this

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    1. Change the Download signed ActiveX controls to Prompt
    2. Change the Download unsigned ActiveX controls to Disable
    3. Change the Initialize and script ActiveX controls not marked as safe to Disable
    4. Change the Installation of desktop items to Prompt
    5. Change the Launching programs and files in an IFRAME to Prompt
    6. Change the Navigate sub-frames across different domains to Prompt
    7. When all these settings have been made, click on the OK button.
    8. If it prompts you as to whether or not you want to save the settings, press the Yes button.
    9. Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here

Do not install more than one firewall program because they will conflict with each other

4. Make sure you keep your Windows OS current by using Windows Update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Important! Windows Vista requires special instructions for a custom Hosts file. Please see here

6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

7. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

8. Finally, I strongly recommend that you read Miekiemoses' good advice - How to prevent Malware

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

——————————————————————————

For a bit of a speed up….

1) TFC
Please download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should reboot your machine, if not, manually reboot to ensure a complete clean

2) chkdsk
  • Close any open windows.
  • Go to the Start Menu, type in cmd.exe
  • Right click on cmd.exe, and click Run as Administrator
  • In the command window that appears, type chkdsk /r, and press enter
  • Agree to any prompts - then reboot the computer.
  • chkdsk should run as you boot the machine up - this will check the harddrive for damaged sectors and attempt to repair them.

3) Defrag
  • Close any open windows.
  • Go to the Start Menu, type in Defrag
  • Defrag all drives in the Disk Defragmenter
Thank you for much for your assistance. This has been such a pleasurable experience. I will follow all your tips and keep my computer in as best shape as I can. Much appreciated.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI