This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Cannot open hijack this or malwarebytes

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I must go to work now and wont be back til tomorrow at earliest. Just let me know what i can do when i get back. Thanks
Hey CatByte,
My work got cancelled so I was able to do what you asked. Heres the results




ComboFix 09-07-28.01 - Susan White 07/28/2009 17:41.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.495.172 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common
c:\windows\010112010146118114.dat
c:\windows\0101120101464849.dat
c:\windows\0101120101465749.dat
c:\windows\0101120101465752.dat
c:\windows\Installer\152d2.msp
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job

.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-28 )))))))))))))))))))))))))))))))
.

2009-07-15 00:52 . 2009-07-15 00:56 10 —-a-w- c:\windows\popcinfo.dat
2009-07-14 01:38 . 2009-07-14 02:14 ——– d—–w- c:\documents and settings\Susan White\Application Data\BitTorrent
2009-07-14 01:38 . 2009-07-14 01:38 ——– d—–w- c:\program files\BitTorrent
2009-07-14 01:37 . 2009-07-14 01:37 ——– d—–w- c:\program files\AskBarDis
2009-07-14 01:36 . 2009-07-14 01:36 ——– d—–w- c:\documents and settings\Susan White\Application Data\Convivea
2009-07-14 01:36 . 2009-04-10 23:40 118784 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\x.exe
2009-07-14 01:36 . 2008-03-28 15:07 20992 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\languages\compare.exe
2009-07-14 01:36 . 2008-03-28 15:02 60928 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\update.exe
2009-07-14 01:36 . 2007-07-12 00:43 24557 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\special.exe
2009-07-14 01:36 . 2003-08-19 10:06 80896 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\x.dll
2009-07-14 01:12 . 2009-07-14 01:12 ——– d—–w- c:\documents and settings\Susan White\Application Data\AVS4YOU
2009-07-14 01:12 . 2009-07-14 01:12 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVS4YOU
2009-07-14 01:10 . 2009-07-14 01:11 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-07-14 01:10 . 2008-08-13 16:22 974848 —-a-w- c:\windows\system32\mfc70.dll
2009-07-14 01:10 . 2008-08-13 16:22 487424 —-a-w- c:\windows\system32\msvcp70.dll
2009-07-14 01:10 . 2008-08-13 16:22 344064 —-a-w- c:\windows\system32\msvcr70.dll
2009-07-14 01:10 . 2008-08-13 16:22 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2009-07-14 01:10 . 2009-07-14 01:11 ——– d—–w- c:\program files\AVS4YOU
2009-07-14 01:10 . 2008-08-13 16:22 24576 —-a-w- c:\windows\system32\msxml3a.dll
2009-07-13 02:20 . 2009-07-13 02:20 ——– d—–w- c:\documents and settings\Susan White\Application Data\MSNInstaller
2009-07-07 22:05 . 2009-07-07 22:05 ——– d—–w- c:\program files\Elaborate Bytes
2009-07-06 22:00 . 2009-07-06 22:00 1 —h–w- c:\windows\bf23567.dat
2009-07-06 17:43 . 2009-07-06 17:43 1 —h–w- c:\windows\jmmark2.dat
2009-07-06 15:14 . 2009-07-06 15:14 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2009-07-06 15:14 . 2009-07-06 15:14 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-07-06 15:07 . 2009-07-06 15:08 ——– d—–w- c:\documents and settings\Susan White\Application Data\DriverCure
2009-07-06 15:06 . 2009-07-12 23:36 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\DriverCure
2009-07-06 15:06 . 2009-07-06 15:06 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\ParetoLogic
2009-07-02 16:45 . 2009-07-02 16:45 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 15:32 . 2008-09-03 18:02 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Google Updater
2009-07-28 15:29 . 2009-05-25 01:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-22 02:41 . 2008-11-24 17:42 256 —-a-w- c:\windows\system32\pool.bin
2009-07-15 00:52 . 2007-04-12 04:19 ——– d—–w- c:\program files\PopCap Games
2009-07-14 01:36 . 2007-11-01 21:47 ——– d—–w- c:\program files\Bit Che
2009-07-13 18:36 . 2009-05-25 01:23 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 18:36 . 2009-05-25 01:23 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 23:35 . 2007-11-07 17:08 ——– d—–w- c:\program files\LimeWire
2009-07-09 14:26 . 2008-11-20 22:12 ——– d—a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-07-09 14:15 . 2007-05-25 22:15 ——– d—–w- c:\documents and settings\Susan White\Application Data\LimeWire
2009-07-05 21:45 . 2006-11-20 16:20 ——– d—–w- c:\program files\Microsoft Digital Image 2006
2009-07-05 20:48 . 2007-05-22 03:48 ——– d—–w- c:\documents and settings\Susan White\Application Data\Image Zone Express
2009-07-04 14:03 . 2009-05-14 01:32 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 19:59 . 2009-06-12 13:33 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2009-06-22 07:55 . 2009-06-08 21:30 3561743 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-16 13:40 . 2009-05-14 01:32 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-12 13:33 . 2009-06-12 13:33 ——– d—–w- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\AVGTOOLBAR
2009-06-11 03:27 . 2006-11-17 23:23 ——– d—–w- c:\program files\Microsoft Works
2009-06-08 03:38 . 2008-06-13 21:40 4810 —-a-w- c:\documents and settings\Susan White\Application Data\wklnhst.dat
2009-06-02 18:38 . 2009-06-12 17:55 1004800 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-01 18:21 . 2009-06-01 18:21 73728 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
2009-06-01 18:21 . 2009-06-01 18:21 499712 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
2009-06-01 18:21 . 2009-06-01 18:21 348160 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
2009-06-01 18:21 . 2009-06-01 18:21 102400 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
2009-06-01 18:21 . 2009-06-01 18:20 8462336 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xul.dll
2009-05-22 23:08 . 2009-05-22 23:08 29696 —-a-w- c:\windows\system32\drivers\VClone.sys
2009-05-22 14:13 . 2009-05-22 13:16 256 —-a-w- c:\documents and settings\Susan White\pool.bin
2009-05-19 17:43 . 2007-05-10 05:32 376424 —-a-w- c:\documents and settings\Susan White\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE2_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 69632 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\DesktopMgr.exe
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE1_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-14 23:41 . 2009-05-14 01:33 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-14 23:41 . 2009-05-14 01:33 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-14 23:41 . 2009-05-14 01:33 12552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-05-13 05:15 . 2006-02-28 12:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2007-05-10 08:00 . 2007-05-10 07:59 288104 -c–a-w- c:\program files\dxwebsetup.exe
2004-10-01 21:00 . 2006-11-20 18:24 40960 -c–a-w- c:\program files\Uninstall_CDS.exe
2004-10-01 21:00 . 2006-11-20 18:24 40960 -c–a-w- c:\program files\Uninstall_CDS(2).exe
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-05-11 10:06 . 2007-05-11 10:06 40048 c:\program files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe

2007-07-23 09:19 . 2007-07-23 09:19 180269 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe

2005-12-15 17:18 . 2005-12-15 17:18 49152 c:\program files\HP\HP Software Update\bak\HPWuSchd2.exe

2007-09-26 19:42 . 2007-09-26 19:42 267064 c:\program files\iTunes\bak\iTunesHelper.exe
2008-09-10 22:40 . 2008-09-10 22:40 289576 c:\program files\iTunes\iTunesHelper.exe

2006-11-17 20:38 . 2004-10-13 16:24 1694208 c:\program files\Messenger\bak\msmsgs.exe
2008-06-28 22:14 . 2008-04-14 00:12 1695232 c:\program files\Messenger\msmsgs.exe

2007-06-29 11:24 . 2007-06-29 11:24 286720 c:\program files\QuickTime\bak\QTTask.exe
2008-09-06 20:09 . 2008-09-06 20:09 413696 c:\program files\QuickTime\QTTask.exe

2006-12-01 00:59 . 2007-03-27 22:22 4670968 c:\program files\Yahoo!\Messenger\bak\YAHOOM~2.EXE

2006-02-28 12:00 . 2006-02-28 12:00 15360 c:\windows\system32\bak\ctfmon.exe
2006-02-28 12:00 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-29 22:24 325000 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 14:29 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-03 39408]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" [2007-11-29 583048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-06-08 236016]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-03-03 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
desktop(2).ini [2006-11-17 84]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2007-5-10 266240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-14 23:41 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Susan White^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Susan White\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/13/2009 8:33 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/13/2009 8:32 PM 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/13/2009 8:33 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/14/2009 6:41 PM 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/14/2009 6:41 PM 298776]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [9/19/2007 11:47 AM 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [9/19/2007 11:47 AM 7680]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Susan White\Desktop\SysProt\SysProt\SysProtDrv.sys [7/28/2009 11:28 AM 44288]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-07-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-03 20:24]

2009-07-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} - hxxp://www.mgisoft.com/ActiveX/LPControl.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
.

**************************************************************************

driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-28 17:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,0c,c7,52,21,5a,a9,46,99,eb,2f,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,0c,c7,52,21,5a,a9,46,99,eb,2f,\

[HKEY_USERS\S-1-5-21-507921405-308236825-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-07-28 17:53
ComboFix-quarantined-files.txt 2009-07-28 22:53
ComboFix2.txt 2009-03-04 16:25

Pre-Run: 122,487,951,360 bytes free
Post-Run: 122,542,903,296 bytes free

257 — E O F — 2009-07-19 02:06
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Cannot_open_hijack_malwarebytes_t105573.html&view=findpost&p=582734#entry582734

Collect::
c:\windows\bf23567.dat
c:\windows\jmmark2.dat

Folder::
c:\program files\AskBarDis

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"=-

RegLock::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Okay got that done for you too. Here is the new log file


ComboFix 09-07-28.01 - Susan White 07/28/2009 19:22.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.495.241 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix\ComboFix.exe
Command switches used :: c:\documents and settings\Susan White\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\windows\bf23567.dat
file zipped: c:\windows\jmmark2.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Cache\0004B2A3
c:\program files\AskBarDis\bar\Cache\0004B581
c:\program files\AskBarDis\bar\Cache\0004B6AA.bin
c:\program files\AskBarDis\bar\Cache\0004B89E.bin
c:\program files\AskBarDis\bar\Cache\0004B979.bin
c:\program files\AskBarDis\bar\Cache\0004BA53.bin
c:\program files\AskBarDis\bar\Cache\0004BB2E.bin
c:\program files\AskBarDis\bar\Cache\0004BC18.bin
c:\program files\AskBarDis\bar\Cache\000DDA05
c:\program files\AskBarDis\bar\Cache\files.ini
c:\program files\AskBarDis\bar\History\search
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\bar\Settings\prevcfg.htm
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\windows\bf23567.dat
c:\windows\jmmark2.dat

.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-29 )))))))))))))))))))))))))))))))
.

2009-07-15 00:52 . 2009-07-15 00:56 10 —-a-w- c:\windows\popcinfo.dat
2009-07-14 01:38 . 2009-07-14 02:14 ——– d—–w- c:\documents and settings\Susan White\Application Data\BitTorrent
2009-07-14 01:38 . 2009-07-14 01:38 ——– d—–w- c:\program files\BitTorrent
2009-07-14 01:36 . 2009-07-14 01:36 ——– d—–w- c:\documents and settings\Susan White\Application Data\Convivea
2009-07-14 01:36 . 2009-04-10 23:40 118784 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\x.exe
2009-07-14 01:36 . 2008-03-28 15:07 20992 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\languages\compare.exe
2009-07-14 01:36 . 2008-03-28 15:02 60928 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\update.exe
2009-07-14 01:36 . 2007-07-12 00:43 24557 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\special.exe
2009-07-14 01:36 . 2003-08-19 10:06 80896 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\x.dll
2009-07-14 01:12 . 2009-07-14 01:12 ——– d—–w- c:\documents and settings\Susan White\Application Data\AVS4YOU
2009-07-14 01:12 . 2009-07-14 01:12 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVS4YOU
2009-07-14 01:10 . 2009-07-14 01:11 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-07-14 01:10 . 2008-08-13 16:22 974848 —-a-w- c:\windows\system32\mfc70.dll
2009-07-14 01:10 . 2008-08-13 16:22 487424 —-a-w- c:\windows\system32\msvcp70.dll
2009-07-14 01:10 . 2008-08-13 16:22 344064 —-a-w- c:\windows\system32\msvcr70.dll
2009-07-14 01:10 . 2008-08-13 16:22 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2009-07-14 01:10 . 2009-07-14 01:11 ——– d—–w- c:\program files\AVS4YOU
2009-07-14 01:10 . 2008-08-13 16:22 24576 —-a-w- c:\windows\system32\msxml3a.dll
2009-07-13 02:20 . 2009-07-13 02:20 ——– d—–w- c:\documents and settings\Susan White\Application Data\MSNInstaller
2009-07-07 22:05 . 2009-07-07 22:05 ——– d—–w- c:\program files\Elaborate Bytes
2009-07-06 15:14 . 2009-07-06 15:14 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2009-07-06 15:14 . 2009-07-06 15:14 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-07-06 15:07 . 2009-07-06 15:08 ——– d—–w- c:\documents and settings\Susan White\Application Data\DriverCure
2009-07-06 15:06 . 2009-07-12 23:36 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\DriverCure
2009-07-06 15:06 . 2009-07-06 15:06 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\ParetoLogic
2009-07-02 16:45 . 2009-07-02 16:45 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 15:32 . 2008-09-03 18:02 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Google Updater
2009-07-28 15:29 . 2009-05-25 01:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-22 02:41 . 2008-11-24 17:42 256 —-a-w- c:\windows\system32\pool.bin
2009-07-15 00:52 . 2007-04-12 04:19 ——– d—–w- c:\program files\PopCap Games
2009-07-14 01:36 . 2007-11-01 21:47 ——– d—–w- c:\program files\Bit Che
2009-07-13 18:36 . 2009-05-25 01:23 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 18:36 . 2009-05-25 01:23 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 23:35 . 2007-11-07 17:08 ——– d—–w- c:\program files\LimeWire
2009-07-09 14:26 . 2008-11-20 22:12 ——– d—a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-07-09 14:15 . 2007-05-25 22:15 ——– d—–w- c:\documents and settings\Susan White\Application Data\LimeWire
2009-07-05 21:45 . 2006-11-20 16:20 ——– d—–w- c:\program files\Microsoft Digital Image 2006
2009-07-05 20:48 . 2007-05-22 03:48 ——– d—–w- c:\documents and settings\Susan White\Application Data\Image Zone Express
2009-07-04 14:03 . 2009-05-14 01:32 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 19:59 . 2009-06-12 13:33 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2009-06-22 07:55 . 2009-06-08 21:30 3561743 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-16 13:40 . 2009-05-14 01:32 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-12 13:33 . 2009-06-12 13:33 ——– d—–w- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\AVGTOOLBAR
2009-06-11 03:27 . 2006-11-17 23:23 ——– d—–w- c:\program files\Microsoft Works
2009-06-08 03:38 . 2008-06-13 21:40 4810 —-a-w- c:\documents and settings\Susan White\Application Data\wklnhst.dat
2009-06-02 18:38 . 2009-06-12 17:55 1004800 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-01 18:21 . 2009-06-01 18:21 73728 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
2009-06-01 18:21 . 2009-06-01 18:21 499712 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
2009-06-01 18:21 . 2009-06-01 18:21 348160 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
2009-06-01 18:21 . 2009-06-01 18:21 102400 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
2009-06-01 18:21 . 2009-06-01 18:20 8462336 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xul.dll
2009-05-22 23:08 . 2009-05-22 23:08 29696 —-a-w- c:\windows\system32\drivers\VClone.sys
2009-05-22 14:13 . 2009-05-22 13:16 256 —-a-w- c:\documents and settings\Susan White\pool.bin
2009-05-19 17:43 . 2007-05-10 05:32 376424 —-a-w- c:\documents and settings\Susan White\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE2_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 69632 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\DesktopMgr.exe
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE1_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-14 23:41 . 2009-05-14 01:33 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-14 23:41 . 2009-05-14 01:33 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-14 23:41 . 2009-05-14 01:33 12552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-05-13 05:15 . 2006-02-28 12:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2007-05-10 08:00 . 2007-05-10 07:59 288104 -c–a-w- c:\program files\dxwebsetup.exe
2004-10-01 21:00 . 2006-11-20 18:24 40960 -c–a-w- c:\program files\Uninstall_CDS.exe
2004-10-01 21:00 . 2006-11-20 18:24 40960 -c–a-w- c:\program files\Uninstall_CDS(2).exe
.

((((((((((((((((((((((((((((( SnapShot@2009-07-28_22.49.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-20 03:37 . 2009-07-28 23:39 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-06-20 03:37 . 2009-07-28 19:53 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-05-11 10:06 . 2007-05-11 10:06 40048 c:\program files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe

2007-07-23 09:19 . 2007-07-23 09:19 180269 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe

2005-12-15 17:18 . 2005-12-15 17:18 49152 c:\program files\HP\HP Software Update\bak\HPWuSchd2.exe

2007-09-26 19:42 . 2007-09-26 19:42 267064 c:\program files\iTunes\bak\iTunesHelper.exe
2008-09-10 22:40 . 2008-09-10 22:40 289576 c:\program files\iTunes\iTunesHelper.exe

2006-11-17 20:38 . 2004-10-13 16:24 1694208 c:\program files\Messenger\bak\msmsgs.exe
2008-06-28 22:14 . 2008-04-14 00:12 1695232 c:\program files\Messenger\msmsgs.exe

2007-06-29 11:24 . 2007-06-29 11:24 286720 c:\program files\QuickTime\bak\QTTask.exe
2008-09-06 20:09 . 2008-09-06 20:09 413696 c:\program files\QuickTime\QTTask.exe

2006-12-01 00:59 . 2007-03-27 22:22 4670968 c:\program files\Yahoo!\Messenger\bak\YAHOOM~2.EXE

2006-02-28 12:00 . 2006-02-28 12:00 15360 c:\windows\system32\bak\ctfmon.exe
2006-02-28 12:00 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 14:29 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-03 39408]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" [2007-11-29 583048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-06-08 236016]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-03-03 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
desktop(2).ini [2006-11-17 84]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2007-5-10 266240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-14 23:41 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Susan White^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Susan White\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/13/2009 8:33 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/13/2009 8:32 PM 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/13/2009 8:33 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/14/2009 6:41 PM 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/14/2009 6:41 PM 298776]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [9/19/2007 11:47 AM 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [9/19/2007 11:47 AM 7680]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Susan White\Desktop\SysProt\SysProt\SysProtDrv.sys [7/28/2009 11:28 AM 44288]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-07-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-03 20:24]

2009-07-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\AskBarDis\bar\bin\askBar.dll


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} - hxxp://www.mgisoft.com/ActiveX/LPControl.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
.

**************************************************************************

catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-28 19:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-507921405-308236825-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-07-29 19:32
ComboFix-quarantined-files.txt 2009-07-29 00:32
ComboFix2.txt 2009-07-28 22:53
ComboFix3.txt 2009-03-04 16:25

Pre-Run: 122,540,613,632 bytes free
Post-Run: 122,528,124,928 bytes free

266 — E O F — 2009-07-19 02:06
Upload was successful
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

AWF::
c:\program files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
c:\program files\HP\HP Software Update\bak\HPWuSchd2.exe
c:\program files\Yahoo!\Messenger\bak\YAHOOM~2.EXE

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
Okay here are the things you requested of me in the order you requested. The kaspersky scan took a few hours all totalled up.


Combo-Fix:


ComboFix 09-07-28.01 - Susan White 07/28/2009 22:06.4.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.495.175 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix\ComboFix.exe
Command switches used :: c:\documents and settings\Susan White\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-29 )))))))))))))))))))))))))))))))
.

2009-07-15 00:52 . 2009-07-15 00:56 10 —-a-w- c:\windows\popcinfo.dat
2009-07-14 01:38 . 2009-07-14 02:14 ——– d—–w- c:\documents and settings\Susan White\Application Data\BitTorrent
2009-07-14 01:38 . 2009-07-14 01:38 ——– d—–w- c:\program files\BitTorrent
2009-07-14 01:36 . 2009-07-14 01:36 ——– d—–w- c:\documents and settings\Susan White\Application Data\Convivea
2009-07-14 01:36 . 2009-04-10 23:40 118784 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\x.exe
2009-07-14 01:36 . 2008-03-28 15:07 20992 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\languages\compare.exe
2009-07-14 01:36 . 2008-03-28 15:02 60928 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\update.exe
2009-07-14 01:36 . 2007-07-12 00:43 24557 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\special.exe
2009-07-14 01:36 . 2003-08-19 10:06 80896 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\x.dll
2009-07-14 01:12 . 2009-07-14 01:12 ——– d—–w- c:\documents and settings\Susan White\Application Data\AVS4YOU
2009-07-14 01:12 . 2009-07-14 01:12 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVS4YOU
2009-07-14 01:10 . 2009-07-14 01:11 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-07-14 01:10 . 2008-08-13 16:22 974848 —-a-w- c:\windows\system32\mfc70.dll
2009-07-14 01:10 . 2008-08-13 16:22 487424 —-a-w- c:\windows\system32\msvcp70.dll
2009-07-14 01:10 . 2008-08-13 16:22 344064 —-a-w- c:\windows\system32\msvcr70.dll
2009-07-14 01:10 . 2008-08-13 16:22 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2009-07-14 01:10 . 2009-07-14 01:11 ——– d—–w- c:\program files\AVS4YOU
2009-07-14 01:10 . 2008-08-13 16:22 24576 —-a-w- c:\windows\system32\msxml3a.dll
2009-07-13 02:20 . 2009-07-13 02:20 ——– d—–w- c:\documents and settings\Susan White\Application Data\MSNInstaller
2009-07-07 22:05 . 2009-07-07 22:05 ——– d—–w- c:\program files\Elaborate Bytes
2009-07-06 15:14 . 2009-07-06 15:14 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2009-07-06 15:14 . 2009-07-06 15:14 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-07-06 15:07 . 2009-07-06 15:08 ——– d—–w- c:\documents and settings\Susan White\Application Data\DriverCure
2009-07-06 15:06 . 2009-07-12 23:36 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\DriverCure
2009-07-06 15:06 . 2009-07-06 15:06 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\ParetoLogic
2009-07-02 16:45 . 2009-07-02 16:45 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 15:32 . 2008-09-03 18:02 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Google Updater
2009-07-28 15:29 . 2009-05-25 01:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-22 02:41 . 2008-11-24 17:42 256 —-a-w- c:\windows\system32\pool.bin
2009-07-15 00:52 . 2007-04-12 04:19 ——– d—–w- c:\program files\PopCap Games
2009-07-14 01:36 . 2007-11-01 21:47 ——– d—–w- c:\program files\Bit Che
2009-07-13 18:36 . 2009-05-25 01:23 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 18:36 . 2009-05-25 01:23 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 23:35 . 2007-11-07 17:08 ——– d—–w- c:\program files\LimeWire
2009-07-09 14:26 . 2008-11-20 22:12 ——– d—a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-07-09 14:15 . 2007-05-25 22:15 ——– d—–w- c:\documents and settings\Susan White\Application Data\LimeWire
2009-07-05 21:45 . 2006-11-20 16:20 ——– d—–w- c:\program files\Microsoft Digital Image 2006
2009-07-05 20:48 . 2007-05-22 03:48 ——– d—–w- c:\documents and settings\Susan White\Application Data\Image Zone Express
2009-07-04 14:03 . 2009-05-14 01:32 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 19:59 . 2009-06-12 13:33 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2009-06-22 07:55 . 2009-06-08 21:30 3561743 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-16 13:40 . 2009-05-14 01:32 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-12 13:33 . 2009-06-12 13:33 ——– d—–w- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\AVGTOOLBAR
2009-06-11 03:27 . 2006-11-17 23:23 ——– d—–w- c:\program files\Microsoft Works
2009-06-08 03:38 . 2008-06-13 21:40 4810 —-a-w- c:\documents and settings\Susan White\Application Data\wklnhst.dat
2009-06-02 18:38 . 2009-06-12 17:55 1004800 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-01 18:21 . 2009-06-01 18:21 73728 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
2009-06-01 18:21 . 2009-06-01 18:21 499712 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
2009-06-01 18:21 . 2009-06-01 18:21 348160 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
2009-06-01 18:21 . 2009-06-01 18:21 102400 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
2009-06-01 18:21 . 2009-06-01 18:20 8462336 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xul.dll
2009-05-22 23:08 . 2009-05-22 23:08 29696 —-a-w- c:\windows\system32\drivers\VClone.sys
2009-05-22 14:13 . 2009-05-22 13:16 256 —-a-w- c:\documents and settings\Susan White\pool.bin
2009-05-19 17:43 . 2007-05-10 05:32 376424 —-a-w- c:\documents and settings\Susan White\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE2_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 69632 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\DesktopMgr.exe
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE1_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-14 23:41 . 2009-05-14 01:33 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-14 23:41 . 2009-05-14 01:33 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-14 23:41 . 2009-05-14 01:33 12552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-05-13 05:15 . 2006-02-28 12:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2007-05-10 08:00 . 2007-05-10 07:59 288104 -c–a-w- c:\program files\dxwebsetup.exe
2004-10-01 21:00 . 2006-11-20 18:24 40960 -c–a-w- c:\program files\Uninstall_CDS.exe
2004-10-01 21:00 . 2006-11-20 18:24 40960 -c–a-w- c:\program files\Uninstall_CDS(2).exe
.

((((((((((((((((((((((((((((( SnapShot@2009-07-28_22.49.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-20 03:37 . 2009-07-28 23:39 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-06-20 03:37 . 2009-07-28 19:53 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-26 19:42 . 2007-09-26 19:42 267064 c:\program files\iTunes\bak\iTunesHelper.exe
2008-09-10 22:40 . 2008-09-10 22:40 289576 c:\program files\iTunes\iTunesHelper.exe

2006-11-17 20:38 . 2004-10-13 16:24 1694208 c:\program files\Messenger\bak\msmsgs.exe
2008-06-28 22:14 . 2008-04-14 00:12 1695232 c:\program files\Messenger\msmsgs.exe

2007-06-29 11:24 . 2007-06-29 11:24 286720 c:\program files\QuickTime\bak\QTTask.exe
2008-09-06 20:09 . 2008-09-06 20:09 413696 c:\program files\QuickTime\QTTask.exe

2006-02-28 12:00 . 2006-02-28 12:00 15360 c:\windows\system32\bak\ctfmon.exe
2006-02-28 12:00 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 14:29 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-03 39408]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" [2007-11-29 583048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-06-08 236016]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-03-03 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
desktop(2).ini [2006-11-17 84]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2007-5-10 266240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-14 23:41 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Susan White^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Susan White\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/13/2009 8:33 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/13/2009 8:32 PM 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/13/2009 8:33 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/14/2009 6:41 PM 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/14/2009 6:41 PM 298776]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [9/19/2007 11:47 AM 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [9/19/2007 11:47 AM 7680]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Susan White\Desktop\SysProt\SysProt\SysProtDrv.sys [7/28/2009 11:28 AM 44288]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-07-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-03 20:24]

2009-07-29 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} - hxxp://www.mgisoft.com/ActiveX/LPControl.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
.

**************************************************************************

driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-28 22:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-507921405-308236825-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2580)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\HPZipm12.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-29 22:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-29 03:24
ComboFix2.txt 2009-07-29 00:45
ComboFix3.txt 2009-07-28 22:53
ComboFix4.txt 2009-03-04 16:25

Pre-Run: 122,471,665,664 bytes free
Post-Run: 122,447,327,232 bytes free

257 — E O F — 2009-07-19 02:06



MalwareBytes Log:


Malwarebytes' Anti-Malware 1.39
Database version: 2525
Windows 5.1.2600 Service Pack 3

7/28/2009 10:36:59 PM
mbam-log-2009-07-28 (22-36-59).txt

Scan type: Quick Scan
Objects scanned: 120591
Time elapsed: 4 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Kaspersky Log:


Wednesday, July 29, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, July 29, 2009 06:15:47
Records in database: 2560065


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area My Computer
A:\
C:\
D:\

Scan statistics
Files scanned 87442
Threat name 5
Infected objects 11
Suspicious objects 0
Duration of the scan 02:32:37

File name Threat name Threats count
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\.tt288.tmp.vbs Infected: Backdoor.Win32.Frauder.eo 1

C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\.tt4.tmp.vbs Infected: Backdoor.Win32.Frauder.eo 1

C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\.tt7.tmp.vbs Infected: Backdoor.Win32.Frauder.eo 1

C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\.tt8.tmp.vbs Infected: Backdoor.Win32.Frauder.eo 1

C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\asher roth.mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1

C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\go head mac bre z.mp3 Infected: Trojan-Downloader.WMA.GetCodec.w 1

C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\life would really suck without.mp3 Infected: Trojan-Downloader.WMA.GetCodec.w 1

C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\the affilates (hot new track).au Infected: Trojan-Downloader.WMA.GetCodec.u 1

C:\System Volume Information\_restore{92326D68-0999-4147-A5A9-63DE7970BEF0}\RP344\A0059462.sys Infected: Rootkit.Win32.Agent.mig 1

C:\System Volume Information\_restore{92326D68-0999-4147-A5A9-63DE7970BEF0}\RP344\A0059463.dll Infected: Packed.Win32.Tdss.w 1

C:\System Volume Information\_restore{92326D68-0999-4147-A5A9-63DE7970BEF0}\RP344\A0059464.dll Infected: Packed.Win32.Tdss.w 1

The selected area was scanned.
Hi

Please do the following:

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Services

:Reg

:Files
C:\Deckard
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\asher roth.mp3 
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\go head mac bre z.mp3 
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\life would really suck without.mp3 
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\the affilates (hot new track).au 

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



NEXT

Run HJT and click on Run a system scan and save a log file.
  • A notepad file will open
  • Copy and paste the log file into your reply.


Also:

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your reply.
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\Deckard\System Scanner\20090221035923\backup\WINDOWS\temp\mdf7ca.tmp moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\WINDOWS\temp\mdf7648.tmp moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\WINDOWS\temp\mdf7151.tmp moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\WINDOWS\temp\mdf4f64.tmp moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\WINDOWS\temp\mdf40dd.tmp moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\WINDOWS\temp moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\WINDOWS\Downloaded Program Files moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\WINDOWS moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\WPDNSE moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GXMVGXM7 moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHAFS16F moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\G1EN8HEN moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0DYNO16B moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5 moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\Temporary Internet Files moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\PSQuar\{C384E28C-3E1D-4839-B5B8-C714F366DA62} moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\PSQuar\{A46C04B5-4A0F-46B9-B014-AF1E4AFA863D} moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\PSQuar\{4637F98F-8A4E-4E1D-9AD3-DDAFDD11A14A} moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\PSQuar\{249AB94B-D765-4EFC-A257-780A43FB810D} moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\PSQuar moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\KAV Updater update files\1065 moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\KAV Updater update files moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\ImageUploader_Temp moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\hsperfdata_Susan White moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1 moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1 moved successfully.
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1 moved successfully.
C:\Deckard\System Scanner\20090221035923\backup moved successfully.
C:\Deckard\System Scanner\20090221035923 moved successfully.
C:\Deckard\System Scanner moved successfully.
C:\Deckard moved successfully.
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\asher roth.mp3 moved successfully.
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\go head mac bre z.mp3 moved successfully.
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\life would really suck without.mp3 moved successfully.
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\the affilates (hot new track).au moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: All Users.WINDOWS

User: Application Data

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 49286 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 2146 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Owner
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 2035968 bytes

User: Susan White
->Temp folder emptied: 76752660 bytes
->Temporary Internet Files folder emptied: 12986909 bytes
->Java cache emptied: 130719 bytes

%systemdrive% .tmp files removed: 0 bytes
C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP folder deleted successfully.
C:\WINDOWS\msdownld.tmp folder deleted successfully.
%systemroot% .tmp files removed: 2198872 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
Windows Temp folder emptied: 12616 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 89.84 mb


OTM by OldTimer - Version 3.0.0.5 log created on 07292009_095333

Files moved on Reboot…

Registry entries deleted on Reboot…









Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:02:01 AM, on 7/29/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SiSPower] "Rundll32.exe" SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} - http://www.mgisoft.com/ActiveX/LPControl.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} - http://67.15.101.33/g_bin/eng/poker_2_0_0_49.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://www.imgag.com/cp/install/Crusher.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://driveragent.com/files/driveragent.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

–
End of file - 11224 bytes
Run HJT and click on Open the Misc Tools section. * Click Open Uninstall Manager… * Click Save list… and save it to your Desktop. * Copy and paste the file uninstall_list.txt into your reply.
Sorry. I missed that last time. Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.1.1 Adobe Shockwave Player Apple Mobile Device Support Apple Software Update ArcSoft PhotoStudio 5.5 ArcSoft VideoImpression 2 AVG 8.5 AVS Update Manager 1.0 AVS Video Converter 6 AVS4YOU Software Navigator 1.3 Bit Che BlackBerry Desktop Software 4.6 BlackBerry Desktop Software 4.6 Bonjour CCleaner (remove only) Critical Update for Windows Media Player 11 (KB959772) DivX Google Earth Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer Google Updater HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) HP Imaging Device Functions 6.1 HP Photosmart Essential HP PSC & OfficeJet 6.1.A HP Software Update HP Solution Center and Imaging Support Tools 6.1 iTunes Java™ 6 Update 6 Java™ 6 Update 7 Kaspersky Online Scanner LiveUpdate (Symantec Corporation) LiveUpdate (Symantec Corporation) LiveUpdate Notice (Symantec Corporation) Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Digital Image Standard 2006 Microsoft Encarta Encyclopedia Standard 2006 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Money 2006 Microsoft National Language Support Downlevel APIs Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Web Publishing Wizard 1.52 Microsoft Word 2002 Microsoft Works Microsoft Works Suite 2006 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word MSXML 4.0 SP2 (KB954430) QuickTime RealPlayer Realtek AC'97 Audio Roxio Media Manager Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) SiS VGA Utilities SiSAGP driver SpywareBlaster 4.2 The Print Shop 22 Update for Windows Internet Explorer 8 (KB971180) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Wal-Mart Digital Photo Manager WeatherBug Windows Defender Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Service Pack 3 Yahoo! Browser Services Yahoo! Internet Mail Yahoo! Messenger Yahoo! Toolbar Zuma Deluxe 1.0
Hi,

You are clean,

just some house keeping to do now

Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

Go to Start > Contol Panel > Add/Remove programs

a list of installed programs will populate

Remove the following programs

WeatherBug
Java™ 6 Update 6
Java™ 6 Update 7


Then go to http://www.java.com/en/download/manual.jsp and download java version 6 update 14 and install.

NEXT:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI