This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] The infamous Clickover.cn problem

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This problem started last week on our family desktop computer. I when doing a search we get redirected to various sites, its always different each time you click the link you want. I have ran malwarebyte's anti malware, adaware, and CCleaner and nothing has helped. The computer appears to work fine other than this. Malwarebyte's anti malware did find the following; Trojan.TDSS Memory Module and Trojan.TDSS File both indicated \\?globalroot\system32\geyekraibynuy.dll. It rebotted to remove and the one indicated as Trojan.TDSS shows up in quarantine but it is still found each time I run malwarebyte's anti malware. Norton showed a trojan as C:\windows\system32\drivers\geyekrwuywquer.sys and rebooted but after the reboot I could see it was still there.

Any assistance is greatly appreciated so we can stop this insanity of the infamous clickover.cn

Below is the HiJack This log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:07:03 AM, on 8/1/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.att.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://photos.walmart.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - https://h20364.www2.hp.com/CSMWeb/Customer/…DataManager.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 12424 bytes
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 10:09:43.07 on Sat 08/01/2009 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3198.1786 [GMT -5:00] AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\hp\support\hpsysdrv.exe C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe C:\Windows\RtHDVCpl.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Windows\System32\rundll32.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\HP Connections\6811507\Program\HP Connections.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Webroot\Washer\WasherSvc.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\ehome\ehsched.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k HPService C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Windows\ehome\ehRecvr.exe C:\hp\kbd\kbd.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\wuauclt.exe C:\Users\Joe and Mel\Desktop\dds.pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.att.net/ uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html mStart Page = hxxp://www.yahoo.com mDefault_Page_URL = hxxp://www.yahoo.com mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.6\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.6\CoIEPlg.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup uRun: [Aim6] uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [KBD] c:\hp\kbd\KbdStub.EXE mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe" mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [ccApp] c:\program files\common files\symantec shared\ccApp.exe mRun: [osCheck] "c:\program files\norton 360\osCheck.exe" mRun: [hpqSRMon] c:\program files\hewlett-packard\digital imaging\bin\hpqSRMon.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpconn~1.lnk - c:\program files\hp connections\6811507\program\HP Connections.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll Trusted Zone: turbotax.com Trusted Zone: walmart.com\photos DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} - hxxps://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} - hxxp://www.linksysfix.com/netcheck/67/install/gtdownls.cab DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ============= SERVICES / DRIVERS =============== R0 AFS;AFS;c:\windows\system32\drivers\AFS.SYS [2007-5-1 79052] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-14 64160] R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\ipsdefs\20090730.002\IDSvix86.sys [2009-7-30 272432] R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1029456] R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-30 24652] R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2007-9-10 598856] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-7-14 101936] R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [2008-1-28 384896] R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2009-2-19 41008] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888] S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-6-17 12648] S3 wrssweep;Webroots Volume Access Driver;c:\program files\webroot\washer\wrSSweep.sys [2007-12-17 21832] S3 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] =============== Created Last 30 ================ 2009-08-01 10:06 –d—– c:\program files\Trend Micro 2009-08-01 08:43 410,984 a——- c:\windows\system32\deploytk.dll 2009-08-01 08:43 –d—– c:\programdata\McAfee 2009-07-15 06:17 289,792 a——- c:\windows\system32\atmfd.dll 2009-07-15 06:17 156,672 a——- c:\windows\system32\t2embed.dll 2009-07-15 06:17 72,704 a——- c:\windows\system32\fontsub.dll 2009-07-15 06:17 10,240 a——- c:\windows\system32\dciman32.dll 2009-07-14 20:34 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-07-14 18:18 –d—– c:\users\joeand~1\appdata\roaming\Malwarebytes 2009-07-14 18:18 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-14 18:18 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-14 18:18 –d—– c:\programdata\Malwarebytes 2009-07-14 18:18 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-14 18:18 –d—– c:\progra~2\Malwarebytes 2009-07-13 21:35 91 a——- c:\windows\system32\geyekryvpwotbw.dat 2009-07-13 21:11 133,502 a——- c:\windows\system32\geyekrbpqwpfeo.dat 2009-07-13 21:11 70,144 a——- c:\windows\system32\drivers\geyekrwuywqear.sys 2009-07-13 21:11 43,520 a——- c:\windows\system32\geyekrmfdvogod.dll 2009-07-13 18:39 –d—– c:\program files\Secunia 2009-07-13 18:07 -cd-h— c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-07-13 18:07 -cd-h— c:\progra~2\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-07-13 18:07 –d—– c:\programdata\Lavasoft 2009-07-13 18:07 –d—– c:\program files\Lavasoft 2009-07-13 17:19 –d—– c:\program files\CCleaner 2009-07-13 17:07 77,824 a——- c:\users\joe and mel\TaskManagerFix.exe 2009-07-08 19:47 –d—– c:\users\joeand~1\appdata\roaming\BSD 2009-07-08 19:47 1,511,936 a——- c:\windows\bsdsetup.dll 2009-07-07 16:31 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-07-07 16:31 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-07-07 16:31 –d—– c:\program files\iPod 2009-07-07 16:31 –d—– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-07-07 16:31 –d—– c:\program files\iTunes 2009-07-07 16:31 –d—– c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-07-07 16:29 –d—– c:\program files\Bonjour ==================== Find3M ==================== 2009-07-18 11:06 827,904 a——- c:\windows\system32\wininet.dll 2009-07-18 11:01 78,336 a——- c:\windows\system32\ieencode.dll 2009-07-18 04:46 26,624 a——- c:\windows\system32\ieUnatt.exe 2009-07-07 16:26 143,360 a——- c:\windows\inf\infstrng.dat 2009-07-07 16:26 86,016 a——- c:\windows\inf\infstor.dat 2009-07-07 16:26 51,200 a——- c:\windows\inf\infpub.dat 2009-06-17 07:20 12,648 a——- c:\windows\system32\drivers\psi_mf.sys 2009-06-05 11:42 2,060,288 a——- c:\windows\system32\usbaaplrc.dll 2009-06-05 11:42 39,424 a——- c:\windows\system32\drivers\usbaapl.sys 2008-07-14 10:55 308,600 ——– c:\programdata\NortonProtectionMemo.exe 2008-07-14 10:55 308,600 ——– c:\progra~2\NortonProtectionMemo.exe 2008-06-11 03:08 665,600 a——- c:\windows\inf\drvindex.dat 2008-05-29 09:41 658 ——– c:\users\joeand~1\appdata\roaming\wklnhst.dat 2008-05-03 16:19 174 a–sh— c:\program files\desktop.ini 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2002-07-31 19:55 108 —sh— c:\windows\WSYS049.SYS ============= FINISH: 10:10:05.25 ===============
Hi,

Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Attached is the CoboFix log ComboFix 09-07-31.04 - Joe and Mel 08/01/2009 10:36.1.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3198.1847 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500 c:\$recycle.bin\S-1-5-21-2638380620-1949518047-3134838997-500 c:\$recycle.bin\S-1-5-21-3499528348-3036978683-1369272189-500 c:\windows\Installer\1b82ec6.msi c:\windows\Installer\22afd.msi c:\windows\system32\drivers\geyekrwuywqear.sys c:\windows\system32\geyekrbpqwpfeo.dat c:\windows\system32\geyekrmfdvogod.dll c:\windows\system32\geyekryvpwotbw.dat c:\windows\twain_16.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_geyekrtxepnrpp ((((((((((((((((((((((((( Files Created from 2009-07-01 to 2009-08-01 ))))))))))))))))))))))))))))))) . 2009-08-01 15:40 . 2009-08-01 15:40 ——– d—–w- c:\users\Joe and Mel\AppData\Local\temp 2009-08-01 15:06 . 2009-08-01 15:06 ——– d—–w- c:\program files\Trend Micro 2009-08-01 14:53 . 2009-07-13 08:00 87888 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090801.003\NAVENG.SYS 2009-08-01 14:53 . 2009-07-13 08:00 875728 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090801.003\NAVEX15.SYS 2009-08-01 14:53 . 2009-06-16 08:00 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090801.003\NAVENG32.DLL 2009-08-01 14:53 . 2009-06-16 08:00 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090801.003\NAVEX32A.DLL 2009-08-01 14:53 . 2009-06-16 08:00 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090801.003\ERASER.SYS 2009-08-01 14:53 . 2009-06-16 08:00 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090801.003\EECTRL.SYS 2009-08-01 14:53 . 2009-06-16 08:00 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090801.003\ECMSVR32.DLL 2009-08-01 14:53 . 2009-06-16 08:00 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090801.003\CCERASER.DLL 2009-08-01 13:43 . 2009-08-01 13:43 410984 —-a-w- c:\windows\system32\deploytk.dll 2009-08-01 13:43 . 2009-08-01 13:43 ——– d—–w- c:\programdata\McAfee 2009-08-01 09:49 . 2009-07-13 08:00 87888 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090731.050\NAVENG.SYS 2009-08-01 09:49 . 2009-07-13 08:00 875728 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090731.050\NAVEX15.SYS 2009-08-01 09:49 . 2009-06-16 08:00 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090731.050\EECTRL.SYS 2009-08-01 09:49 . 2009-06-16 08:00 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090731.050\ECMSVR32.DLL 2009-08-01 09:49 . 2009-06-16 08:00 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090731.050\CCERASER.DLL 2009-08-01 09:49 . 2009-06-16 08:00 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090731.050\NAVENG32.DLL 2009-08-01 09:49 . 2009-06-16 08:00 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090731.050\NAVEX32A.DLL 2009-08-01 09:49 . 2009-06-16 08:00 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090731.050\ERASER.SYS 2009-07-31 00:39 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090730.002\Scxpx86.dll 2009-07-31 00:39 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090730.002\IDSvix86.sys 2009-07-31 00:39 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090730.002\SymIDSco.sys 2009-07-31 00:39 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090730.002\IDSxpx86.dll 2009-07-31 00:39 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090730.002\SymIDSI.dll 2009-07-31 00:39 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090730.002\IDSviA64.sys 2009-07-31 00:39 . 2008-08-09 02:27 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090730.002\IDS9xx86.dll 2009-07-28 01:36 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090722.001\Scxpx86.dll 2009-07-28 01:36 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090722.001\IDSvix86.sys 2009-07-28 01:36 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090722.001\SymIDSco.sys 2009-07-28 01:36 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090722.001\IDSxpx86.dll 2009-07-28 01:36 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090722.001\SymIDSI.dll 2009-07-28 01:36 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090722.001\IDSviA64.sys 2009-07-28 01:36 . 2008-08-09 02:27 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090722.001\IDS9xx86.dll 2009-07-15 11:17 . 2009-06-15 15:24 156672 —-a-w- c:\windows\system32\t2embed.dll 2009-07-15 11:17 . 2009-06-15 15:20 72704 —-a-w- c:\windows\system32\fontsub.dll 2009-07-15 11:17 . 2009-06-15 15:20 10240 —-a-w- c:\windows\system32\dciman32.dll 2009-07-15 11:17 . 2009-06-15 12:52 289792 —-a-w- c:\windows\system32\atmfd.dll 2009-07-15 01:34 . 2009-07-14 23:15 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys 2009-07-14 23:18 . 2009-07-14 23:18 ——– d—–w- c:\users\Joe and Mel\AppData\Roaming\Malwarebytes 2009-07-14 23:18 . 2009-07-13 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-14 23:18 . 2009-07-14 23:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-07-14 23:18 . 2009-07-14 23:18 ——– d—–w- c:\programdata\Malwarebytes 2009-07-14 23:18 . 2009-07-13 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-07-14 23:15 . 2009-07-14 23:15 53617 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aebb.dll 2009-07-13 23:39 . 2009-07-13 23:39 ——– d—–w- c:\program files\Secunia 2009-07-13 23:07 . 2009-08-01 14:31 ——– dc-h–w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-07-13 23:07 . 2009-01-18 21:43 2892112 -c–a-w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe 2009-07-13 23:07 . 2009-07-13 23:08 ——– d—–w- c:\programdata\Lavasoft 2009-07-13 23:07 . 2009-07-13 23:07 ——– d—–w- c:\program files\Lavasoft 2009-07-13 22:19 . 2009-07-13 22:19 ——– d—–w- c:\program files\CCleaner 2009-07-13 22:07 . 2009-07-13 22:07 77824 —-a-w- c:\users\Joe and Mel\TaskManagerFix.exe 2009-07-13 21:32 . 2009-07-13 08:00 87888 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090713.024\NAVENG.SYS 2009-07-13 21:32 . 2009-07-13 08:00 875728 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090713.024\NAVEX15.SYS 2009-07-13 21:32 . 2009-06-16 08:00 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090713.024\NAVENG32.DLL 2009-07-13 21:32 . 2009-06-16 08:00 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090713.024\NAVEX32A.DLL 2009-07-13 21:32 . 2009-06-16 08:00 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090713.024\ERASER.SYS 2009-07-13 21:32 . 2009-06-16 08:00 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090713.024\EECTRL.SYS 2009-07-13 21:32 . 2009-06-16 08:00 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090713.024\ECMSVR32.DLL 2009-07-13 21:32 . 2009-06-16 08:00 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090713.024\CCERASER.DLL 2009-07-09 01:11 . 2009-07-09 01:11 ——– d—–w- c:\users\Joe and Mel\AppData\Local\Xenocode 2009-07-09 00:47 . 2009-07-09 00:47 ——– d—–w- c:\users\Joe and Mel\AppData\Roaming\BSD 2009-07-09 00:47 . 2009-04-27 08:30 1511936 —-a-w- c:\windows\bsdsetup.dll 2009-07-07 21:31 . 2009-03-19 21:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-07-07 21:31 . 2008-04-17 17:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll 2009-07-07 21:31 . 2009-07-07 21:31 ——– d—–w- c:\program files\iPod 2009-07-07 21:31 . 2009-07-07 21:31 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-07-07 21:31 . 2009-07-07 21:31 ——– d—–w- c:\program files\iTunes 2009-07-07 21:29 . 2009-07-07 21:29 ——– d—–w- c:\program files\Bonjour 2009-07-07 21:28 . 2009-07-07 21:28 ——– d—–w- c:\program files\QuickTime 2009-07-07 21:22 . 2009-07-07 21:22 75048 ——w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-01 15:35 . 2009-08-01 15:35 6736 —-a-w- c:\windows\system32\drivers\PROCEXP90.SYS 2009-08-01 14:20 . 2008-03-04 00:47 ——– d—–w- c:\program files\Microsoft Silverlight 2009-08-01 13:43 . 2007-04-23 01:34 ——– d—–w- c:\program files\Java 2009-07-30 08:05 . 2008-09-27 16:30 18368 —-a-w- c:\programdata\Microsoft\VSA\9.0\1033\ResourceCache.dll 2009-07-30 08:05 . 2007-02-09 14:15 ——– d—–w- c:\programdata\Microsoft Help 2009-07-30 08:05 . 2008-09-27 16:30 1154112 —-a-w- c:\programdata\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll 2009-07-30 08:03 . 2008-09-27 16:20 ——– d—–w- c:\program files\Common Files\Merge Modules 2009-07-29 00:04 . 2008-04-14 16:49 5941 —-a-w- c:\programdata\Intuit\QuickBooks 2008\qbbackup.sys 2009-07-18 16:06 . 2009-07-29 11:32 827904 —-a-w- c:\windows\system32\wininet.dll 2009-07-18 16:01 . 2009-07-29 11:32 78336 —-a-w- c:\windows\system32\ieencode.dll 2009-07-18 09:46 . 2009-07-29 11:32 26624 —-a-w- c:\windows\system32\ieUnatt.exe 2009-07-17 11:29 . 2007-10-18 00:37 256 —-a-w- c:\windows\system32\pool.bin 2009-07-17 11:23 . 2007-05-01 23:30 ——– d—–w- c:\program files\PrintMaster Platinum 17 2009-07-16 12:26 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2009-07-14 23:15 . 2009-07-14 23:15 2133360 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ToolBox\LT\HostFileEditor.exe 2009-07-07 21:31 . 2007-07-30 17:13 ——– d—–w- c:\program files\Common Files\Apple 2009-07-07 21:25 . 2007-07-30 17:13 ——– d—–w- c:\programdata\Apple 2009-07-07 00:34 . 2007-04-22 17:44 324552 —-a-w- c:\users\Joe and Mel\AppData\Local\GDIPFONTCACHEV1.DAT 2009-07-06 22:59 . 2007-02-09 14:14 ——– d—–w- c:\program files\Microsoft Works 2009-06-17 12:20 . 2009-06-17 12:20 12648 —-a-w- c:\windows\system32\drivers\psi_mf.sys 2009-06-16 08:00 . 2009-06-16 08:00 89104 ——w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys 2009-06-16 08:00 . 2009-06-16 08:00 876144 ——w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys 2009-06-16 08:00 . 2009-06-16 08:00 371248 ——w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys 2009-06-16 08:00 . 2009-06-16 08:00 259368 ——w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll 2009-06-16 08:00 . 2009-06-16 08:00 2414128 ——w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll 2009-06-16 08:00 . 2009-06-16 08:00 177520 ——w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll 2009-06-16 08:00 . 2009-06-16 08:00 1181040 ——w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll 2009-06-16 08:00 . 2009-06-16 08:00 101936 ——w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys 2009-06-05 16:42 . 2009-06-05 16:42 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2009-06-05 16:42 . 2009-06-05 16:42 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll 2009-05-08 10:17 . 2008-05-04 03:28 849184 ——w- c:\programdata\Intuit\QuickBooks 2008\Components\DownloadQB18\Patch\qbpatch.exe 2009-05-03 22:45 . 2009-05-03 22:45 26694 —-a-r- c:\users\Joe and Mel\AppData\Roaming\Microsoft\Installer\{3B6E1E25-36B3-408B-A658-9AC4F6A721AD}\BlackBerry.exe 2002-08-01 00:55 . 2008-07-18 11:56 108 –sh–w- c:\windows\WSYS049.SYS . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-11 218032] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] "WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-19 2153472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536] "KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536] "OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2006-11-20 155648] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048] "osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512] "hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-01 148888] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-25 44136] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Connections.lnk - c:\program files\HP Connections\6811507\Program\HP Connections.exe [2007-2-9 34520] HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Event Reminder.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Event Reminder.lnk backup=c:\windows\pss\Event Reminder.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^MBCameraMonitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MBCameraMonitor.lnk backup=c:\windows\pss\MBCameraMonitor.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^Users^Joe and Mel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^DING!.lnk] path=c:\users\Joe and Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DING!.lnk backup=c:\windows\pss\DING!.lnk.Startup backupExtension=.Startup [HKLM\~\startupfolder\C:^Users^Joe and Mel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk] path=c:\users\Joe and Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup backupExtension=.Startup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{3E40D532-807E-4817-82AF-9663E6904A7B}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections "{DE06A27E-4C43-4096-BC87-2F3F35BE3663}"= TCP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections "{517C1DF7-3350-4623-BDD0-A089F7280BB8}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections "{B6907B4A-B2F2-4B9A-8E9F-86A900A77496}"= TCP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections "{BAACC9BF-2F2D-4B3F-BD97-7943549C16EF}"= c:\program files\HP Connections\6811507\Program\HP Connections:HP Connections "{C0732967-EBA3-4692-9101-6441CE90F3EC}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections "{92D16FFE-3827-4167-A697-96922BC60EFA}"= TCP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections "{A974D757-AF29-4889-A452-DA741D2938B3}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{0BE2B827-0842-432D-A6B5-19989399CDF8}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{24EE35E3-1883-439B-A1BF-E16011E8ACEB}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{8538C621-E095-4FA6-8750-47507F1012E7}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{7F377FE4-F98D-42AC-B5D8-EEE41A80F757}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{71EB98AF-4B7D-4682-B743-4E55C7565689}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{F2E3FC60-086A-47D3-B8D9-365DBBBE51D1}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger "{2CFAFD09-9847-45E0-8A46-EEDDFEA6AE57}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger "{7001F8D9-6404-4EC7-A867-CCCFEDD2A05C}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server "{8DC49A92-FE18-4CDA-A82A-638E00AA96B9}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server "{A514D52D-85A6-4B09-8785-E53DB93E421A}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{D2E32A60-942A-4C13-9984-B31510CC527E}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{73B540B4-CD8F-47BE-875B-12A29C8F79F2}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{3C198990-F15E-4667-9922-E82964618F60}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{86BCCA24-7D41-464A-9576-000A1374F972}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{CFED341B-0E40-4383-84BE-6652078E9B4D}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{4AB07A1D-1A5A-446A-9941-A62E9ADF5532}"= UDP:c:\program files\TurboTax\Home & Business 2007\32bit\ttax.exe:TurboTax "{1612EF09-4C1A-4856-8A4A-BE61FDAE71E2}"= TCP:c:\program files\TurboTax\Home & Business 2007\32bit\ttax.exe:TurboTax "{CF62179D-3CBB-49E4-BAA0-394D3D05E449}"= UDP:c:\program files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:TurboTax Update Manager "{EADC33C5-079B-4332-83CF-394B542206BE}"= TCP:c:\program files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:TurboTax Update Manager "{E3DE00AE-1C2B-4408-B7FD-2C77F483FFFB}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{367EF1F9-F754-4617-9774-99CDCFCB0666}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{4E513839-EDB7-412E-91F2-B1AB8DC58C2A}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{1214446E-4AC4-4841-951E-FED5B903072E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "{6FE20E90-31A8-4303-BCD9-D977D7699AE4}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{2198E126-E1C8-451D-AC49-4AC01CE8655E}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{2EC17F8D-EE1B-4864-AC0F-F1440F7047C2}"= e:\setup\hpznui01.exe:hpznui01.exe "{2973F62D-6ED0-455D-B823-4F2D46E519A7}"= TCP:427|RPort=427|c:\windows\system32\svchost.exe|Svc=HPSLPSVC:SLP_Service "{F86A421A-3CEF-4741-BFA0-58CC28393050}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe "{56257844-A7D0-4293-A385-C718A0A0F7E4}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:hpqste08.exe "{0324ABD1-9ACA-44B7-AC2B-CA8CB77B695E}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe "{FEBA41FC-278D-4E46-BA4E-901D653925F0}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hposfx08.exe:hposfx08.exe "{8181DC3B-2107-47B9-98A7-20340CE9E7AE}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:hposid01.exe "{1F37D737-49FE-453C-ADE5-1B825CA339C1}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe "{5A438F00-4037-4484-8E58-2CA41DE53604}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpfccopy.exe:hpfccopy.exe "{DEC19A81-8805-4842-B45D-EB23ACDB6D1D}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe "{DC424287-DF67-4B2E-AC10-8944B7136913}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:hpoews01.exe "{74B60C67-A306-441C-9660-E5D71703CDF5}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe "{B85C2D81-E2B1-4038-820F-43176270E72A}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe "{891771BF-FB37-4FA4-A81B-3EB7F3FCD827}"= c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe:hpqphotocrm.exe "{A4A6C870-97B1-4968-A5A1-2329D6BAEFD6}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqsudi.exe:hpqsudi.exe "{D15930B7-CC85-48AC-9EF7-C5805796FDCE}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqpsapp.exe:hpqpsapp.exe "{553EA907-66F4-452E-98CB-EC4A67C8A3B4}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqcopy2.exe:hpqcopy2.exe "{1EF3196D-0B1D-4991-91DC-A17DD4C789CE}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpofxs08.exe:hpofxs08.exe "{4D1360FA-EB65-4556-B8B5-8358CA83C35D}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqfxt08.exe:hpqfxt08.exe "{73D836FD-7AB6-4240-A93A-6452D4B65D5D}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqpse.exe:hpqpse.exe "{781DAFF6-77CD-4738-825C-05DB23B5FA3D}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqgplgtupl.exe:hpqgplgtupl.exe "{2CC92790-236A-4801-B965-5CB9BB6316AA}"= c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe:hpqgpc01.exe "{9F99E0AC-890E-4301-B7EA-29D507BAE668}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{2A4542FE-0BF9-4DD0-BA47-42510706B109}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{16B2BAE2-CB87-4431-9AA5-AB1D1AD08F55}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{7FA9610F-F52C-47CF-AC2B-1AE739CDC15E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List] "c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink "c:\\Program Files\\Microsoft Expression\\Media 2\\Media.exe"= c:\program files\Microsoft Expression\Media 2\Media.exe:*:Enabled:iView Multimedia R0 AFS;AFS;c:\windows\System32\drivers\AFS.SYS [5/1/2007 6:47 PM 79052] R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [7/14/2009 8:34 PM 64160] R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090730.002\IDSvix86.sys [7/30/2009 7:39 PM 272432] R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 4:34 PM 1029456] R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 2:37 PM 149352] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/30/2007 12:28 PM 24652] R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [9/10/2007 4:13 PM 598856] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [7/14/2009 6:30 PM 101936] R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\System32\drivers\hcw18bda.sys [1/28/2008 10:44 PM 384896] R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 12:31 PM 41008] S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [1/12/2008 9:32 PM 23888] S3 PSI;PSI;c:\windows\System32\drivers\psi_mf.sys [6/17/2009 7:20 AM 12648] S3 wrssweep;Webroots Volume Access Driver;c:\program files\Webroot\Washer\wrSSweep.sys [12/17/2007 7:10 PM 21832] — Other Services/Drivers In Memory — *NewlyCreated* - COMHOST [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc HPService REG_MULTI_SZ HPSLPSVC . Contents of the 'Scheduled Tasks' folder 2009-07-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 23:15] 2009-08-01 c:\windows\Tasks\User_Feed_Synchronization-{816CA817-9B7F-4154-83FF-62E8DB19959B}.job - c:\windows\system32\msfeedssync.exe [2008-05-03 07:33] . - - - - ORPHANS REMOVED - - - - HKCU-Run-Aim6 - (no file) . ——- Supplementary Scan ——- . uStart Page = hxxp://www.att.net/ mStart Page = hxxp://www.yahoo.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 Trusted Zone: turbotax.com Trusted Zone: walmart.com\photos . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\windows\System32\nvvsvc.exe c:\windows\System32\audiodg.exe c:\windows\System32\rundll32.exe c:\program files\Nero\Nero8\InCD\InCDsrv.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Common Files\microsoft shared\VS7DEBUG\mdm.exe c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe c:\windows\System32\WUDFHost.exe c:\windows\System32\drivers\XAudio.exe c:\windows\System32\wbem\unsecapp.exe c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe c:\windows\ehome\ehsched.exe c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe c:\windows\ehome\ehrecvr.exe . ************************************************************************** . Completion time: 2009-08-01 10:52 - machine was rebooted ComboFix-quarantined-files.txt 2009-08-01 15:52 Pre-Run: 403,856,224,256 bytes free Post-Run: 404,189,138,944 bytes free 357 — E O F — 2009-07-31 08:00
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report


Also, please advise how your computer is running now and if there are any outstanding issues
Here are my Malwarebytes log and Kaspersky report. The computer seems to be running just fine. I do have a question though that I would like an opinion on, I have Norton 360 currently but was thinking of switching to Kaspersky? Any thoughts? Thanks again for all the help. Malwarebytes' Anti-Malware 1.39 Database version: 2541 Windows 6.0.6001 Service Pack 1 8/2/2009 5:07:55 PM mbam-log-2009-08-02 (17-07-55).txt Scan type: Quick Scan Objects scanned: 95649 Time elapsed: 5 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Sunday, August 2, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Sunday, August 02, 2009 20:35:17 Records in database: 2575705 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ G:\ H:\ I:\ J:\ Z:\ Scan statistics: Files scanned: 227305 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 03:02:23 File name / Threat name / Threats count C:\Qoobox\Quarantine\C\Windows\System32\geyekrmfdvogod.dll.vir Infected: Backdoor.Win32.Small.wi 1 The selected area was scanned.
Hi,

How is the computer running now?

I have Norton 360 currently but was thinking of switching to Kaspersky

They are both good, it is personal preference and how it works with your system configuration that matters. If you are happen with Norton - keep it.
If you ask 10 people, you will get 10 different opinions. No no antivirus can find all the infections, that's why it's good to have a program like MalwareBytes on board and do an online scan with Kaspersky every once in a while. If I had to choose between the two, I'd pick kaspersky.

Please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


  • Hold down the Windows key and press R to open a run box
  • type the following text into the run box

    appwiz.cpl

  • This will open your Programs And Features
  • A list of installed programs will populate
  • Remove the following programs:

J2SE Runtime Environment 5.0 Update 2
LimeWire PRO 4.12.15


P2P - I see you have P2P software Limewire installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.


Next


Please post a fresh DDS log and advise how your computer is running and if you have any outstanding issues
No other problems, everything seems to be doing ok. DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 18:14:14.99 on Sun 08/02/2009 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3198.1887 [GMT -5:00] AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\hp\support\hpsysdrv.exe C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe C:\Windows\RtHDVCpl.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Windows\System32\rundll32.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\HP Connections\6811507\Program\HP Connections.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Webroot\Washer\WasherSvc.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\svchost.exe -k HPService C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\ehome\ehsched.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Windows\system32\taskeng.exe C:\Windows\ehome\ehRecvr.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe C:\hp\kbd\kbd.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\Joe and Mel\Desktop\dds.pif C:\Windows\servicing\TrustedInstaller.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.att.net/ mStart Page = hxxp://www.yahoo.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.6\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.6\CoIEPlg.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [KBD] c:\hp\kbd\KbdStub.EXE mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe" mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [ccApp] c:\program files\common files\symantec shared\ccApp.exe mRun: [osCheck] "c:\program files\norton 360\osCheck.exe" mRun: [hpqSRMon] c:\program files\hewlett-packard\digital imaging\bin\hpqSRMon.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpconn~1.lnk - c:\program files\hp connections\6811507\program\HP Connections.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\npjpi160_14.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll Trusted Zone: turbotax.com Trusted Zone: walmart.com\photos DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} - hxxps://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} - hxxp://www.linksysfix.com/netcheck/67/install/gtdownls.cab DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ============= SERVICES / DRIVERS =============== R0 AFS;AFS;c:\windows\system32\drivers\AFS.SYS [2007-5-1 79052] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-14 64160] R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\ipsdefs\20090730.002\IDSvix86.sys [2009-7-30 272432] R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1029456] R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-30 24652] R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2007-9-10 598856] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-7-14 101936] R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [2008-1-28 384896] R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2009-2-19 41008] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888] S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-6-17 12648] S3 wrssweep;Webroots Volume Access Driver;c:\program files\webroot\washer\wrSSweep.sys [2007-12-17 21832] S3 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] =============== Created Last 30 ================ 2009-08-02 17:53 –d—– c:\users\joeand~1\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2009-08-02 17:30 –d—– c:\programdata\NOS 2009-08-01 10:52 –dsh— C:\$RECYCLE.BIN 2009-08-01 10:35 219,648 a——- c:\windows\PEV.exe 2009-08-01 10:35 161,792 a——- c:\windows\SWREG.exe 2009-08-01 10:35 98,816 a——- c:\windows\sed.exe 2009-08-01 10:35 6,736 a——- c:\windows\system32\drivers\PROCEXP90.SYS 2009-08-01 10:35 –ds—- C:\ComboFix 2009-08-01 10:06 –d—– c:\program files\Trend Micro 2009-08-01 08:43 410,984 a——- c:\windows\system32\deploytk.dll 2009-08-01 08:43 –d—– c:\programdata\McAfee 2009-07-15 06:17 289,792 a——- c:\windows\system32\atmfd.dll 2009-07-15 06:17 156,672 a——- c:\windows\system32\t2embed.dll 2009-07-15 06:17 72,704 a——- c:\windows\system32\fontsub.dll 2009-07-15 06:17 10,240 a——- c:\windows\system32\dciman32.dll 2009-07-14 20:34 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-07-14 18:18 –d—– c:\users\joeand~1\appdata\roaming\Malwarebytes 2009-07-14 18:18 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-14 18:18 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-14 18:18 –d—– c:\programdata\Malwarebytes 2009-07-14 18:18 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-14 18:18 –d—– c:\progra~2\Malwarebytes 2009-07-13 18:39 –d—– c:\program files\Secunia 2009-07-13 18:07 -cd-h— c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-07-13 18:07 -cd-h— c:\progra~2\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-07-13 18:07 –d—– c:\programdata\Lavasoft 2009-07-13 18:07 –d—– c:\program files\Lavasoft 2009-07-13 17:19 –d—– c:\program files\CCleaner 2009-07-13 17:07 77,824 a——- c:\users\joe and mel\TaskManagerFix.exe 2009-07-08 19:47 –d—– c:\users\joeand~1\appdata\roaming\BSD 2009-07-08 19:47 1,511,936 a——- c:\windows\bsdsetup.dll 2009-07-07 16:31 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-07-07 16:31 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-07-07 16:31 –d—– c:\program files\iPod 2009-07-07 16:31 –d—– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-07-07 16:31 –d—– c:\program files\iTunes 2009-07-07 16:31 –d—– c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-07-07 16:29 –d—– c:\program files\Bonjour ==================== Find3M ==================== 2009-07-18 11:06 827,904 a——- c:\windows\system32\wininet.dll 2009-07-18 11:01 78,336 a——- c:\windows\system32\ieencode.dll 2009-07-18 04:46 26,624 a——- c:\windows\system32\ieUnatt.exe 2009-07-07 16:26 143,360 a——- c:\windows\inf\infstrng.dat 2009-07-07 16:26 86,016 a——- c:\windows\inf\infstor.dat 2009-07-07 16:26 51,200 a——- c:\windows\inf\infpub.dat 2009-06-17 07:20 12,648 a——- c:\windows\system32\drivers\psi_mf.sys 2009-06-05 11:42 2,060,288 a——- c:\windows\system32\usbaaplrc.dll 2009-06-05 11:42 39,424 a——- c:\windows\system32\drivers\usbaapl.sys 2008-07-14 10:55 308,600 ——– c:\programdata\NortonProtectionMemo.exe 2008-07-14 10:55 308,600 ——– c:\progra~2\NortonProtectionMemo.exe 2008-06-11 03:08 665,600 a——- c:\windows\inf\drvindex.dat 2008-05-29 09:41 658 ——– c:\users\joeand~1\appdata\roaming\wklnhst.dat 2008-05-03 16:19 174 a–sh— c:\program files\desktop.ini 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2002-07-31 19:55 108 —sh— c:\windows\WSYS049.SYS ============= FINISH: 18:14:46.60 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 3/11/2007 11:33:25 AM System Uptime: 8/2/2009 6:04:45 PM (0 hours ago) Motherboard: ASUSTek Computer INC. | | NARRA Processor: AMD Athlon™ 64 X2 Dual Core Processor 5200+ | Socket AM2 | 2600/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 458 GiB total, 361.891 GiB free. D: is FIXED (NTFS) - 8 GiB total, 0.875 GiB free. E: is CDROM () F: is FIXED (NTFS) - 466 GiB total, 368.074 GiB free. G: is Removable H: is Removable I: is Removable J: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: Photosmart C309a series Device ID: ROOT\MULTIFUNCTION\0000 Manufacturer: HP Name: Photosmart C309a series PNP Device ID: ROOT\MULTIFUNCTION\0000 Service: ==== System Restore Points =================== ==== Installed Programs ====================== 101 Law Forms 32 Bit HP CIO Components Installer AAC Decoder Acrobat.com Activation Assistant for the 2007 Microsoft Office suites ActiveCheck component for HP Active Support Library Ad-Aware Adobe AIR Adobe Flash Player 10 ActiveX Adobe Reader 9.1 AIM 6 AM-DeadLink 3.3 AnswerWorks 4.0 Runtime - English AnswerWorks 5.0 English Runtime AppCore Apple Mobile Device Support Apple Software Update ArcSoft Software Suite AutoUpdate Backup BlackBerry Desktop Software 4.7 BlackBerry Device Software v4.5.0 for the BlackBerry 8100 smartphone BlackBerry v4.2.1 for the 8100 Series Wireless Handheld Bonjour BufferChm C309a Camera Support Core Library Camera Window DS Camera Window DVC Camera Window MC Canon Camera Support Core Library Canon Camera Window DC_DV 5 for ZoomBrowser EX Canon Camera Window DS for ZoomBrowser EX Canon Camera Window MC 5 for ZoomBrowser EX Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon Utilities PhotoStitch 3.1 Canon ZoomBrowser EX ccCommon CCleaner (remove only) Citrix Presentation Server Client CoffeeCup Ad Producer CoffeeCup Direct FTP CoffeeCup Direct FTP 6.5.5 CoffeeCup Flash Blogger - Registered CoffeeCup Flash FireStarter CoffeeCup Flash Menu Builder CoffeeCup Flash Password Wizard CoffeeCup Flash Photo Gallery - Registered CoffeeCup Flash Website Font CoffeeCup Flash Website Font Pack CoffeeCup Flash Website Search - Registered CoffeeCup GIF Animator CoffeeCup Google SiteMapper CoffeeCup HTML Editor 2007 CoffeeCup HTML Editor 2008 CoffeeCup Image Mapper CoffeeCup Live Chat - Registered CoffeeCup LockBox CoffeeCup MP3 Rip & Burn CoffeeCup Password Wizard CoffeeCup Photo Gallery - Registered CoffeeCup PixConverter CoffeeCup RSS News Flash - Registered CoffeeCup StyleSheet Maker CoffeeCup Visual Site Designer Software CoffeeCup Web Calendar CoffeeCup Web Form Builder - Registered CoffeeCup Web JukeBox - Registered CoffeeCup Web Video Player - Registered CoffeeCup Web Video Recorder CoffeeCup WebCam CoffeeCup Website Color Schemer CoffeeCup Website Font Copy CustomerResearchQFolder dBpoweramp [Calculate Audio CRC] Codec dBpoweramp AAC Encoder dBpoweramp FLAC Codec dBpoweramp m4a Codec dBpoweramp m4a Utilities dBpoweramp Midi Decoder dBpoweramp Monkeys Audio Codec dBpoweramp Mp2 and BwfMp2 codec dBpoweramp mp3 (Fraunhofer IIS) Codec dBpoweramp Musepack Codec dBpoweramp Music Converter dBpoweramp Ogg Vorbis Codec dBpoweramp WavPack Codec dBpoweramp Windows Media Audio 10 Codec Destination Component DeviceDiscovery DeviceManagementQFolder DHTML Editing Component Digital Photo Navigator 1.5 DING! DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Version Checker DivX Web Player DocProc DocProcQFolder DYMO Label Software Easy Mail Plus for Windows 95/98/00/ME/NT/XP Enhanced Multimedia Keyboard Solution eSupportQFolder Everio MediaBrowser Fax ffdshow [rev 1299] [2007-06-17] Flock (Photobucket Edition) 0.7 Garmin Communicator Plugin Garmin WebUpdater GearDrvs Google Earth GPBaseService2 H.264 Decoder Hardware Diagnostic Tools HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Microsoft Visual Studio 2008 Standard Edition - ENU (KB952241) Hotfix for Microsoft Visual Studio 2008 Standard Edition - ENU (KB971091) HP Active Support Library HP Active Support Library 32 bit components HP Connections (remove only) HP Customer Experience Enhancements HP Customer Feedback HP Driver Diagnostics HP Easy Setup - Core HP Easy Setup - Frontend HP Imaging Device Functions 12.0 HP On-Screen Caps/Num/Scroll Lock Indicator HP Photosmart Essential HP Photosmart Essential 3.5 HP Picasso Media Center Add-In HP Smart Web Printing HP Total Care Advisor HP Update HPAsset component for HP Active Support Library HPPhotoGadget HPPhotoSmartDiscLabel_PaperLabel HPPhotoSmartDiscLabel_PrintOnDisc HPPhotoSmartDiscLabelContent1 hpphotosmartdisclabelplugin HPPhotosmartEssential HPProductAssistant HPSSupply iTunes Java™ 6 Update 14 Learning QuickBooks 2008 LightScribe 1.4.136.1 LiveUpdate (Symantec Corporation) Macromedia Shockwave Player Malwarebytes' Anti-Malware MarketResearch Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB929729) Microsoft .NET Framework 3.5 SP1 Microsoft Document Explorer 2008 Microsoft Expression Blend 2 Microsoft Expression Design 2 Microsoft Expression Encoder 2 Microsoft Expression Media 2 SP2 Microsoft Expression Studio 2 Microsoft Expression Web 2 Microsoft Expression Web 2 MUI (English) Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2) Microsoft Office Visual Web Developer 2007 Microsoft Office Visual Web Developer MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) Microsoft SQL Server 2005 Tools Express Edition Microsoft SQL Server Compact 3.5 Design Tools ENU Microsoft SQL Server Compact 3.5 ENU Microsoft SQL Server Database Publishing Wizard 1.2 Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual Studio 2008 Standard Edition - ENU Microsoft Visual Studio Web Authoring Component Microsoft Web Publishing Wizard 1.52 Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense Microsoft Windows SDK for Visual Studio 2008 Tools Microsoft Windows SDK for Visual Studio 2008 Win32 Tools Microsoft Works MKV Splitter MobileMe Control Panel MovieEdit Task MSDN Library for Visual Studio 2008 - ENU MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 Parser and SDK muvee autoProducer 5.0 My HP Games Nero 8 neroxml Network Norton 360 Norton 360 (Symantec Corporation) Norton 360 HTMLHelp Norton Confidential Core NVIDIA Drivers OBD-PC Link OCR Software by I.R.I.S. 12.0 Octoshape add-in for Adobe Flash Player Photo Album Downloader for Yahoo 2.6 Photo2DVD Studio 3 Build [removed] PhotoStitch PrintMaster Platinum 17 PS_AIO_05_C309_Software_Min Python 2.4.3 QuickBooks Customer Manager Version 2.5 QuickBooks Pro 2008 QuickBooks Product Listing Service Quicken 2007 Quicken Legal Business Pro 2006 Quicken WillMaker Plus 2006 Quicken WillMaker Plus 2008 QuickTime RAW Image Task 2.1 RealPlayer Realtek High Definition Audio Driver Rhapsody Rhapsody Player Engine Roxio Creator Tools Roxio Express Labeler 3 Scan Secunia PSI Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (KB954326) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office Word 2007 (KB969604) Shop for HP Supplies SmartWebPrinting Soft Data Fax Modem with SmartCP SolutionCenter SPBBC 32bit Status SupportSoft Assisted Service Symantec Real Time Storage Protection Component Symantec Technical Support Controls SymNet Toolbox TrayApp TurboTax 2008 TurboTax 2008 WinPerFedFormset TurboTax 2008 WinPerProgramHelp TurboTax 2008 WinPerReleaseEngine TurboTax 2008 WinPerTaxSupport TurboTax 2008 WinPerUserEducation TurboTax 2008 wmoiper TurboTax 2008 wrapper UnloadSupport Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Expression Web 2 (KB957827) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB969907) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (kb971933) VC Runtimes MSI VC80CRTRedist - 8.0.50727.762 VCRedistSetup Viewpoint Media Player Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WD Diagnostics WebReg Window Washer WinRAR archiver WinZip 11.1 Xvid 1.2.1 final uninstall Yahoo! Messenger Yahoo! Search Protection Yahoo! SiteBuilder Yahoo! Software Update Yahoo! Toolbar ==== End Of File ===========================
Hi,

You are clean,

just need to clean up our tools now

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI