This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unable to Remove Trojan

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For the past two weeks I've had some sort of Trojan that I have not been able to remove. It comes up during MBAM Scans and I cannot get it to remove the file even though MBAM says it will after a reboot.

At first, this Trojan would hijack my browser and would redirect my searches. That problem seems to be fixed, however, now I can't launch safemode.

Any help or info would be greatly appreciated.

Below are my MBAM and Hijack This logs.

—-

Malwarebytes' Anti-Malware 1.39
Database version: 2468
Windows 5.1.2600 Service Pack 3

7/20/2009 6:42:30 PM
mbam-log-2009-07-20 (18-42-30).txt

Scan type: Quick Scan
Objects scanned: 109203
Time elapsed: 6 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\CLSID\{46c166aa-3108-11d4-9348-00c04f8eeb71}\inprocserver32\(default) (Hijack.Hnetcfg) -> Bad: (\\?\globalroot\systemroot\installer\1a34734.msi) Good: (hnetcfg.dll) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:05:07 PM, on 7/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\GHL\Self-Installed\Avast\aswUpdSv.exe
C:\Program Files\GHL\Self-Installed\Avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\GHL\Self-Installed\Avast\ashMaiSv.exe
C:\Program Files\GHL\Self-Installed\Avast\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\PROGRA~1\GHL\SELF-I~1\Avast\ashDisp.exe
C:\Program Files\GHL\Self-Installed\PowerISO\PWRISOVM.EXE
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\GHL\Self-Installed\Tunebite\tunebite.exe
C:\Program Files\GHL\Self-Installed\AnyDVD\AnyDVDtray.exe
C:\Program Files\GHL\Self-Installed\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\GHL\Self-Installed\Palm\Hotsync.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
C:\Program Files\GHL\Self-Installed\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: VideoRaptorIePlugin Class - {90C8E8F8-A7C9-41E4-92E4-C679AE6FB78D} - C:\Program Files\Videoraptor\VideoRaptorIePlugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\GHL\SELF-I~1\Avast\ashDisp.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\GHL\Self-Installed\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\GHL\Self-Installed\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [tunebite.exe] C:\Program Files\GHL\Self-Installed\Tunebite\tunebite.exe -tray
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\GHL\Self-Installed\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\GHL\Self-Installed\SUPERAntiSpyware.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\GHL\Self-Installed\Palm\Hotsync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=21871
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\GHL\Self-Installed\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\GHL\Self-Installed\Avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\GHL\Self-Installed\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\GHL\Self-Installed\Avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\GHL\Self-Installed\Avast\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 11827 bytes
Hi greyspace, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post


Please post back with
  • GMER log
  • both DDS logs

Thanks
Thank you for the reply to my problem. I have read through your instructions, however, when I downloaded the GMER program and opened it, the "show all" button is placed behind the "Scan" "Copy," and "Save" buttons and I cant seem to move it and when clicking on "scan," nothing happens. Any advice for this? Thanks agian.
I was finally able to get it to scan, however, after it ran for about an hour the program just shut down. Now, when I try ti reload it, I get a message that says that I do not have access or permissions to run it. Any help?
Hi greyspace,

Let's try GMER in safe mode. First we''ll fix your safe mode.

Right click the attached file
  • 📎user.zip
  • Click Save Target AS
  • set the Save in box to Desktop
  • Click Save
Note:
If you are using Firefox, make sure that your download settings are as follows:
-Tools->Options->Main tab
-Set to "Always ask me where to Save the files".

Locate user.zip on your desktop
  • Right click user.zip
  • extract the contents to your desktop
You should now have a new file named SafeBoot-for-Windows-XP-SP3.reg with an icon like this [external image: Posted Image]

To use this file you will need to right click the icon and select merge, accept the warning if it appears and you are done.

Try booting into safe mode and run GMER.

Please post back with
  • GMER log
Once again, thank you so much for taking the time out to help me with this problem. It is really appreciated. Below are the requested logs as well as the attachment.

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-24 01:38:51
Windows 5.1.2600 Service Pack 3


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs crpf.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \FileSystem\Fastfat \Fat B9DFED20
Device \FileSystem\Fastfat \Fat B9E029F2

AttachedDevice \FileSystem\Fastfat \Fat crpf.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)

—- Files - GMER 1.0.15 —-

ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000032.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000047.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000063.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000085.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000102.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000122.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000241.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000139.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000159.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000196.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000211.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0001241.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0001259.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0001281.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0001325.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0001306.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0001360.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0001384.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0001406.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP5\A0001467.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP5\A0001511.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP6\A0001543.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP6\A0001567.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP6\A0001633.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP6\A0001582.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP6\A0001600.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP6\A0001654.sys:1 8192 bytes executable

—- EOF - GMER 1.0.15 —-



DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 8:16:07.73 on Fri 07/24/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1177 [GMT -7:00]

AV: avast! antivirus 4.8.1335 [VPS 090724-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\Program Files\GHL\Self-Installed\Avast\aswUpdSv.exe
C:\Program Files\GHL\Self-Installed\Avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\GHL\Self-Installed\Avast\ashMaiSv.exe
C:\Program Files\GHL\Self-Installed\Avast\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\GHL\SELF-I~1\Avast\ashDisp.exe
C:\Program Files\GHL\Self-Installed\PowerISO\PWRISOVM.EXE
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\GHL\Self-Installed\Tunebite\tunebite.exe
C:\Program Files\GHL\Self-Installed\AnyDVD\AnyDVDtray.exe
C:\Program Files\GHL\Self-Installed\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\GHL\Self-Installed\Palm\Hotsync.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\AIM6\anotify.exe
C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
C:\Documents and Settings\GHL\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
BHO: VideoRaptorIePlugin Class: {90c8e8f8-a7c9-41e4-92e4-c679ae6fb78d} - c:\program files\videoraptor\VideoRaptorIePlugin.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [tunebite.exe] c:\program files\ghl\self-installed\tunebite\tunebite.exe -tray
uRun: [Aim6]
uRun: [AnyDVD] c:\program files\ghl\self-installed\anydvd\AnyDVDtray.exe
uRun: [SUPERAntiSpyware] c:\program files\ghl\self-installed\SUPERAntiSpyware.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_06\bin\jusched.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [Corel Photo Downloader] c:\program files\corel\corel snapfire plus\Corel Photo Downloader.exe
mRun: [avast!] c:\progra~1\ghl\self-i~1\avast\ashDisp.exe
mRun: [PWRISOVM.EXE] c:\program files\ghl\self-installed\poweriso\PWRISOVM.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\ghl\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\ghl\self-installed\palm\Hotsync.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl.sun.com/webapps/download/AutoDL?BundleId=21871
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: !SASWinLogon - c:\program files\ghl\self-installed\SASWINLO.dll
Notify: LMIinit - LMIinit.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\ghl\self-installed\SASSEH.DLL

============= SERVICES / DRIVERS ===============

R0 crpf;crpf;c:\windows\system32\drivers\crpf.sys [2009-7-10 36512]
R0 csdf;csdf;c:\windows\system32\drivers\csdf.sys [2009-7-10 39456]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-6 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\ghl\self-installed\sasdifsv.sys [2009-2-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\ghl\self-installed\SASKUTIL.SYS [2009-2-17 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-6 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\ghl\self-installed\avast\ashServ.exe [2009-6-6 138680]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-2-4 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-2-4 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-4-12 24652]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\ghl\self-installed\avast\ashMaiSv.exe [2009-6-6 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\ghl\self-installed\avast\ashWebSv.exe [2009-6-6 352920]
R3 SASENUM;SASENUM;c:\program files\ghl\self-installed\SASENUM.SYS [2009-2-17 7408]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]

=============== Created Last 30 ================

2009-07-23 10:52 278,221 a——- c:\program files\gmer.zip
2009-07-12 10:49 308,160 a——- c:\program files\avast_home_setup.exe
2009-07-11 18:20 265,216 a——- c:\program files\TFC.exe
2009-07-11 18:14 794,112 a——- c:\program files\The_Comedian.exe
2009-07-11 05:50 –d—– c:\program files\Trend Micro
2009-07-11 05:50 812,344 a——- c:\program files\HJTInstall.exe
2009-07-10 21:25 39,456 a——- c:\windows\system32\drivers\csdf.sys
2009-07-10 21:25 36,512 a——- c:\windows\system32\drivers\crpf.sys
2009-07-10 21:25 8,456 a——- c:\windows\system32\cnat.exe
2009-07-10 21:25 –d—– c:\program files\COMODO
2009-07-10 21:24 5,575,824 a——- c:\program files\CSC_Setup_1.1.64946.38_xp_vista_server2003_x32.exe
2009-07-10 19:40 –dsh— c:\windows\System Volume Information
2009-07-04 15:27 –d—– c:\program files\Audacity
2009-07-04 15:26 2,228,534 a——- c:\program files\audacity-win-1.2.6.exe
2009-07-04 15:12 –d—– c:\windows\system32\appmgmt
2009-07-04 11:04 –d—– c:\program files\QuickMediaConverter
2009-07-04 10:38 2,790,624 a——- c:\program files\x-audio-converter-CNET.exe
2009-07-04 10:27 6,698,028 a——- c:\program files\aaep.exe
2009-07-04 10:24 86,683 a——- c:\windows\system32\pthreadGC2.dll
2009-07-04 10:24 –d—– c:\program files\AoA Audio Extractor
2009-07-04 10:19 –d—– c:\program files\YouTube Downloader
2009-07-04 10:18 3,176,437 a——- c:\program files\youtubedownloader.exe
2009-07-04 10:01 8,079,082 a——- c:\program files\audioextractor.exe
2009-07-04 08:56 107,864 a——- c:\windows\system32\tsccvid.dll
2009-07-04 08:56 –d—– c:\windows\system32\QuickTime
2009-07-04 08:56 –d—– c:\program files\common files\TechSmith Shared
2009-07-03 19:41 –d—– c:\docume~1\ghl\applic~1\River Past G5
2009-07-03 19:41 –d—– c:\docume~1\alluse~1\applic~1\River Past G5
2009-07-03 19:41 7,814,384 a——- c:\program files\audiocapture_wmf_setup.exe
2009-07-03 19:40 23,442,487 a——- c:\program files\INSTALL.zip
2009-07-03 19:30 –d—– c:\program files\SoundCapture
2009-07-03 19:29 751,167 a——- c:\program files\sc11a.exe
2009-07-03 19:23 –d—– c:\program files\Free M4a to MP3 Converter
2009-07-03 19:23 2,813,421 a——- c:\program files\m4a-to-mp3-converter.exe
2009-07-03 19:00 107,368 a——- c:\windows\system32\GEARAspi.dll
2009-07-03 19:00 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-03 19:00 –d—– c:\program files\iPod
2009-07-03 19:00 –d—– c:\program files\iTunes
2009-07-03 19:00 –d—– c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-03 18:57 77,690,152 a——- c:\program files\iTunesSetup.exe
2009-07-03 11:34 –d—– c:\program files\NCH Software
2009-07-03 11:34 434,832 a——- c:\program files\switchsetup.exe
2009-07-03 11:25 6,692,753 a——- c:\program files\Setup_FreeConverter.exe
2009-07-03 11:18 21,935,408 a——- c:\program files\QuickTimeInstaller.exe
2009-07-03 11:00 2,560 ——– c:\windows\system32\drivers\cdralw2k.sys
2009-07-03 11:00 2,432 ——– c:\windows\system32\drivers\cdr4_xp.sys
2009-07-03 10:59 –d—– c:\program files\common files\muvee Technologies
2009-07-03 10:58 –d—– c:\windows\RegisteredPackages

==================== Find3M ====================

2009-07-22 20:37 48,928 a——- c:\windows\system32\nvModes.dat
2009-07-13 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-24 07:03 13,905,056 a——- c:\program files\aim6591.exe
2009-05-07 08:32 345,600 a——- c:\windows\system32\localspl.dll
2009-05-07 08:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll
2009-04-28 21:56 827,392 a——- c:\windows\system32\wininet.dll
2009-04-28 21:56 827,392 ——– c:\windows\system32\dllcache\wininet.dll
2009-04-28 21:56 233,472 ——– c:\windows\system32\dllcache\webcheck.dll
2009-04-28 21:56 1,159,680 ——– c:\windows\system32\dllcache\urlmon.dll
2009-04-28 21:56 671,232 ——– c:\windows\system32\dllcache\mstime.dll
2009-04-28 21:56 105,984 ——– c:\windows\system32\dllcache\url.dll
2009-04-28 21:56 102,912 ——– c:\windows\system32\dllcache\occache.dll
2009-04-28 21:56 44,544 ——– c:\windows\system32\dllcache\pngfilt.dll
2009-04-28 21:56 3,596,288 ——– c:\windows\system32\dllcache\mshtml.dll
2009-04-28 21:56 477,696 ——– c:\windows\system32\dllcache\mshtmled.dll
2009-04-28 21:56 193,024 ——– c:\windows\system32\dllcache\msrating.dll
2009-04-28 02:05 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-04-28 02:05 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-04-26 12:30 123,131 a——- c:\windows\HPHins12.dat
2009-04-12 12:32 15,452,536 a——- c:\program files\IE7-WindowsXP-x86-enu.exe

============= FINISH: 8:16:16.60 ===============

Attachments:

Hi Greyspace,

That's what this forum is for.

GMER and DDS logs look good. Not sure why GMER wouldn't run in normal windows.

Safe Mode is working now? Any symptoms?

µTorrent
You have µTorrent, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it. It's not the program itself that is the problem, but what can be downloaded with it. Many times the material is from an unkown source.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.



You have some old vulnerable versions of java on your computer.

  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 14
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u14-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs and uninstall

J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 6


Do not uninstall Java TM 6 Update 14 if found! :yeah:

Reboot your computer.

  • Double-click on the saved file ( jre-6u14-windows-i586-p.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.


You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • MBAM log
  • new DDS.txt

Thanks
Hello again. I tried to install the jre-6u14-windows-i586.exe file however, whenever I try to download it I get an error message that reads, "Unable to download, maximum attempts exceeded." I've tried multiple times over the past few days and have not had any success in getting it to download. Any ideas for this? Also, I kept the UTorrent program as I only download legal live-show torrents from my favorite band's website and it requires UTorrent. I did run the MBAM scan and kept getting the same message of 1 file infected. It would say that it would delete after a reboot, but every single time the same file would re-appear. I decided to run MBAM in Safe Mode to see if that would work, and it seemed to as the file no longer seems to be appearing. I hope that was okay. Below are the two scans from MBAM and DDS. Malwarebytes' Anti-Malware 1.39 Database version: 2505 Windows 5.1.2600 Service Pack 3 7/26/2009 8:55:29 AM mbam-log-2009-07-26 (08-55-29).txt Scan type: Quick Scan Objects scanned: 123592 Time elapsed: 14 minute(s), 27 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 8:57:05.26 on Sun 07/26/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1062 [GMT -7:00] AV: avast! antivirus 4.8.1335 [VPS 090725-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe svchost.exe svchost.exe C:\Program Files\GHL\Self-Installed\Avast\aswUpdSv.exe C:\Program Files\GHL\Self-Installed\Avast\ashServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\GHL\Self-Installed\Avast\ashMaiSv.exe C:\Program Files\GHL\Self-Installed\Avast\ashWebSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\WINDOWS\stsystra.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe C:\PROGRA~1\GHL\SELF-I~1\Avast\ashDisp.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\GHL\Self-Installed\PowerISO\PWRISOVM.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\Program Files\NetWaiting\netWaiting.exe C:\Program Files\Dell Support\DSAgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\GHL\Self-Installed\Tunebite\tunebite.exe C:\Program Files\GHL\Self-Installed\AnyDVD\AnyDVDtray.exe C:\Program Files\GHL\Self-Installed\SUPERAntiSpyware.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\GHL\Self-Installed\Palm\Hotsync.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wuauclt.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe C:\Program Files\AIM6\anotify.exe C:\Program Files\AIM6\aolsoftware.exe C:\Documents and Settings\GHL\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://google.com/ uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403 uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403 BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll BHO: VideoRaptorIePlugin Class: {90c8e8f8-a7c9-41e4-92e4-c679ae6fb78d} - c:\program files\videoraptor\VideoRaptorIePlugin.dll uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [tunebite.exe] c:\program files\ghl\self-installed\tunebite\tunebite.exe -tray uRun: [Aim6] uRun: [AnyDVD] c:\program files\ghl\self-installed\anydvd\AnyDVDtray.exe uRun: [SUPERAntiSpyware] c:\program files\ghl\self-installed\SUPERAntiSpyware.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe" mRun: [Corel Photo Downloader] c:\program files\corel\corel snapfire plus\Corel Photo Downloader.exe mRun: [avast!] c:\progra~1\ghl\self-i~1\avast\ashDisp.exe mRun: [PWRISOVM.EXE] c:\program files\ghl\self-installed\poweriso\PWRISOVM.EXE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] c:\program files\java\jre1.6.0_06\bin\jusched.exe StartupFolder: c:\docume~1\ghl\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\ghl\self-installed\palm\Hotsync.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: !SASWinLogon - c:\program files\ghl\self-installed\SASWINLO.dll Notify: LMIinit - LMIinit.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\ghl\self-installed\SASSEH.DLL ============= SERVICES / DRIVERS =============== R0 crpf;crpf;c:\windows\system32\drivers\crpf.sys [2009-7-10 36512] R0 csdf;csdf;c:\windows\system32\drivers\csdf.sys [2009-7-10 39456] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-6 114768] R1 SASDIFSV;SASDIFSV;c:\program files\ghl\self-installed\sasdifsv.sys [2009-2-17 8944] R1 SASKUTIL;SASKUTIL;c:\program files\ghl\self-installed\SASKUTIL.SYS [2009-2-17 55024] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-6 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\ghl\self-installed\avast\ashServ.exe [2009-6-6 138680] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-2-4 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-2-4 47640] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-4-12 24652] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\ghl\self-installed\avast\ashMaiSv.exe [2009-6-6 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\ghl\self-installed\avast\ashWebSv.exe [2009-6-6 352920] R3 SASENUM;SASENUM;c:\program files\ghl\self-installed\SASENUM.SYS [2009-2-17 7408] S4 LMIRfsClientNP;LMIRfsClientNP; [x] =============== Created Last 30 ================ 2009-07-26 08:33 0 ——– c:\program files\jre-6u14-windows-i586.exe 2009-07-25 20:15 –d—– c:\documents and settings\ghl\.SunDownloadManager 2009-07-25 14:35 –d—– c:\program files\Windows Media Connect 2 2009-07-23 10:52 278,221 a——- c:\program files\gmer.zip 2009-07-12 10:49 308,160 a——- c:\program files\avast_home_setup.exe 2009-07-11 18:20 265,216 a——- c:\program files\TFC.exe 2009-07-11 18:14 794,112 a——- c:\program files\The_Comedian.exe 2009-07-11 05:50 –d—– c:\program files\Trend Micro 2009-07-11 05:50 812,344 a——- c:\program files\HJTInstall.exe 2009-07-10 21:25 39,456 a——- c:\windows\system32\drivers\csdf.sys 2009-07-10 21:25 36,512 a——- c:\windows\system32\drivers\crpf.sys 2009-07-10 21:25 8,456 a——- c:\windows\system32\cnat.exe 2009-07-10 21:25 –d—– c:\program files\COMODO 2009-07-10 21:24 5,575,824 a——- c:\program files\CSC_Setup_1.1.64946.38_xp_vista_server2003_x32.exe 2009-07-10 19:40 –dsh— c:\windows\System Volume Information 2009-07-04 15:27 –d—– c:\program files\Audacity 2009-07-04 15:26 2,228,534 a——- c:\program files\audacity-win-1.2.6.exe 2009-07-04 15:12 –d—– c:\windows\system32\appmgmt 2009-07-04 11:04 –d—– c:\program files\QuickMediaConverter 2009-07-04 10:38 2,790,624 a——- c:\program files\x-audio-converter-CNET.exe 2009-07-04 10:27 6,698,028 a——- c:\program files\aaep.exe 2009-07-04 10:24 86,683 a——- c:\windows\system32\pthreadGC2.dll 2009-07-04 10:24 –d—– c:\program files\AoA Audio Extractor 2009-07-04 10:19 –d—– c:\program files\YouTube Downloader 2009-07-04 10:18 3,176,437 a——- c:\program files\youtubedownloader.exe 2009-07-04 10:01 8,079,082 a——- c:\program files\audioextractor.exe 2009-07-04 08:56 107,864 a——- c:\windows\system32\tsccvid.dll 2009-07-04 08:56 –d—– c:\windows\system32\QuickTime 2009-07-04 08:56 –d—– c:\program files\common files\TechSmith Shared 2009-07-03 19:41 –d—– c:\docume~1\ghl\applic~1\River Past G5 2009-07-03 19:41 –d—– c:\docume~1\alluse~1\applic~1\River Past G5 2009-07-03 19:41 7,814,384 a——- c:\program files\audiocapture_wmf_setup.exe 2009-07-03 19:40 23,442,487 a——- c:\program files\INSTALL.zip 2009-07-03 19:30 –d—– c:\program files\SoundCapture 2009-07-03 19:29 751,167 a——- c:\program files\sc11a.exe 2009-07-03 19:23 –d—– c:\program files\Free M4a to MP3 Converter 2009-07-03 19:23 2,813,421 a——- c:\program files\m4a-to-mp3-converter.exe 2009-07-03 19:00 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-07-03 19:00 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-07-03 19:00 –d—– c:\program files\iPod 2009-07-03 19:00 –d—– c:\program files\iTunes 2009-07-03 19:00 –d—– c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-07-03 18:57 77,690,152 a——- c:\program files\iTunesSetup.exe 2009-07-03 11:34 –d—– c:\program files\NCH Software 2009-07-03 11:34 434,832 a——- c:\program files\switchsetup.exe 2009-07-03 11:25 6,692,753 a——- c:\program files\Setup_FreeConverter.exe 2009-07-03 11:18 21,935,408 a——- c:\program files\QuickTimeInstaller.exe 2009-07-03 11:00 2,560 ——– c:\windows\system32\drivers\cdralw2k.sys 2009-07-03 11:00 2,432 ——– c:\windows\system32\drivers\cdr4_xp.sys 2009-07-03 10:59 –d—– c:\program files\common files\muvee Technologies 2009-07-03 10:58 –d—– c:\windows\RegisteredPackages ==================== Find3M ==================== 2009-07-26 08:05 1,191 a——- c:\program files\jre-6u14-windows-i586.exe.sdm 2009-07-25 23:20 48,937 a——- c:\windows\system32\nvModes.dat 2009-07-13 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-13 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-24 07:03 13,905,056 a——- c:\program files\aim6591.exe 2009-05-07 08:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-07 08:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll 2009-04-28 21:56 827,392 a——- c:\windows\system32\wininet.dll 2009-04-28 21:56 827,392 ——– c:\windows\system32\dllcache\wininet.dll 2009-04-28 21:56 233,472 ——– c:\windows\system32\dllcache\webcheck.dll 2009-04-28 21:56 1,159,680 ——– c:\windows\system32\dllcache\urlmon.dll 2009-04-28 21:56 671,232 ——– c:\windows\system32\dllcache\mstime.dll 2009-04-28 21:56 105,984 ——– c:\windows\system32\dllcache\url.dll 2009-04-28 21:56 102,912 ——– c:\windows\system32\dllcache\occache.dll 2009-04-28 21:56 44,544 ——– c:\windows\system32\dllcache\pngfilt.dll 2009-04-28 21:56 3,596,288 ——– c:\windows\system32\dllcache\mshtml.dll 2009-04-28 21:56 477,696 ——– c:\windows\system32\dllcache\mshtmled.dll 2009-04-28 21:56 193,024 ——– c:\windows\system32\dllcache\msrating.dll 2009-04-28 02:05 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-04-28 02:05 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-04-12 12:32 15,452,536 a——- c:\program files\IE7-WindowsXP-x86-enu.exe ============= FINISH: 8:57:26.26 ===============
Hi greyspace.

According to your last DDS log, jre-6u14-windows-i586.exe has been downloaded and is located

c:\program files\jre-6u14-windows-i586.exe

Have you tried to install it by double clicking the file?


That's fine with MBAM, but let's have a deeper look at your system.

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Post back with
  • combofix log

How's the computer?

Thanks
Hi again.

From what I can tell, the computer seems to be running fine (thanks again for all your hard work), but I know you can never be to sure.

With regard to the Java update… when I run the Sun Java Install thing, it still tells me that the download fails. I saw that there was a java exe file on my desktop but clicking on that says that there is not a valid win 32 file.

Also according to the notes for combofix, it disabled autorun of usb/cd/dvd devices, etc. Is there a way to turn that back on?

Below is my combofix log.

ComboFix 09-07-27.04 - GHL 07/28/2009 3:11.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1453 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090727-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\1a34734.msi
c:\windows\Installer\43058.msp
c:\windows\Installer\a94995.msp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}


((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-28 )))))))))))))))))))))))))))))))
.

2009-07-26 15:33 . 2009-07-26 15:33 0 ——w- c:\program files\jre-6u14-windows-i586.exe
2009-07-26 05:49 . 2009-07-26 05:49 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-07-26 03:15 . 2009-07-28 10:02 ——– d—–w- c:\documents and settings\GHL\.SunDownloadManager
2009-07-25 21:47 . 2008-04-14 00:12 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-07-25 21:35 . 2009-07-25 21:35 ——– d—–w- c:\program files\Windows Media Connect 2
2009-07-25 21:34 . 2009-07-25 21:34 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-07-23 17:52 . 2009-07-23 17:52 278221 —-a-w- c:\program files\gmer.zip
2009-07-12 17:49 . 2009-07-12 17:49 308160 —-a-w- c:\program files\avast_home_setup.exe
2009-07-12 01:20 . 2009-07-12 01:20 265216 —-a-w- c:\program files\TFC.exe
2009-07-12 01:16 . 2009-07-12 01:19 ——– d—–w- c:\program files\ERUNT
2009-07-12 01:14 . 2009-07-12 01:18 794112 —-a-w- c:\program files\The_Comedian.exe
2009-07-11 12:50 . 2009-07-11 12:50 ——– d—–w- c:\program files\Trend Micro
2009-07-11 12:50 . 2009-07-11 12:50 812344 —-a-w- c:\program files\HJTInstall.exe
2009-07-11 04:29 . 2009-07-24 04:42 ——– d—–w- c:\documents and settings\GH\Local Settings\Application Data\Apple Computer
2009-07-11 04:25 . 2009-04-30 18:47 39456 —-a-w- c:\windows\system32\drivers\csdf.sys
2009-07-11 04:25 . 2009-04-30 18:46 36512 —-a-w- c:\windows\system32\drivers\crpf.sys
2009-07-11 04:25 . 2009-04-30 18:45 8456 —-a-w- c:\windows\system32\cnat.exe
2009-07-11 04:25 . 2009-07-11 04:25 ——– d—–w- c:\program files\COMODO
2009-07-11 04:24 . 2009-07-11 04:24 5575824 —-a-w- c:\program files\CSC_Setup_1.1.64946.38_xp_vista_server2003_x32.exe
2009-07-11 02:40 . 2009-07-11 02:40 ——– d-sh–w- c:\windows\System Volume Information
2009-07-04 22:27 . 2009-07-04 22:27 ——– d—–w- c:\program files\Audacity
2009-07-04 22:26 . 2009-07-04 22:26 2228534 —-a-w- c:\program files\audacity-win-1.2.6.exe
2009-07-04 18:04 . 2009-07-04 22:09 ——– d—–w- c:\program files\QuickMediaConverter
2009-07-04 17:38 . 2009-07-04 17:39 2790624 —-a-w- c:\program files\x-audio-converter-CNET.exe
2009-07-04 17:27 . 2009-07-04 17:27 6698028 —-a-w- c:\program files\aaep.exe
2009-07-04 17:24 . 2007-05-13 19:24 86683 —-a-w- c:\windows\system32\pthreadGC2.dll
2009-07-04 17:24 . 2009-07-04 17:24 ——– d—–w- c:\program files\AoA Audio Extractor
2009-07-04 17:19 . 2009-07-04 17:19 ——– d—–w- c:\program files\YouTube Downloader
2009-07-04 17:18 . 2009-07-04 17:19 3176437 —-a-w- c:\program files\youtubedownloader.exe
2009-07-04 17:01 . 2009-07-04 17:23 8079082 —-a-w- c:\program files\audioextractor.exe
2009-07-04 15:56 . 2008-07-10 20:56 107864 —-a-w- c:\windows\system32\tsccvid.dll
2009-07-04 15:56 . 2009-07-04 15:56 ——– d—–w- c:\windows\system32\QuickTime
2009-07-04 15:56 . 2009-07-04 15:56 ——– d—–w- c:\documents and settings\All Users\Application Data\TechSmith
2009-07-04 15:56 . 2009-07-04 15:56 ——– d—–w- c:\program files\Common Files\TechSmith Shared
2009-07-04 02:41 . 2009-07-04 17:53 ——– d—–w- c:\documents and settings\All Users\Application Data\River Past G5
2009-07-04 02:41 . 2009-07-04 02:41 ——– d—–w- c:\documents and settings\GHL\Application Data\River Past G5
2009-07-04 02:41 . 2009-07-04 02:41 7814384 —-a-w- c:\program files\audiocapture_wmf_setup.exe
2009-07-04 02:40 . 2009-07-04 18:04 23442487 —-a-w- c:\program files\INSTALL.zip
2009-07-04 02:30 . 2009-07-04 14:41 ——– d—–w- c:\program files\SoundCapture
2009-07-04 02:29 . 2009-07-04 02:30 751167 —-a-w- c:\program files\sc11a.exe
2009-07-04 02:23 . 2009-07-04 22:16 ——– d—–w- c:\program files\Free M4a to MP3 Converter
2009-07-04 02:23 . 2009-07-04 02:23 2813421 —-a-w- c:\program files\m4a-to-mp3-converter.exe
2009-07-04 02:00 . 2009-07-05 22:42 ——– d—–w- c:\documents and settings\GHL\Application Data\Apple Computer
2009-07-04 02:00 . 2009-03-19 23:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-04 02:00 . 2008-04-17 19:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-07-04 02:00 . 2009-07-04 02:00 ——– d—–w- c:\program files\iPod
2009-07-04 02:00 . 2009-07-04 02:00 ——– d—–w- c:\program files\iTunes
2009-07-04 02:00 . 2009-07-04 02:00 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-04 01:59 . 2009-07-04 22:12 ——– dc—-w- c:\windows\system32\DRVSTORE
2009-07-04 01:58 . 2009-07-04 22:12 ——– d—–w- c:\program files\Common Files\Apple
2009-07-04 01:57 . 2009-07-04 01:58 77690152 —-a-w- c:\program files\iTunesSetup.exe
2009-07-03 23:57 . 2009-07-03 23:57 ——– d—–w- c:\documents and settings\GHL\Application Data\Recordpad
2009-07-03 18:34 . 2009-07-03 23:57 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-07-03 18:34 . 2009-07-03 18:34 ——– d—–w- c:\program files\NCH Software
2009-07-03 18:34 . 2009-07-03 23:57 ——– d—–w- c:\documents and settings\GHL\Application Data\NCH Swift Sound
2009-07-03 18:34 . 2009-07-03 18:34 434832 —-a-w- c:\program files\switchsetup.exe
2009-07-03 18:25 . 2009-07-03 18:31 6692753 —-a-w- c:\program files\Setup_FreeConverter.exe
2009-07-03 18:19 . 2009-07-03 18:20 ——– d—–w- c:\program files\QuickTime
2009-07-03 18:19 . 2009-07-04 02:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-03 18:19 . 2009-07-03 18:19 ——– d—–w- c:\documents and settings\GHL\Local Settings\Application Data\Apple
2009-07-03 18:18 . 2009-07-04 02:00 ——– d—–w- c:\documents and settings\GHL\Local Settings\Application Data\Apple Computer
2009-07-03 18:18 . 2009-07-03 18:18 21935408 —-a-w- c:\program files\QuickTimeInstaller.exe
2009-07-03 18:08 . 2009-07-05 23:25 ——– d—–w- c:\documents and settings\GHL\Application Data\muvee Technologies
2009-07-03 18:00 . 2006-08-30 14:10 2560 ——w- c:\windows\system32\drivers\cdralw2k.sys
2009-07-03 18:00 . 2006-08-30 14:10 2432 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2009-07-03 17:59 . 2009-07-03 17:59 ——– d—–w- c:\program files\Common Files\muvee Technologies
2009-07-03 17:57 . 2009-07-04 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\muvee Technologies
2009-07-03 17:56 . 2009-07-03 17:56 ——– d—–w- c:\documents and settings\GHL\Application Data\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 10:19 . 2009-04-12 14:41 117760 —-a-w- c:\documents and settings\GHL\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-28 10:02 . 2009-07-26 03:22 1191 —-a-w- c:\program files\jre-6u14-windows-i586.exe.sdm
2009-07-28 09:53 . 2007-04-20 16:07 ——– d—–w- c:\program files\LogMeIn
2009-07-28 00:53 . 2009-04-18 12:06 ——– d—–w- c:\documents and settings\GHL\Application Data\uTorrent
2009-07-26 06:20 . 2007-04-04 02:48 48937 —-a-w- c:\windows\system32\nvModes.dat
2009-07-26 03:10 . 2007-04-04 03:01 ——– d—–w- c:\program files\Java
2009-07-24 00:06 . 2007-07-16 15:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-23 00:35 . 2008-03-22 05:43 ——– d—–w- c:\documents and settings\GHL\Application Data\vlc
2009-07-16 01:07 . 2007-12-29 21:28 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-07-15 00:55 . 2008-02-09 03:31 ——– d—–w- c:\documents and settings\GHL\Application Data\Canon
2009-07-14 00:19 . 2009-04-12 15:16 3775176 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-13 20:36 . 2009-03-08 19:24 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 20:36 . 2009-03-08 19:24 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-11 01:18 . 2008-02-09 01:18 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-04 22:37 . 2007-04-04 03:20 74712 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-04 19:19 . 2009-07-04 19:18 49164 —-a-w- c:\windows\Fonts\MAFW____.TTF
2009-07-04 19:18 . 2009-07-04 19:18 48860 —-a-w- c:\windows\Fonts\MAFT____.TTF
2009-07-03 17:59 . 2007-04-04 03:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-24 14:05 . 2007-09-27 20:38 ——– d—–w- c:\program files\AIM6
2009-06-24 14:04 . 2007-09-27 20:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-24 14:03 . 2009-06-24 14:02 13905056 —-a-w- c:\program files\aim6591.exe
2009-06-23 22:17 . 2007-04-20 16:04 ——– d—–w- c:\program files\GHL
2009-06-17 22:30 . 2007-04-04 03:15 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-05 20:57 . 2009-06-05 20:57 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-19 08:36 . 2009-06-15 03:14 2884832 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\vwpt.exe
2009-05-19 08:36 . 2009-06-15 03:14 28 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\unregister.bat
2009-05-19 08:36 . 2009-06-15 03:14 1484856 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\toolbar.exe
2009-05-19 08:36 . 2009-06-15 03:14 25 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\register.bat
2009-05-19 08:36 . 2009-06-15 03:14 97072 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\bsetutil.exe
2009-05-19 08:36 . 2009-06-15 03:14 142040 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\alsetup.exe
2009-05-19 08:36 . 2009-06-15 03:14 30512 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\Uninstaller.exe
2009-05-19 08:36 . 2009-06-15 03:14 111920 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\AOLSearch.dll
2009-05-07 15:32 . 2004-08-11 22:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-12 19:32 . 2009-04-12 19:30 15452536 —-a-w- c:\program files\IE7-WindowsXP-x86-enu.exe
2009-04-19 18:28 . 2008-01-09 03:19 88 –sh–r- c:\windows\system32\1B491E2DAE.sys
2009-04-19 18:28 . 2008-01-09 03:19 2828 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-29 395776]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"tunebite.exe"="c:\program files\GHL\Self-Installed\Tunebite\tunebite.exe" [2007-09-13 2846720]
"AnyDVD"="c:\program files\GHL\Self-Installed\AnyDVD\AnyDVDtray.exe" [2008-12-18 2304960]
"SUPERAntiSpyware"="c:\program files\GHL\Self-Installed\SUPERAntiSpyware.exe" [2009-02-17 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-21 7557120]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-08-22 184320]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 63048]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Corel Photo Downloader"="c:\program files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe" [2006-08-14 462336]
"avast!"="c:\progra~1\GHL\SELF-I~1\Avast\ashDisp.exe" [2009-02-05 81000]
"PWRISOVM.EXE"="c:\program files\GHL\Self-Installed\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-03-21 1519616]
"NVHotkey"="nvHotkey.dll" - c:\windows\system32\nvhotkey.dll [2006-03-21 73728]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]

c:\documents and settings\GHL\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-4-3 24576]
HOTSYNCSHORTCUTNAME.lnk - c:\program files\GHL\Self-Installed\Palm\Hotsync.exe [2004-6-9 471040]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\GHL\Self-Installed\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 18:05 356352 —-a-w- c:\program files\GHL\Self-Installed\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-12-17 00:36 87352 —-a-w- c:\windows\system32\LMIinit.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\GHL\\Self-Installed\\utorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 crpf;crpf;c:\windows\system32\drivers\crpf.sys [7/10/2009 9:25 PM 36512]
R0 csdf;csdf;c:\windows\system32\drivers\csdf.sys [7/10/2009 9:25 PM 39456]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/6/2009 12:26 AM 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\GHL\Self-Installed\sasdifsv.sys [2/17/2009 11:43 AM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\GHL\Self-Installed\SASKUTIL.SYS [2/17/2009 11:43 AM 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/6/2009 12:26 AM 20560]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2/4/2008 9:00 AM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2/4/2008 9:00 AM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/12/2009 7:55 AM 24652]
R3 SASENUM;SASENUM;c:\program files\GHL\Self-Installed\SASENUM.SYS [2/17/2009 11:43 AM 7408]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder

2009-07-28 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-25 05:18]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
.

**************************************************************************

driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-28 03:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(964)
c:\program files\GHL\Self-Installed\SASWINLO.dll
c:\windows\system32\LMIinit.dll

- - - - - - - > 'explorer.exe'(2708)
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\GHL\Self-Installed\Avast\aswUpdSv.exe
c:\program files\GHL\Self-Installed\Avast\ashServ.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\LogMeIn\x86\ramaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\rundll32.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-28 3:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-28 10:23

Pre-Run: 11,228,975,104 bytes free
Post-Run: 15,864,344,576 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

270 — E O F — 2009-07-27 00:18
Hi greyspace,

I see that Viewpoint products are installed installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is often installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
It is recommended that you remove the Viewpoint products; however, decide for yourself. You can uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player) via Add/Remove programs. However if you use AOL products, Viewpoint will reinstall itself. As noted above, the player's updates can be stopped if ViewPoint Manager is installed and the console is in Contol Panel.

Also according to the notes for combofix, it disabled autorun of usb/cd/dvd devices, etc. Is there a way to turn that back on?

It may be possible. However from a security standpoint it is highly advisable to leave autoruns disabled. There is a host of nasty malware that uses this feature as an entry point into your computer. By having autoruns enabled you are allowing an infected disc, usb storage device, phone, camera etc to run and execute malicious files upon the device being attached to the computer.



For the java, you may have a corrupt download. Let's try it this way.

Open windows explorer (right click the Start button and click Explore)

  • Navigate to this folder

    C:\program files
  • In the right hand panel, locate this file jre-6u14-windows-i586.exe
  • If found, right click the file and select delete
  • Accept any warning you may recieve.
    Do the same with this file jre-6u14-windows-i586.exe.sdm
If you have a copy of the file on your desktop, please delete it also.

Here's a direct link to the file. JAVA

  • Download it to your desktop
  • Close all browsers
  • Double-click on the saved file ( jre-6u14-windows-i586-p.exe) to install the update.
Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.


Next

Go here to run an online scannner from ESET:
http://www.eset.eu/online-scanner

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. We will need this later.
Please post back with the ESET log and a new DDS log (just the DDS.txt this time).


Did you manage to install the java?

Any problems with the computer?

Thanks
Hi again, I tried to download the Java update again and think that I was successful with it this time, thanks! The computer seems to be running fine now. I have inlcuded the requested logs below: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=7.00.6000.16876 (vista_gdr.090625-2339) # OnlineScanner.ocx=1.0.0.5889 # api_version=3.0.2 # EOSSerial=083344a53dd35843a4f5ef44763952e7 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-08-01 01:24:43 # local_time=2009-07-31 06:24:43 (-0800, Pacific Daylight Time) # country="United States" # lang=9 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=769 37 100 98 57295781250 # scanned=67963 # found=0 # cleaned=0 # scan_time=1629 DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 18:27:04.59 on Fri 07/31/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1107 [GMT -7:00] AV: avast! antivirus 4.8.1335 [VPS 090731-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe svchost.exe svchost.exe C:\Program Files\GHL\Self-Installed\Avast\aswUpdSv.exe C:\Program Files\GHL\Self-Installed\Avast\ashServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\WINDOWS\stsystra.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe C:\PROGRA~1\GHL\SELF-I~1\Avast\ashDisp.exe C:\Program Files\GHL\Self-Installed\PowerISO\PWRISOVM.EXE C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\NetWaiting\netWaiting.exe C:\Program Files\Dell Support\DSAgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\GHL\Self-Installed\Tunebite\tunebite.exe C:\Program Files\GHL\Self-Installed\AnyDVD\AnyDVDtray.exe C:\Program Files\GHL\Self-Installed\SUPERAntiSpyware.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\Program Files\GHL\Self-Installed\Palm\Hotsync.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\AIM6\aolsoftware.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\AIM6\anotify.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\GHL\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://google.com/ uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403 BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: VideoRaptorIePlugin Class: {90c8e8f8-a7c9-41e4-92e4-c679ae6fb78d} - c:\program files\videoraptor\VideoRaptorIePlugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [tunebite.exe] c:\program files\ghl\self-installed\tunebite\tunebite.exe -tray uRun: [AnyDVD] c:\program files\ghl\self-installed\anydvd\AnyDVDtray.exe uRun: [SUPERAntiSpyware] c:\program files\ghl\self-installed\SUPERAntiSpyware.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe" mRun: [Corel Photo Downloader] c:\program files\corel\corel snapfire plus\Corel Photo Downloader.exe mRun: [avast!] c:\progra~1\ghl\self-i~1\avast\ashDisp.exe mRun: [PWRISOVM.EXE] c:\program files\ghl\self-installed\poweriso\PWRISOVM.EXE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\ghl\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\ghl\self-installed\palm\Hotsync.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: !SASWinLogon - c:\program files\ghl\self-installed\SASWINLO.dll Notify: LMIinit - LMIinit.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\ghl\self-installed\SASSEH.DLL ============= SERVICES / DRIVERS =============== R0 crpf;crpf;c:\windows\system32\drivers\crpf.sys [2009-7-10 36512] R0 csdf;csdf;c:\windows\system32\drivers\csdf.sys [2009-7-10 39456] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-6 114768] R1 SASDIFSV;SASDIFSV;c:\program files\ghl\self-installed\sasdifsv.sys [2009-2-17 8944] R1 SASKUTIL;SASKUTIL;c:\program files\ghl\self-installed\SASKUTIL.SYS [2009-2-17 55024] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-6 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\ghl\self-installed\avast\ashServ.exe [2009-6-6 138680] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-2-4 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-2-4 47640] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-4-12 24652] R3 SASENUM;SASENUM;c:\program files\ghl\self-installed\SASENUM.SYS [2009-2-17 7408] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\ghl\self-installed\avast\ashMaiSv.exe [2009-6-6 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\ghl\self-installed\avast\ashWebSv.exe [2009-6-6 352920] S4 LMIRfsClientNP;LMIRfsClientNP; [x] =============== Created Last 30 ================ 2009-07-31 17:12 –d—– c:\program files\ESET 2009-07-31 16:37 410,984 a——- c:\windows\system32\deploytk.dll 2009-07-28 03:22 –d—– c:\windows\system32\dllcache\cache 2009-07-28 03:08 a-dshr– C:\cmdcons 2009-07-28 03:04 219,648 a——- c:\windows\PEV.exe 2009-07-28 03:04 161,792 a——- c:\windows\SWREG.exe 2009-07-28 03:04 98,816 a——- c:\windows\sed.exe 2009-07-25 20:15 –d—– c:\documents and settings\ghl\.SunDownloadManager 2009-07-25 14:35 –d—– c:\program files\Windows Media Connect 2 2009-07-23 10:52 278,221 a——- c:\program files\gmer.zip 2009-07-12 10:49 308,160 a——- c:\program files\avast_home_setup.exe 2009-07-11 18:20 265,216 a——- c:\program files\TFC.exe 2009-07-11 18:14 794,112 a——- c:\program files\The_Comedian.exe 2009-07-11 05:50 –d—– c:\program files\Trend Micro 2009-07-11 05:50 812,344 a——- c:\program files\HJTInstall.exe 2009-07-10 21:25 39,456 a——- c:\windows\system32\drivers\csdf.sys 2009-07-10 21:25 36,512 a——- c:\windows\system32\drivers\crpf.sys 2009-07-10 21:25 8,456 a——- c:\windows\system32\cnat.exe 2009-07-10 21:25 –d—– c:\program files\COMODO 2009-07-10 21:24 5,575,824 a——- c:\program files\CSC_Setup_1.1.64946.38_xp_vista_server2003_x32.exe 2009-07-10 19:40 –dsh— c:\windows\System Volume Information 2009-07-04 15:27 –d—– c:\program files\Audacity 2009-07-04 15:26 2,228,534 a——- c:\program files\audacity-win-1.2.6.exe 2009-07-04 15:12 –d—– c:\windows\system32\appmgmt 2009-07-04 11:04 –d—– c:\program files\QuickMediaConverter 2009-07-04 10:38 2,790,624 a——- c:\program files\x-audio-converter-CNET.exe 2009-07-04 10:27 6,698,028 a——- c:\program files\aaep.exe 2009-07-04 10:24 86,683 a——- c:\windows\system32\pthreadGC2.dll 2009-07-04 10:24 –d—– c:\program files\AoA Audio Extractor 2009-07-04 10:19 –d—– c:\program files\YouTube Downloader 2009-07-04 10:18 3,176,437 a——- c:\program files\youtubedownloader.exe 2009-07-04 10:01 8,079,082 a——- c:\program files\audioextractor.exe 2009-07-04 08:56 107,864 a——- c:\windows\system32\tsccvid.dll 2009-07-04 08:56 –d—– c:\windows\system32\QuickTime 2009-07-04 08:56 –d—– c:\program files\common files\TechSmith Shared 2009-07-03 19:41 –d—– c:\docume~1\ghl\applic~1\River Past G5 2009-07-03 19:41 –d—– c:\docume~1\alluse~1\applic~1\River Past G5 2009-07-03 19:41 7,814,384 a——- c:\program files\audiocapture_wmf_setup.exe 2009-07-03 19:40 23,442,487 a——- c:\program files\INSTALL.zip 2009-07-03 19:30 –d—– c:\program files\SoundCapture 2009-07-03 19:29 751,167 a——- c:\program files\sc11a.exe 2009-07-03 19:23 –d—– c:\program files\Free M4a to MP3 Converter 2009-07-03 19:23 2,813,421 a——- c:\program files\m4a-to-mp3-converter.exe 2009-07-03 19:00 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-07-03 19:00 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-07-03 19:00 –d—– c:\program files\iPod 2009-07-03 19:00 –d—– c:\program files\iTunes 2009-07-03 19:00 –d—– c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-07-03 18:57 77,690,152 a——- c:\program files\iTunesSetup.exe 2009-07-03 11:34 –d—– c:\program files\NCH Software 2009-07-03 11:34 434,832 a——- c:\program files\switchsetup.exe 2009-07-03 11:25 6,692,753 a——- c:\program files\Setup_FreeConverter.exe 2009-07-03 11:18 21,935,408 a——- c:\program files\QuickTimeInstaller.exe 2009-07-03 11:00 2,560 ——– c:\windows\system32\drivers\cdralw2k.sys 2009-07-03 11:00 2,432 ——– c:\windows\system32\drivers\cdr4_xp.sys 2009-07-03 10:59 –d—– c:\program files\common files\muvee Technologies 2009-07-03 10:58 –d—– c:\windows\RegisteredPackages ==================== Find3M ==================== 2009-07-25 23:20 48,937 a——- c:\windows\system32\nvModes.dat 2009-07-19 06:33 3,597,824 ——– c:\windows\system32\dllcache\mshtml.dll 2009-07-19 06:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll 2009-07-13 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-13 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-29 04:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-06-29 04:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-06-29 01:35 634,632 ——– c:\windows\system32\dllcache\iexplore.exe 2009-06-29 01:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat 2009-06-29 01:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2009-06-24 07:03 13,905,056 a——- c:\program files\aim6591.exe 2009-05-07 08:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-07 08:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll 2009-04-12 12:32 15,452,536 a——- c:\program files\IE7-WindowsXP-x86-enu.exe ============= FINISH: 18:27:14.57 ===============
Hi greyspace,

I tried to download the Java update again and think that I was successful with it this time

It does look like it worked, it's showing in your log. :thumbup:

Did you manage to uninstall Java™ 6 Update 6 as it shows in your log also.

Eset log loook good.

If no other problems, we can clean up our tools.

From your desktop, please delete
  • any notepads/logs that we created
  • user.zip
  • SafeBoot-for-Windows-XP-SP3.reg
  • DDS.scr
  • GMER.zip from wherever you downloaded it to
  • GMER.exe from where you extracted it to
Eset online can be removed via add/remove programs if you wish.

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u


Updates and upgrades

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7.0.8 first. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have an antivirus program (Avast), and an on dema antispyware program (MBAM).

I recommend you use an antispyware program with resident (real time) scanning. I suggest

Winpatrol
OR
Windows Defender


* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI