This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unsure of infection and unable to remove bitdefender online

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all!
I am new here so I hope this is posted in the right forum. My laptop (using Windows Vista) performance is a bit slow so I am not sure whether or not there is an infection anywhere. It says that you can come here for a check up.
I also used the bit defender online scanner, but when it comes time for removal it will not uninstall. I get the error message
"Windows cannot find 'D:\Windows\bdoscandel.exe'. Make sure you typed the name correctly, and then try again." I tried several times to remove it but the same error keeps coming up. At present I have disabled it on IE7.
Any ideas what to do?
Thanks

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:50:03 AM, on 8/14/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
D:\Windows\system32\taskeng.exe
D:\Windows\system32\Dwm.exe
D:\Windows\Explorer.EXE
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Windows\System32\rundll32.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Windows\vsnp2uvc.exe
D:\Program Files\Windows Sidebar\sidebar.exe
D:\Windows\ehome\ehtray.exe
D:\Program Files\Windows Media Player\wmpnscfg.exe
D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
D:\Program Files\Windows Defender\MSASCui.exe
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Windows\ehome\ehmsas.exe
D:\Windows\system32\wuauclt.exe
D:\Program Files\Internet Explorer\ieuser.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - D:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - D:\Program Files\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {73F7F495-A325-4C52-BE48-5F97FA511E89} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - D:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVP] "D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [snp2uvc] D:\Windows\vsnp2uvc.exe
O4 - HKCU\..\Run: [Sidebar] D:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] D:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] D:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] D:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-492191835-2237326735-3823121520-1001\..\Run: [Sidebar] D:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Cece_Phoenix')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: Add to Banner Ad Blocker - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - (no file)
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - D:\Program Files\WOT\WOT.dll
O20 - AppInit_DLLs: D:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,D:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,D:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: 0301941240878354mcinstcleanup - - (no file)
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - D:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - D:\Windows\system32\nvvsvc.exe

–
End of file - 8061 bytes
Hi stargazercece,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Thank you for the welcome Tomk :thumbup:
Okay I've done everything. At present my laptop is running a bit faster. I still can't get rid of the bit defender scanner so I left it disabled again.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:26:54 PM, on 8/19/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
D:\Windows\system32\taskeng.exe
D:\Windows\system32\Dwm.exe
D:\Windows\System32\rundll32.exe
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
D:\Windows\explorer.exe
D:\Windows\ehome\ehtray.exe
D:\Program Files\Windows Sidebar\sidebar.exe
D:\Program Files\Windows Media Player\wmpnscfg.exe
D:\Windows\ehome\ehmsas.exe
D:\Program Files\Windows Defender\MSASCui.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - D:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - D:\Program Files\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {73F7F495-A325-4C52-BE48-5F97FA511E89} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - D:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVP] "D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [snp2uvc] D:\Windows\vsnp2uvc.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] D:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] D:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] D:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-492191835-2237326735-3823121520-1001\..\Run: [Sidebar] D:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Cece_Phoenix')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - (no file)
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - D:\Program Files\WOT\WOT.dll
O20 - AppInit_DLLs: D:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,D:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,D:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: 0301941240878354mcinstcleanup - - (no file)
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - D:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - D:\Windows\system32\nvvsvc.exe

–
End of file - 7442 bytes


Malwarebytes' Anti-Malware 1.40
Database version: 2658
Windows 6.0.6001 Service Pack 1

8/19/2009 8:01:38 PM
mbam-log-2009-08-19 (20-01-38).txt

Scan type: Quick Scan
Objects scanned: 88838
Time elapsed: 5 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
stargazercece,

I'm not really seeing anything. Let's get a deeper look.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Here ya go :) DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 22:38:24.96 on Fri 08/21/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_14 Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.1982.1028 [GMT -4:00] AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== D:\Windows\system32\wininit.exe D:\Windows\system32\lsm.exe D:\Windows\system32\svchost.exe -k DcomLaunch D:\Windows\system32\nvvsvc.exe D:\Windows\system32\svchost.exe -k rpcss D:\Windows\System32\svchost.exe -k secsvcs D:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted D:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted D:\Windows\system32\svchost.exe -k netsvcs D:\Windows\system32\SLsvc.exe D:\Windows\system32\svchost.exe -k LocalService D:\Windows\system32\rundll32.exe D:\Windows\system32\WLANExt.exe D:\Windows\System32\spoolsv.exe D:\Windows\system32\svchost.exe -k LocalServiceNoNetwork D:\Windows\system32\taskeng.exe D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe D:\Windows\system32\svchost.exe -k NetworkService D:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted D:\Windows\system32\svchost.exe -k imgsvc D:\Windows\System32\svchost.exe -k WerSvcGroup D:\Windows\system32\SearchIndexer.exe D:\Windows\system32\taskeng.exe D:\Windows\system32\Dwm.exe D:\Windows\Explorer.EXE D:\Program Files\Windows Defender\MSASCui.exe D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe D:\Windows\System32\rundll32.exe D:\Program Files\Java\jre6\bin\jusched.exe D:\Windows\vsnp2uvc.exe D:\Program Files\Windows Sidebar\sidebar.exe D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe D:\Program Files\Common Files\Real\Update_OB\realsched.exe D:\Program Files\Internet Explorer\ieuser.exe D:\Program Files\Skype\Phone\Skype.exe D:\Program Files\Skype\Plugin Manager\skypePM.exe D:\Program Files\Mozilla Firefox\firefox.exe D:\Windows\system32\DllHost.exe D:\Windows\system32\DllHost.exe D:\Users\Cece_Phoenix\Downloads\dds.scr D:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== mStart Page = about:blank BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - d:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - d:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - d:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - d:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - d:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - d:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll TB: {73F7F495-A325-4C52-BE48-5F97FA511E89} - No File TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - d:\program files\google\google toolbar\GoogleToolbar_32.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - d:\program files\wot\WOT.dll uRun: [Sidebar] d:\program files\windows sidebar\sidebar.exe /autoRun uRun: [swg] "d:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ehTray.exe] d:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] d:\program files\windows media player\WMPNSCFG.exe uRun: [Skype] "d:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [AVP] "d:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe" mRun: [NvCplDaemon] RUNDLL32.EXE d:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE d:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [TkBellExe] "d:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe" mRun: [snp2uvc] d:\windows\vsnp2uvc.exe mRunOnce: [Malwarebytes' Anti-Malware] d:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: d:\users\cece\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - d:\program files\microsoft office\office12\ONENOTEM.EXE mPolicies-explorer: NoAutorun = 1 (0x1) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport; to Microsoft Excel - d:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - {73F7F495-A325-4C52-BE48-5F97FA511E89} IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - d:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/E/3/9/E39C664F-A8E3-4F69-A109-1AE9849204EE/OGAControl.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - d:\program files\wot\WOT.dll Notify: klogon - d:\windows\system32\klogon.dll AppInit_DLLs: d:\progra~1\kasper~1\kasper~1\mzvkbd.dll,d:\progra~1\kasper~1\kasper~1\adialhk.dll,d:\progra~1\kasper~1\kasper~1\kloehk.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - d:\users\cece\appdata\roaming\mozilla\firefox\profiles\m8nai9rf.default\ FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 klbg;Kaspersky Lab Boot Guard Driver;d:\windows\system32\drivers\klbg.sys [2008-1-29 33808] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;d:\windows\system32\drivers\klim6.sys [2008-3-26 20496] R3 KLFLTDEV;Kaspersky Lab KLFltDev;d:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640] S2 0301941240878354mcinstcleanup;0301941240878354mcinstcleanup; [x] S3 getPlus® Helper;getPlus® Helper;d:\program files\nos\bin\getPlus_HelperSvc.exe [2009-4-20 66048] =============== Created Last 30 ================ 2009-08-21 21:01 56 a—h— d:\programdata\ezsidmv.dat 2009-08-21 21:01 56 a—h— d:\progra~2\ezsidmv.dat 2009-08-21 20:57 –d–r– d:\program files\Skype 2009-08-21 20:57 –d—– d:\programdata\Skype 2009-08-19 15:13 –d—– d:\users\cece\appdata\roaming\Malwarebytes 2009-08-19 15:13 38,160 a——- d:\windows\system32\drivers\mbamswissarmy.sys 2009-08-19 15:13 –d—– d:\programdata\Malwarebytes 2009-08-19 15:13 –d—– d:\progra~2\Malwarebytes 2009-08-19 15:12 19,096 a——- d:\windows\system32\drivers\mbam.sys 2009-08-19 15:12 –d—– d:\program files\Malwarebytes' Anti-Malware 2009-08-13 19:30 499,712 a——- d:\windows\system32\kerberos.dll 2009-08-13 19:29 213,504 a——- d:\windows\system32\msv1_0.dll 2009-08-13 19:29 175,104 a——- d:\windows\system32\wdigest.dll 2009-08-13 19:29 1,256,448 a——- d:\windows\system32\lsasrv.dll 2009-08-13 19:29 270,848 a——- d:\windows\system32\schannel.dll 2009-08-13 19:29 439,896 a——- d:\windows\system32\drivers\ksecdd.sys 2009-08-13 19:29 72,704 a——- d:\windows\system32\secur32.dll 2009-08-13 19:29 9,728 a——- d:\windows\system32\lsass.exe 2009-08-12 00:03 160,256 a——- d:\windows\system32\wkssvc.dll 2009-08-12 00:03 71,680 a——- d:\windows\system32\atl.dll 2009-08-12 00:02 2,066,432 a——- d:\windows\system32\mstscax.dll 2009-08-12 00:02 91,136 a——- d:\windows\system32\avifil32.dll 2009-08-12 00:02 313,344 a——- d:\windows\system32\wmpdxm.dll 2009-08-12 00:02 7,680 a——- d:\windows\system32\spwmp.dll 2009-08-12 00:02 4,096 a——- d:\windows\system32\msdxm.ocx 2009-08-12 00:02 4,096 a——- d:\windows\system32\dxmasf.dll 2009-08-12 00:02 8,147,456 a——- d:\windows\system32\wmploc.DLL 2009-08-12 00:02 43,520 a——- d:\windows\system32\msdxm.tlb 2009-08-12 00:02 18,432 a——- d:\windows\system32\amcompat.tlb 2009-08-11 23:57 –d—– d:\program files\WOT 2009-08-09 16:13 0 a—h— d:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf 2009-08-04 11:16 –d—– d:\program files\Trend Micro 2009-08-03 17:36 410,984 a——- d:\windows\system32\deploytk.dll 2009-07-29 17:30 –d—– d:\users\cece\appdata\roaming\AVG8 2009-07-28 13:57 827,904 a——- d:\windows\system32\wininet.dll 2009-07-28 13:57 389,632 a——- d:\windows\system32\html.iec 2009-07-28 13:57 26,624 a——- d:\windows\system32\ieUnatt.exe 2009-07-28 13:57 1,383,424 a——- d:\windows\system32\mshtml.tlb 2009-07-28 13:57 78,336 a——- d:\windows\system32\ieencode.dll ==================== Find3M ==================== 2009-08-21 11:52 56,800 a——- d:\programdata\nvModes.dat 2009-08-21 11:52 56,800 a——- d:\progra~2\nvModes.dat 2009-08-19 20:29 811,040 a–sh— d:\windows\system32\drivers\fidbox2.dat 2009-08-19 20:11 4,900 a–sh— d:\windows\system32\drivers\fidbox2.idx 2009-08-19 16:34 4,057,120 a–sh— d:\windows\system32\drivers\fidbox.dat 2009-08-19 16:34 33,824 a–sh— d:\windows\system32\drivers\fidbox.idx 2009-08-10 03:02 143,360 a——- d:\windows\inf\infstrng.dat 2009-08-10 03:02 51,200 a——- d:\windows\inf\infpub.dat 2009-08-10 03:02 86,016 a——- d:\windows\inf\infstor.dat 2009-07-31 23:33 382,072 a——- d:\windows\system32\perfh011.dat 2009-07-31 23:33 101,350 a——- d:\windows\system32\perfc011.dat 2009-06-24 17:30 249,856 ——– d:\windows\Setup1.exe 2009-06-24 17:30 73,216 a——- d:\windows\ST6UNST.EXE 2009-06-15 11:24 156,672 a——- d:\windows\system32\t2embed.dll 2009-06-15 11:20 72,704 a——- d:\windows\system32\fontsub.dll 2009-06-15 11:20 10,240 a——- d:\windows\system32\dciman32.dll 2009-06-15 08:52 289,792 a——- d:\windows\system32\atmfd.dll 2009-05-05 20:04 12,978 a——- d:\users\cece\appdata\roaming\nvModes.dat 2009-03-26 03:08 665,600 a——- d:\windows\inf\drvindex.dat 2009-03-26 03:02 139,030 a——- d:\windows\inf\perflib\0411\perfi.dat 2009-03-26 03:02 139,030 a——- d:\windows\inf\perflib\0411\perfh.dat 2009-03-26 03:02 30,674 a——- d:\windows\inf\perflib\0411\perfd.dat 2009-03-26 03:02 30,674 a——- d:\windows\inf\perflib\0411\perfc.dat 2009-03-25 13:45 174 a–sh— d:\program files\desktop.ini 2006-11-02 08:40 287,440 a——- d:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:40 287,440 a——- d:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:40 30,674 a——- d:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:40 30,674 a——- d:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- d:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- d:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- d:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- d:\windows\inf\perflib\0000\perfc.dat 2009-05-12 04:47 16,384 a–sh— d:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat 2009-05-12 04:47 32,768 a–sh— d:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 2009-05-12 04:47 16,384 a–sh— d:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat 2006-11-22 10:58 8,192 a–sh— d:\windows\users\default\NTUSER.DAT ============= FINISH: 22:40:28.60 ===============

Attachments:

It is listed as an add-on in my internet explorer. Every time I try to remove it the error message appears. So I have left it disabled on IE.
stargazercece,

Well let's see if we can clean that up.

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{85d1f590-48f4-11d9-9669-0800200c9a66}]
    
    :Files
    %windir%\bdoscandel.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
I have the OTM log results but the kaspersky scanner will not scan because I have kaspersky internet security already installed on the computer. Do you want me to disable it, run the online scanner and post the log results in my next response? All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== REGISTRY ========== Registry delete failed. HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{85d1f590-48f4-11d9-9669-0800200c9a66}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85d1f590-48f4-11d9-9669-0800200c9a66}\ not found. ========== FILES ========== Folder D:\WindowsD:\Windows\bdoscandel.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Cece File delete failed. D:\Users\Cece\AppData\Local\Temp\Cece.bmp scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Temp\jusched.log scheduled to be deleted on reboot. ->Temp folder emptied: 32714 bytes File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VBPX41RY\desktop.ini scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHAK83RE\desktop.ini scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHAK83RE\favicon[3].ico scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHAK83RE\favicon[4].ico scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FU9ZYFG0\desktop.ini scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FU9ZYFG0\favicon[1].ico scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FU9ZYFG0\osd3[1].xml scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\574MUKBG\desktop.ini scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 318850 bytes ->Java cache emptied: 0 bytes File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\OfflineCache\index.sqlite scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\04A79A4Bd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\076FE9CBd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\08E59609d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\10E48E08d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\14E08A0Cd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\153D7213d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\2067DCC3d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\2118A00Cd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\2440CAE4d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\256C286Ad01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\26132314d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\26774406d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\291EFB23d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\29FCB710d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\2EF19965d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\3090F782d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\30A7AE4Bd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\34F1632Cd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\3AC1587Cd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\43B9C3D5d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\4601A8A5d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\46425D7Ad01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\46DDD831d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\5144CFA8d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\5346CDAAd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\5540CBACd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\5D523041d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\61019DA5d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\622156BCd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\64D96346d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\674C592Ed01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\723AD904d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\7248C73Cd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\746C722Cd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\8028E431d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\88AF2D38d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\9358C232d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\97B603B6d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\9A5503AFd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\A0A1D19Cd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\A80E7E4Cd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\A89F4DBCd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\A91647B2d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\D55C29F8d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\D5C6C26Dd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\DB4C0588d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\DE09C3F5d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\DEAA17A3d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\E4E12AD5d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\EB5417F0d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\F1C56F29d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\F3876D6Bd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\F5C16B2Dd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\F6298D07d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\F6E3FFDAd01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\FB5BCE70d01 scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\XPC.mfl scheduled to be deleted on reboot. File delete failed. D:\Users\Cece\AppData\Local\Mozilla\Firefox\Profiles\m8nai9rf.default\XUL.mfl scheduled to be deleted on reboot. ->FireFox cache emptied: 34120509 bytes User: Cece_Phoenix ->Temp folder emptied: 71405 bytes ->Temporary Internet Files folder emptied: 15742509 bytes ->Java cache emptied: 13425503 bytes ->FireFox cache emptied: 41037922 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 99.90 mb OTM by OldTimer - Version 3.0.0.6 log created on 08292009_115109
stargazercece,

Let's use a different one.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Sorry I took so long to reply. Here is everything. ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internet# version=6 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6050 # api_version=3.0.2 # EOSSerial=7a69318ed770754e963ea0f9f941a886 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-09-04 02:52:54 # local_time=2009-09-03 10:52:54 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=6.0.6001 NT Service Pack 1 # compatibility_mode=1281 61 100 99 121034534201286 # compatibility_mode=5889 61 66 100 513044556655508 # scanned=145789 # found=0 # cleaned=0 # scan_time=5501
Here is the new DDS log. Everything is running fine so far. The bit defender online scanner still shows on internet explorer and can't be uninstalled, but since it isn't causing problems I guess its fine? DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 19:14:24.01 on Mon 09/07/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_14 Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.1982.1055 [GMT -4:00] AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== D:\Windows\system32\wininit.exe D:\Windows\system32\lsm.exe D:\Windows\system32\svchost.exe -k DcomLaunch D:\Windows\system32\nvvsvc.exe D:\Windows\system32\svchost.exe -k rpcss D:\Windows\System32\svchost.exe -k secsvcs D:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted D:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted D:\Windows\system32\svchost.exe -k netsvcs D:\Windows\system32\SLsvc.exe D:\Windows\system32\svchost.exe -k LocalService D:\Windows\system32\rundll32.exe D:\Windows\system32\WLANExt.exe D:\Windows\System32\spoolsv.exe D:\Windows\system32\svchost.exe -k LocalServiceNoNetwork D:\Windows\system32\taskeng.exe D:\Windows\system32\Dwm.exe D:\Windows\system32\taskeng.exe D:\Windows\Explorer.EXE D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe D:\Windows\system32\svchost.exe -k NetworkService D:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted D:\Windows\system32\svchost.exe -k imgsvc D:\Windows\System32\svchost.exe -k WerSvcGroup D:\Windows\system32\SearchIndexer.exe D:\Program Files\Windows Defender\MSASCui.exe D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe D:\Windows\System32\rundll32.exe D:\Program Files\Java\jre6\bin\jusched.exe D:\Windows\vsnp2uvc.exe D:\Program Files\Windows Sidebar\sidebar.exe D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe D:\Program Files\Internet Explorer\ieuser.exe D:\Program Files\Microsoft Office\Office12\EXCEL.EXE D:\Program Files\Mozilla Firefox\firefox.exe D:\Program Files\Common Files\Real\Update_OB\realsched.exe D:\Windows\system32\wbem\wmiprvse.exe D:\Windows\system32\DllHost.exe D:\Windows\system32\DllHost.exe D:\Users\Cece_Phoenix\Downloads\dds.scr ============== Pseudo HJT Report =============== mStart Page = about:blank BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - d:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - d:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - d:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - d:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - d:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - d:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll TB: {73F7F495-A325-4C52-BE48-5F97FA511E89} - No File TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - d:\program files\google\google toolbar\GoogleToolbar_32.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - d:\program files\wot\WOT.dll uRun: [Sidebar] d:\program files\windows sidebar\sidebar.exe /autoRun uRun: [swg] "d:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ehTray.exe] d:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] d:\program files\windows media player\WMPNSCFG.exe uRun: [Skype] "d:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [AVP] "d:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe" mRun: [NvCplDaemon] RUNDLL32.EXE d:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE d:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [TkBellExe] "d:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe" mRun: [snp2uvc] d:\windows\vsnp2uvc.exe mRunOnce: [Malwarebytes' Anti-Malware] d:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: d:\users\cece\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - d:\program files\microsoft office\office12\ONENOTEM.EXE mPolicies-explorer: NoAutorun = 1 (0x1) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - {73F7F495-A325-4C52-BE48-5F97FA511E89} IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - d:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/E/3/9/E39C664F-A8E3-4F69-A109-1AE9849204EE/OGAControl.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - d:\program files\wot\WOT.dll Notify: klogon - d:\windows\system32\klogon.dll AppInit_DLLs: d:\progra~1\kasper~1\kasper~1\mzvkbd.dll,d:\progra~1\kasper~1\kasper~1\adialhk.dll,d:\progra~1\kasper~1\kasper~1\kloehk.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 klbg;Kaspersky Lab Boot Guard Driver;d:\windows\system32\drivers\klbg.sys [2008-1-29 33808] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;d:\windows\system32\drivers\klim6.sys [2008-3-26 20496] R3 KLFLTDEV;Kaspersky Lab KLFltDev;d:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640] S2 0301941240878354mcinstcleanup;0301941240878354mcinstcleanup; [x] S3 getPlus® Helper;getPlus® Helper;d:\program files\nos\bin\getPlus_HelperSvc.exe [2009-4-20 66048] =============== Created Last 30 ================ 2009-09-03 00:57 28,672 a——- d:\windows\system32\Apphlpdm.dll 2009-09-03 00:56 4,240,384 a——- d:\windows\system32\GameUXLegacyGDFs.dll 2009-08-29 11:51 –d—– D:\_OTM 2009-08-28 00:43 –d—– d:\programdata\Office Genuine Advantage 2009-08-27 12:17 2,048 a——- d:\windows\system32\tzres.dll 2009-08-21 21:01 56 a—h— d:\programdata\ezsidmv.dat 2009-08-21 21:01 56 a—h— d:\progra~2\ezsidmv.dat 2009-08-21 20:57 –d–r– d:\program files\Skype 2009-08-21 20:57 –d—– d:\programdata\Skype 2009-08-19 15:13 –d—– d:\users\cece\appdata\roaming\Malwarebytes 2009-08-19 15:13 38,160 a——- d:\windows\system32\drivers\mbamswissarmy.sys 2009-08-19 15:13 –d—– d:\programdata\Malwarebytes 2009-08-19 15:13 –d—– d:\progra~2\Malwarebytes 2009-08-19 15:12 19,096 a——- d:\windows\system32\drivers\mbam.sys 2009-08-19 15:12 –d—– d:\program files\Malwarebytes' Anti-Malware 2009-08-13 19:30 499,712 a——- d:\windows\system32\kerberos.dll 2009-08-13 19:29 213,504 a——- d:\windows\system32\msv1_0.dll 2009-08-13 19:29 175,104 a——- d:\windows\system32\wdigest.dll 2009-08-13 19:29 1,256,448 a——- d:\windows\system32\lsasrv.dll 2009-08-13 19:29 270,848 a——- d:\windows\system32\schannel.dll 2009-08-13 19:29 439,896 a——- d:\windows\system32\drivers\ksecdd.sys 2009-08-13 19:29 72,704 a——- d:\windows\system32\secur32.dll 2009-08-13 19:29 9,728 a——- d:\windows\system32\lsass.exe 2009-08-12 00:03 160,256 a——- d:\windows\system32\wkssvc.dll 2009-08-12 00:03 71,680 a——- d:\windows\system32\atl.dll 2009-08-12 00:02 2,066,432 a——- d:\windows\system32\mstscax.dll 2009-08-12 00:02 91,136 a——- d:\windows\system32\avifil32.dll 2009-08-12 00:02 313,344 a——- d:\windows\system32\wmpdxm.dll 2009-08-12 00:02 7,680 a——- d:\windows\system32\spwmp.dll 2009-08-12 00:02 4,096 a——- d:\windows\system32\msdxm.ocx 2009-08-12 00:02 4,096 a——- d:\windows\system32\dxmasf.dll 2009-08-12 00:02 8,147,456 a——- d:\windows\system32\wmploc.DLL 2009-08-12 00:02 43,520 a——- d:\windows\system32\msdxm.tlb 2009-08-12 00:02 18,432 a——- d:\windows\system32\amcompat.tlb 2009-08-11 23:57 –d—– d:\program files\WOT 2009-08-09 16:13 0 a—h— d:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf ==================== Find3M ==================== 2009-09-07 11:56 56,800 a——- d:\programdata\nvModes.dat 2009-09-07 11:56 56,800 a——- d:\progra~2\nvModes.dat 2009-09-03 06:32 4,956 a–sh— d:\windows\system32\drivers\fidbox2.idx 2009-09-03 06:32 4,100,128 a–sh— d:\windows\system32\drivers\fidbox.dat 2009-09-03 06:32 827,424 a–sh— d:\windows\system32\drivers\fidbox2.dat 2009-09-03 06:32 34,160 a–sh— d:\windows\system32\drivers\fidbox.idx 2009-08-28 08:39 173,056 a——- d:\windows\apppatch\AcXtrnal.dll 2009-08-28 08:38 2,153,984 a——- d:\windows\apppatch\AcGenral.dll 2009-08-28 08:38 541,696 a——- d:\windows\apppatch\AcLayers.dll 2009-08-28 08:38 459,776 a——- d:\windows\apppatch\AcSpecfc.dll 2009-08-23 21:56 382,072 a——- d:\windows\system32\perfh011.dat 2009-08-23 21:56 101,350 a——- d:\windows\system32\perfc011.dat 2009-08-10 03:02 143,360 a——- d:\windows\inf\infstrng.dat 2009-08-10 03:02 51,200 a——- d:\windows\inf\infpub.dat 2009-08-10 03:02 86,016 a——- d:\windows\inf\infstor.dat 2009-08-03 17:36 410,984 a——- d:\windows\system32\deploytk.dll 2009-08-03 15:07 403,816 a——- d:\windows\system32\OGACheckControl.dll 2009-08-03 15:07 322,928 a——- d:\windows\system32\OGAAddin.dll 2009-08-03 15:07 230,768 a——- d:\windows\system32\OGAEXEC.exe 2009-07-18 12:06 827,904 a——- d:\windows\system32\wininet.dll 2009-07-18 12:01 78,336 a——- d:\windows\system32\ieencode.dll 2009-07-18 05:46 26,624 a——- d:\windows\system32\ieUnatt.exe 2009-06-24 17:30 249,856 ——– d:\windows\Setup1.exe 2009-06-24 17:30 73,216 a——- d:\windows\ST6UNST.EXE 2009-06-15 11:24 156,672 a——- d:\windows\system32\t2embed.dll 2009-06-15 11:20 72,704 a——- d:\windows\system32\fontsub.dll 2009-06-15 11:20 10,240 a——- d:\windows\system32\dciman32.dll 2009-06-15 08:52 289,792 a——- d:\windows\system32\atmfd.dll 2009-05-05 20:04 12,978 a——- d:\users\cece\appdata\roaming\nvModes.dat 2009-03-26 03:08 665,600 a——- d:\windows\inf\drvindex.dat 2009-03-26 03:02 139,030 a——- d:\windows\inf\perflib\0411\perfi.dat 2009-03-26 03:02 139,030 a——- d:\windows\inf\perflib\0411\perfh.dat 2009-03-26 03:02 30,674 a——- d:\windows\inf\perflib\0411\perfd.dat 2009-03-26 03:02 30,674 a——- d:\windows\inf\perflib\0411\perfc.dat 2009-03-25 13:45 174 a–sh— d:\program files\desktop.ini 2006-11-02 08:40 287,440 a——- d:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:40 287,440 a——- d:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:40 30,674 a——- d:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:40 30,674 a——- d:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- d:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- d:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- d:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- d:\windows\inf\perflib\0000\perfc.dat 2009-05-12 04:47 16,384 a–sh— d:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat 2009-05-12 04:47 32,768 a–sh— d:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 2009-05-12 04:47 16,384 a–sh— d:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat 2006-11-22 10:58 8,192 a–sh— d:\windows\users\default\NTUSER.DAT ============= FINISH: 19:15:25.55 ===============

Attachments:

stargazercece,

Let's try OTM again.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    bdoscandel.exe
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{85d1f590-48f4-11d9-9669-0800200c9a66}]
    
    :Files
    D:\Windows\bdoscandel.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Here ya go…and i think its actually gone this time. I don't see it listed in IE as an add on anymore. All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! No active process named bdoscandel.exe was found! ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{85d1f590-48f4-11d9-9669-0800200c9a66}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85d1f590-48f4-11d9-9669-0800200c9a66}\ not found. ========== FILES ========== File/Folder D:\Windows\bdoscandel.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Cece ->Temp folder emptied: 438015 bytes ->Temporary Internet Files folder emptied: 323832 bytes ->Java cache emptied: 25493434 bytes ->FireFox cache emptied: 34120509 bytes User: Cece_Phoenix ->Temp folder emptied: 11246856 bytes ->Temporary Internet Files folder emptied: 54721572 bytes ->Java cache emptied: 13553650 bytes ->FireFox cache emptied: 23786183 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 96238 bytes RecycleBin emptied: 335554 bytes Total Files Cleaned = 156.51 mb OTM by OldTimer - Version 3.0.0.6 log created on 09102009_201209

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI