This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Slow startup

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My boot is very slow, and various drivers/services/programs take a long time to load, sometimes not starting at all. I've tried Norton AV, Windows Defender, even Reg Cure and CCleaner. I would appreciate any help from anyone in deciphering the HijackThis log for possible causes. Thanks in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:54:39 AM, on 8/15/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\schtasks.exe
C:\Windows\system32\jusched.exe
C:\hp\kbd\kbd.exe
C:\Users\Ron\Downloads\HiJackThis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL
O2 - BHO: TTB000000 - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: CouponBar - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - (no file)
O3 - Toolbar: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\System32\nvSCPAPISvr.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 6746 bytes
Hi easyriter,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hello,

I ran the TFC, and below are the Malwarebytes and HJT reports. At this time my computer still takes three to four minutes from power-up to actually being able to use my desktop. I'm thinking Malware and temp internet files aren't behind my problems, but I really appreciate your suggestions.

Thanks,

Ron

Malwarebytes' Anti-Malware 1.40
Database version: 2659
Windows 6.0.6002 Service Pack 2

8/19/2009 6:57:06 PM
mbam-log-2009-08-19 (18-57-06).txt

Scan type: Quick Scan
Objects scanned: 109232
Time elapsed: 4 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:58:31 PM, on 8/19/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\schtasks.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\jusched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\hp\kbd\kbd.exe
C:\Users\Ron\Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL
O2 - BHO: TTB000000 - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: CouponBar - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - (no file)
O3 - Toolbar: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O13 - Gopher Prefix:
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\System32\nvSCPAPISvr.exe

–
End of file - 5919 bytes
easyriter,

Let's clean up some orphans and then get a deeper scan.
  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      O2 - BHO: (no name) - AutorunsDisabled - (no file)
      O2 - BHO: TTB000000 - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - (no file)
      O3 - Toolbar: CouponBar - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - (no file)
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
TomK, The orphans are gone. And here are the results of the Kaspersky scan: KASPERSKY ONLINE SCANNER 7.0: scan report Friday, August 21, 2009 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, August 21, 2009 00:51:11 Records in database: 2667526 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ G:\ Scan statistics: Objects scanned: 169327 Threats found: 2 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 03:50:40 File name / Threat / Threats count C:\Users\kellie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FJJJ5FG1\fi36le[1].pdf Infected: Exploit.Win32.Pidief.bjx 1 E:\autorun.inf Infected: Trojan.Win32.VB.aqt 1 Selected area has been scanned. easyriter
easyriter,

You apparently have an infected thumb drive.

Please download Flash Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the
    utility to clean up those drives as well. Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that is plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

Then, Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Now let me know how things are running.
TomK, I downloaded the Flash Disinfector, but it won't run. I unblocked it, turned off my auto-protection (NAV09), and tried running it as administrator, but still no go. I also downloaded the ATF, but I haven't run it yet. Now what? Thanks, easyriter
easyriter,

Let's do this:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
TomK,

Here's the CF log. I see it got rid of "E:\Autorun.inf" problem. Also, I (and apparently others) have been having problems with "Symantec Service Framework" (NAV09) slowing down startup. I was instructed by the website to load an updated version. I did so, and things are running better. I ran a scan, and deleted a detected cookie. Could that be "C:\Users\kellie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FJJJ5FG1\fi36le[1].pdf Infected: Exploit.Win32.Pidief.bjx 1" found by the Kaspersky scan? Anyway, when I tried to follow the path, it ended at "C:\Users\kellie\AppData\Local\Microsoft\Windows". There were no Temporary Internet Files shown, or hidden.

Thanks,

easyriter

ComboFix 09-08-24.05 - Ron 08/24/2009 20:10.1.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.2229 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-26859080-1141177850-1269440115-1004
c:\$recycle.bin\S-1-5-21-26859080-1141177850-1269440115-1005
c:\$recycle.bin\S-1-5-21-26859080-1141177850-1269440115-1008
c:\$recycle.bin\S-1-5-21-26859080-1141177850-1269440115-1009
c:\$recycle.bin\S-1-5-21-26859080-1141177850-1269440115-500
c:\$recycle.bin\S-1-5-21-3448895173-3614957218-1390422072-500
c:\$recycle.bin\S-1-5-21-909821549-444324555-4134441507-1000
c:\windows\desktop
c:\windows\desktop\Play Rogue Squadron.lnk
c:\windows\Installer\260737.msi
c:\windows\Installer\31c832.msi
E:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-07-25 to 2009-08-25 )))))))))))))))))))))))))))))))
.

2009-08-25 00:16 . 2009-08-25 00:16 ——– d—–w- c:\users\Ron\AppData\Local\temp
2009-08-25 00:16 . 2009-08-25 00:16 ——– d—–w- c:\users\Stacie\AppData\Local\temp
2009-08-24 23:52 . 2009-08-24 23:41 259368 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090824.024\ECMSVR32.DLL
2009-08-24 23:52 . 2009-07-12 05:15 533880 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\Scxpx86.dll
2009-08-24 23:52 . 2009-07-12 05:15 451960 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSxpx86.dll
2009-08-24 23:52 . 2009-07-12 05:15 397360 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSviA64.sys
2009-08-24 23:52 . 2009-07-12 05:15 293424 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSvix86.sys
2009-08-24 23:52 . 2009-07-12 05:15 276344 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSXpx86.sys
2009-08-24 23:52 . 2009-07-12 05:15 533880 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-08-24 23:52 . 2009-07-12 05:15 451960 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-08-24 23:52 . 2009-07-12 05:15 397360 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-08-24 23:52 . 2009-07-12 05:15 293424 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-08-24 23:52 . 2009-07-12 05:15 276344 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-08-24 23:41 . 2009-08-24 23:41 25136 —-a-r- c:\windows\system32\drivers\SymIMV.sys
2009-08-24 23:41 . 2009-08-24 23:41 ——– d—–w- c:\windows\LastGood
2009-08-24 23:41 . 2009-08-24 23:41 124464 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-08-24 23:41 . 2009-08-24 23:41 136840 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-08-24 23:41 . 2009-08-24 23:41 1290584 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-08-24 23:41 . 2009-08-24 23:41 800112 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-08-24 23:41 . 2009-08-24 23:41 2393648 ——w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20081202.022\CCERASER.DLL
2009-08-24 23:41 . 2009-08-24 23:41 ——– d—–w- c:\windows\system32\drivers\NAV
2009-08-24 23:41 . 2009-08-24 23:41 ——– d—–w- c:\program files\Norton AntiVirus
2009-08-24 23:40 . 2009-08-24 23:40 ——– d—–w- c:\program files\NortonInstaller
2009-08-24 08:00 . 2009-08-24 08:00 87888 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090824.024\NAVENG.SYS
2009-08-24 08:00 . 2009-08-24 08:00 875728 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090824.024\NAVEX15.SYS
2009-08-24 08:00 . 2009-08-24 08:00 371248 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090824.024\EECTRL.SYS
2009-08-24 08:00 . 2009-08-24 08:00 2414128 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090824.024\CCERASER.DLL
2009-08-24 08:00 . 2009-08-24 08:00 177520 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090824.024\NAVENG32.DLL
2009-08-24 08:00 . 2009-08-24 08:00 1181040 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090824.024\NAVEX32A.DLL
2009-08-24 08:00 . 2009-08-24 08:00 101936 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090824.024\ERASER.SYS
2009-08-22 21:40 . 2009-08-22 21:40 ——– d—–w- c:\users\Ron\AppData\Local\2DBoy
2009-08-22 21:40 . 2009-08-22 21:40 ——– d—–w- c:\programdata\2DBoy
2009-08-22 21:38 . 2009-08-22 21:38 ——– d—–w- c:\program files\Brighter Minds Media
2009-08-21 01:04 . 2009-08-21 01:04 ——– d—–w- c:\users\Ron\AppData\Roaming\CyberLink
2009-08-20 23:58 . 2009-08-20 23:58 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-19 22:51 . 2009-08-19 22:51 ——– d—–w- c:\users\Ron\AppData\Roaming\Malwarebytes
2009-08-19 22:51 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-19 22:51 . 2009-08-19 22:51 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 22:51 . 2009-08-19 22:51 ——– d—–w- c:\programdata\Malwarebytes
2009-08-19 22:51 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 00:28 . 2009-06-15 14:53 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-08-15 00:28 . 2009-06-15 14:52 499712 —-a-w- c:\windows\system32\kerberos.dll
2009-08-15 00:28 . 2009-06-15 14:54 175104 —-a-w- c:\windows\system32\wdigest.dll
2009-08-15 00:28 . 2009-06-15 23:15 439864 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-15 00:28 . 2009-06-15 14:53 72704 —-a-w- c:\windows\system32\secur32.dll
2009-08-15 00:28 . 2009-06-15 14:53 270848 —-a-w- c:\windows\system32\schannel.dll
2009-08-15 00:28 . 2009-06-15 14:52 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2009-08-15 00:28 . 2009-06-15 12:48 9728 —-a-w- c:\windows\system32\lsass.exe
2009-08-12 16:43 . 2009-07-17 13:54 71680 —-a-w- c:\windows\system32\atl.dll
2009-08-12 16:43 . 2009-06-10 11:42 160256 —-a-w- c:\windows\system32\wkssvc.dll
2009-08-12 16:43 . 2009-06-04 12:07 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-08-12 16:43 . 2009-06-10 11:38 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-08-12 16:43 . 2009-07-15 12:39 313344 —-a-w- c:\windows\system32\wmpdxm.dll
2009-08-12 16:43 . 2009-07-15 12:39 4096 —-a-w- c:\windows\system32\dxmasf.dll
2009-08-12 16:43 . 2009-07-15 12:40 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-08-12 16:43 . 2009-07-15 12:39 7680 —-a-w- c:\windows\system32\spwmp.dll
2009-08-09 19:34 . 2009-08-09 19:46 ——– d—–w- c:\program files\Fox
2009-08-09 13:06 . 2009-08-09 13:06 ——– d—–w- c:\users\Ron\AppData\Local\Help
2009-08-01 03:07 . 2009-08-01 03:07 9922 —-a-w- c:\windows\system32\cc_20090731_230743.reg

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-24 23:47 . 2007-12-06 16:16 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-24 23:41 . 2009-08-24 23:41 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-08-24 23:41 . 2009-08-24 23:41 10635 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-08-24 23:41 . 2009-02-01 15:49 ——– d—–w- c:\program files\Symantec
2009-08-24 23:41 . 2008-09-14 17:35 ——– d—–w- c:\programdata\Norton
2009-08-24 23:38 . 2009-07-08 13:37 96961 —-a-w- c:\programdata\nvModes.dat
2009-08-24 23:38 . 2009-05-20 01:18 ——– d—–w- c:\programdata\NVIDIA
2009-08-24 00:33 . 2009-05-22 20:34 ——– d—–w- c:\users\Kellie\AppData\Roaming\gtk-2.0
2009-08-22 20:46 . 2009-02-05 21:32 ——– d—–w- c:\programdata\ATTToolbar
2009-08-22 20:35 . 2008-12-29 15:53 ——– d—–w- c:\program files\MunSoft
2009-08-20 23:58 . 2007-12-06 16:06 ——– d—–w- c:\program files\Java
2009-08-16 14:26 . 2008-08-06 00:34 21840 —-atw- c:\windows\system32\SIntfNT.dll
2009-08-16 14:26 . 2008-08-06 00:34 17212 —-atw- c:\windows\system32\SIntf32.dll
2009-08-16 14:26 . 2008-08-06 00:34 12067 —-atw- c:\windows\system32\SIntf16.dll
2009-08-15 00:57 . 2008-09-14 16:24 ——– d—–w- c:\programdata\Google Updater
2009-08-14 01:00 . 2008-05-19 03:14 ——– d—–w- c:\program files\LucasArts
2009-08-14 00:59 . 2008-12-28 00:02 ——– d—–w- c:\program files\EA Games
2009-08-14 00:57 . 2009-07-19 16:47 ——– d—–w- c:\program files\Sierra Entertainment
2009-08-14 00:57 . 2008-05-21 02:44 ——– d—–w- c:\program files\Sierra
2009-08-12 21:00 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-08-10 23:10 . 2008-10-04 03:03 ——– d—–w- c:\program files\Creative
2009-08-09 19:46 . 2007-12-06 15:52 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-09 03:53 . 2007-12-06 16:04 ——– d—a-w- c:\program files\Common Files\LightScribe
2009-08-01 02:38 . 2008-09-14 17:35 ——– d—–w- c:\programdata\NortonInstaller
2009-07-31 22:46 . 2008-09-27 16:13 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-27 00:00 . 2009-06-06 02:09 ——– d—–w- c:\programdata\Media Center Programs
2009-07-25 13:33 . 2009-07-25 13:33 713992 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-07-21 21:52 . 2009-07-29 14:27 915456 —-a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 14:27 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 14:27 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 14:27 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 00:31 . 2009-05-29 02:06 ——– d—–w- c:\program files\RivaTuner v2.24
2009-07-17 00:31 . 2007-12-06 16:07 ——– d—–w- c:\program files\Microsoft Works
2009-07-12 15:46 . 2009-06-28 23:55 138608 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-12 15:46 . 2009-06-28 23:55 189800 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-07-09 03:11 . 2008-06-21 16:59 ——– d—–w- c:\users\Ron\AppData\Roaming\Apple Computer
2009-07-08 13:27 . 2008-05-18 00:12 2032 —-a-w- c:\users\Ron\AppData\Local\d3d9caps.dat
2009-07-08 02:06 . 2007-12-06 16:12 ——– d—–w- c:\programdata\WildTangent
2009-07-08 02:03 . 2008-05-18 19:24 1700784 —-a-w- c:\programdata\WildTangent\My HP Game Console\Downloads\en-us\Installers\SetupGamesClient.exe
2009-07-05 16:08 . 2009-07-05 16:07 ——– d—–w- c:\program files\AGEIA Technologies
2009-07-05 16:07 . 2009-05-20 01:15 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-07-01 13:05 . 2008-10-04 03:06 ——– d—–w- c:\programdata\Creative
2009-07-01 03:25 . 2009-06-28 23:54 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-07-01 03:13 . 2008-12-25 21:14 22328 —-a-w- c:\users\Ron\AppData\Roaming\PnkBstrK.sys
2009-07-01 03:13 . 2008-12-25 21:14 22328 —-a-w- c:\users\Ron\AppData\Roaming\PnkBstrK.sys
2009-06-30 01:06 . 2009-06-30 01:06 413696 —-a-w- c:\windows\system32\wrap_oal.dll
2009-06-30 01:06 . 2009-06-30 01:06 110592 —-a-w- c:\windows\system32\OpenAL32.dll
2009-06-28 23:41 . 2009-06-28 23:41 ——– d—–w- c:\program files\Activision
2009-06-15 14:53 . 2009-07-15 14:32 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-06-15 14:52 . 2009-07-15 14:32 23552 —-a-w- c:\windows\system32\lpk.dll
2009-06-15 14:52 . 2009-07-15 14:32 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-06-15 14:51 . 2009-07-15 14:32 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:42 . 2009-07-15 14:32 289792 —-a-w- c:\windows\system32\atmfd.dll
2009-06-10 12:35 . 2009-06-10 12:35 1194528 —-a-w- c:\windows\system32\nvcplui.exe
2009-06-10 12:35 . 2009-06-10 12:35 1296928 —-a-w- c:\windows\system32\nvsvs.dll
2009-06-10 12:34 . 2009-06-10 12:34 3123744 —-a-w- c:\windows\system32\nvwss.dll
2009-06-10 12:34 . 2009-06-10 12:34 4045344 —-a-w- c:\windows\system32\nvvitvs.dll
2009-06-10 12:34 . 2009-06-10 12:34 4028960 —-a-w- c:\windows\system32\nvdisps.dll
2009-06-10 12:34 . 2009-06-10 12:34 3516960 —-a-w- c:\windows\system32\nvgames.dll
2009-06-10 12:34 . 2009-06-10 12:34 211488 —-a-w- c:\windows\system32\nvvsvc.exe
2009-06-10 12:34 . 2009-06-10 12:34 195104 —-a-w- c:\windows\system32\nvmccss.dll
2009-06-10 12:34 . 2009-06-10 12:34 1288736 —-a-w- c:\windows\system32\nvmobls.dll
2009-06-10 12:34 . 2009-06-10 12:34 92704 —-a-w- c:\windows\system32\nvmctray.dll
2009-06-10 12:34 . 2009-06-10 12:34 768544 —-a-w- c:\windows\system32\nvsvc.dll
2009-06-10 12:34 . 2009-06-10 12:34 143360 —-a-w- c:\windows\system32\nvshext.dll
2009-06-10 12:34 . 2009-06-10 12:34 13785632 —-a-w- c:\windows\system32\nvcpl.dll
2009-06-10 10:33 . 2009-06-10 10:33 244736 —-a-w- c:\windows\system32\nvStInst.exe
2009-06-10 10:33 . 2009-06-10 10:33 467968 —-a-w- c:\windows\system32\nvstlink.exe
2009-06-10 10:33 . 2009-06-10 10:33 3953152 —-a-w- c:\windows\system32\nvstwiz.exe
2009-06-10 10:33 . 2009-06-10 10:33 141824 —-a-w- c:\windows\system32\nvStereoApiI.dll
2009-06-10 10:33 . 2009-06-10 10:33 171520 —-a-w- c:\windows\system32\nvStereoApiI64.dll
2009-06-10 10:33 . 2009-06-10 10:33 232960 —-a-w- c:\windows\system32\nvSCPAPISvr.exe
2009-06-10 10:32 . 2009-06-10 10:32 257536 —-a-w- c:\windows\system32\nvSCPAPI.dll
2009-06-10 10:32 . 2009-06-10 10:32 301568 —-a-w- c:\windows\system32\nvSCPAPI64.dll
2009-06-10 10:32 . 2009-06-10 10:32 3293184 —-a-w- c:\windows\system32\nvstres.dll
2009-06-10 10:32 . 2009-06-10 10:32 5847 —-a-w- c:\windows\system32\oglstreg.reg
2009-06-10 10:31 . 2009-06-10 10:31 167424 —-a-w- c:\windows\system32\nvstreg.exe
2009-06-10 10:31 . 2009-06-10 10:31 1718272 —-a-w- c:\windows\system32\nvsttest.exe
2009-06-10 10:31 . 2009-06-10 10:31 1034752 —-a-w- c:\windows\system32\nvstview.exe
2009-06-10 10:31 . 2009-06-10 10:31 89088 —-a-w- c:\windows\system32\nvimage.dll
2009-06-10 10:29 . 2009-06-10 10:29 1656 —-a-w- c:\windows\system32\nvstdef.reg
2009-06-10 10:03 . 2009-06-10 10:03 9899296 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2009-06-10 10:03 . 2009-06-10 10:03 989696 —-a-w- c:\windows\system32\nvapi.dll
2009-06-10 10:03 . 2009-06-10 10:03 7611904 —-a-w- c:\windows\system32\nvd3dum.dll
2009-06-10 10:03 . 2009-06-10 10:03 678432 —-a-w- c:\windows\system32\nvcuvid.dll
2009-06-10 10:03 . 2009-06-10 10:03 457248 —-a-w- c:\windows\system32\nvudisp.exe
2009-06-10 10:03 . 2009-06-10 10:03 3148288 —-a-w- c:\windows\system32\nvwgf2um.dll
2009-06-10 10:03 . 2009-06-10 10:03 1704960 —-a-w- c:\windows\system32\nvcuda.dll
2009-06-10 10:03 . 2009-06-10 10:03 151552 —-a-w- c:\windows\system32\nvcod155.dll
2009-06-10 10:03 . 2009-06-10 10:03 151552 —-a-w- c:\windows\system32\nvcod.dll
2009-06-10 10:03 . 2009-06-10 10:03 1317408 —-a-w- c:\windows\system32\nvcuvenc.dll
2009-06-10 10:03 . 2009-06-10 10:03 10379264 —-a-w- c:\windows\system32\nvoglv32.dll
2009-06-04 20:39 . 2009-07-08 13:30 457248 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-05-31 11:24 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-05-30 15:06 . 2008-08-04 00:59 50117776 —-a-w- c:\programdata\WildTangent\My HP Game Console\Downloads\en-us\Installers\battlestargalactica-setup.exe
2009-05-29 00:00 . 2009-05-28 23:59 9708 —-a-w- c:\windows\system32\cc_20090528_195953.reg
2008-09-27 17:10 . 2008-09-27 15:35 2048 –sh–w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-09-27 17:10 . 2008-09-27 15:35 2048 –sh–w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
2008-06-03 01:09 . 2008-06-03 01:09 22 –sh–w- c:\windows\SMINST\HPCD.sys
2007-12-06 15:19 . 2007-12-06 15:15 8192 –sh–w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13785632]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-20 149280]
"SPIRunE"="SPIRunE.dll" - c:\windows\System32\SpiRunE.dll [2007-05-09 18432]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):0c,35,df,7c,e3,e1,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-26859080-1141177850-1269440115-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3351FCEE-2439-4BE8-9180-0CD1FA47AA2A}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{E4A25DD1-BC98-4CE9-ABC9-3A49691BDAE1}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4BEBA389-C49A-43B1-A43C-4B8C4B45B2FD}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{BC8B0879-6B27-45FA-BC3F-1F9C660E8B6C}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D2C7C774-3825-4580-AAEE-2772E610ADAD}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{B2019820-4CCF-423D-A128-6388D6F424E6}"= UDP:c:\program files\Steam\Steam.exe:Steam
"{ADDFDE35-7033-496B-93E6-C97460CB515F}"= TCP:c:\program files\Steam\Steam.exe:Steam
"{C7368045-0B39-4662-98AA-DCB0CFEB8760}"= c:\program files\HP\DVDPlay\DVDPlay.exe:DVD Play
"{0C78B5CE-BA01-4464-A3A5-8C3D4BC36D6A}"= c:\program files\HP\DVDPlay\DPService.exe:DVD Play Resident Program
"TCP Query User{76E0832E-4040-4F49-9CA2-CA6505138FFA}c:\\program files\\electronic arts\\the battle for middle-earth ™ ii\\patchget.dat"= UDP:c:\program files\electronic arts\the battle for middle-earth ™ ii\patchget.dat:patchgrabber
"UDP Query User{0DED9D1A-F83A-4462-B773-27632CD7EB36}c:\\program files\\electronic arts\\the battle for middle-earth ™ ii\\patchget.dat"= TCP:c:\program files\electronic arts\the battle for middle-earth ™ ii\patchget.dat:patchgrabber
"{A4539084-29CF-4CF3-A253-A247DD2C662F}"= UDP:c:\program files\Portrait Displays\forteManager\dthtml.exe:forteManager
"{8520D0F7-7BEF-49E6-A7D6-783E3BE8709B}"= TCP:c:\program files\Portrait Displays\forteManager\dthtml.exe:forteManager
"{F8116513-5977-4BF3-8284-D42995F37926}"= UDP:c:\sierra\Empire Earth\Empire Earth.exe:Empire Earth
"{DF1308D6-92AA-4627-B0F1-AEC3B944CD36}"= TCP:c:\sierra\Empire Earth\Empire Earth.exe:Empire Earth
"TCP Query User{C26F3714-7EBF-40ED-9CB1-E782E9F4EA52}c:\\sierra\\empire earth\\empire earth.exe"= UDP:c:\sierra\empire earth\empire earth.exe:Empire Earth
"UDP Query User{635B8B8A-6677-4B86-B458-821926264112}c:\\sierra\\empire earth\\empire earth.exe"= TCP:c:\sierra\empire earth\empire earth.exe:Empire Earth
"TCP Query User{9EBD816A-3960-4E8F-8C29-F1EFE2F009F7}c:\\program files\\lucasarts\\star wars galactic battlegrounds saga\\game\\battlegrounds_x1.exe"= UDP:c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe:Star Wars Galactic Battlegrounds: Clone Campaigns
"UDP Query User{6E19494C-E71E-4C4D-88F0-F4EC28F4ECEE}c:\\program files\\lucasarts\\star wars galactic battlegrounds saga\\game\\battlegrounds_x1.exe"= TCP:c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe:Star Wars Galactic Battlegrounds: Clone Campaigns
"{FCFC85A8-8711-42A8-9D5A-0A3DE71C2A97}"= UDP:c:\program files\LucasArts\Star Wars Battlefront\LaunchBF.exe:Play Star Wars Battlefront
"{1D4E0BA3-F66D-450D-AE6B-7C1715F38207}"= TCP:c:\program files\LucasArts\Star Wars Battlefront\LaunchBF.exe:Play Star Wars Battlefront
"{207291F0-1F1F-46E2-AE02-2A25BC388C57}"= UDP:c:\program files\Dreamcatcher\Dungeon Lords\dlords.exe:Launch Dungeon Lords!
"{0B924A86-BB5F-416D-9147-EE66637BADBF}"= TCP:c:\program files\Dreamcatcher\Dungeon Lords\dlords.exe:Launch Dungeon Lords!
"{09190E3F-DC5C-42A3-B376-A59099FE0847}"= UDP:c:\program files\Dreamcatcher\Dungeon Lords\dlords.exe:Launch Dungeon Lords!
"{5B407205-91E4-4B2D-A77B-2D4DA7F53068}"= TCP:c:\program files\Dreamcatcher\Dungeon Lords\dlords.exe:Launch Dungeon Lords!
"{1646396E-DF6E-4BC5-A09A-4AF4B60FF147}"= UDP:c:\program files\Sierra\Empire Earth II\EE2.exe:Launch Empire Earth II
"{073E6599-F36E-46E6-B734-DFAE5E89ACB3}"= TCP:c:\program files\Sierra\Empire Earth II\EE2.exe:Launch Empire Earth II
"{637915C0-3664-458A-A866-AA07B1542B65}"= UDP:c:\program files\Sierra\Empire Earth II\EE2X.exe:Launch Empire Earth II The Art of Supremacy
"{E4F19F1F-EADD-4C64-A6D4-40D0771578B1}"= TCP:c:\program files\Sierra\Empire Earth II\EE2X.exe:Launch Empire Earth II The Art of Supremacy
"{63BCD900-FCE4-4078-BF08-0FED31A00A59}"= UDP:c:\program files\Xfire\Xfire.exe:Xfire
"{628D60B5-4E18-4D2A-B590-891AB462D6D9}"= TCP:c:\program files\Xfire\Xfire.exe:Xfire
"{6F2485ED-136C-420D-A83B-EF377765AD66}"= UDP:c:\windows\System32\Macromed\Flash\FlashUtil10.exe:FlashUtil10
"{B9F8846C-415E-4B8F-A144-D7B75506DEFB}"= TCP:c:\windows\System32\Macromed\Flash\FlashUtil10.exe:FlashUtil10
"{AA4A21A0-319E-4735-9426-BB88474E967C}"= UDP:c:\program files\Sierra\FEAR\FEARMP.exe:FEAR
"{F8018D3F-7BA3-4B6C-B43F-A46FC506FF45}"= TCP:c:\program files\Sierra\FEAR\FEARMP.exe:FEAR
"{D3F53467-CAB5-4C0E-A119-A7F2AC08A55B}"= UDP:c:\program files\LucasArts\Armed and Dangerous\ArmedAndDangerous.exe:Play Armed and Dangerous
"{9A533F87-6CA5-47FA-8DFC-7C39E2BB1916}"= TCP:c:\program files\LucasArts\Armed and Dangerous\ArmedAndDangerous.exe:Play Armed and Dangerous
"{8FEEE1FA-EB46-4405-83C6-4E0EC9166B32}"= UDP:c:\nvidia\WinVista\175.19\English\setup.exe:setup
"{97F6C9AC-203D-42D8-93DE-6C34377BAC9A}"= TCP:c:\nvidia\WinVista\175.19\English\setup.exe:setup
"TCP Query User{903589C3-55D7-4875-84B3-F9761DBC6AAF}c:\\windows\\system32\\ftp.exe"= Disabled:UDP:c:\windows\system32\ftp.exe:File Transfer Program
"UDP Query User{5CFC25D4-D997-4BC5-AC9E-870D5C94D310}c:\\windows\\system32\\ftp.exe"= Disabled:TCP:c:\windows\system32\ftp.exe:File Transfer Program
"{A34F42BF-F3F3-4D7C-802D-6295D3D0BA0F}"= UDP:c:\program files\Creative\Shared Files\Software Update\AutoUpdate.exe:Creative Software AutoUpdate
"{1E6920DB-CC33-4669-80F5-C49B54A09BFA}"= TCP:c:\program files\Creative\Shared Files\Software Update\AutoUpdate.exe:Creative Software AutoUpdate
"{BB5832D7-05C8-42ED-BAB5-66B857CBD6C6}"= UDP:c:\program files\Prey\prey.exe:Prey
"{C9BA5A1B-6F81-4F20-963E-16158D61698B}"= TCP:c:\program files\Prey\prey.exe:Prey
"{2C6C7C69-3395-4E5D-9397-435D7AF3D91D}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{D10A338B-82C2-42F4-B92C-347BE9B4625E}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{F60DFD53-364A-4C87-BF09-F9E586755EC5}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{2C62C964-A206-4971-A4BD-784678AC3024}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{31C821BD-4DD5-4D47-9A27-EE32E4CEC1B8}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{6DAC9619-70B4-4863-A098-1B5EBBEE5FE6}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{BF6B9339-D163-4823-8B13-4E84C22F1553}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{3612881D-19F9-4D39-ACF9-7DFB4A8191DD}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{7906F02E-47CE-4AB5-824D-FE1CCF139ED7}"= UDP:c:\program files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"{09ECE2EF-5417-4326-A5C5-EE9CCC898B89}"= TCP:c:\program files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"TCP Query User{0C6C184A-D511-4CA4-8663-055E13035EB8}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{75E8B98C-7B7B-402C-BC29-0A07AC980DA5}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{2FA463B9-3337-4B7D-B83B-E981A5FA4982}"= UDP:c:\program files\ATT-HSI\McciBrowser.exe:motivebrowser.exe
"{47866BC3-E0B2-48F9-9DEA-683A39CDF1C0}"= TCP:c:\program files\ATT-HSI\McciBrowser.exe:motivebrowser.exe
"TCP Query User{E51255DD-7888-4412-9264-2773B91C136D}c:\\program files\\unreal tournament 3\\binaries\\ut3.exe"= UDP:c:\program files\unreal tournament 3\binaries\ut3.exe:UT3
"UDP Query User{A04F4B66-114F-4C0F-A66B-F20F6CB5055F}c:\\program files\\unreal tournament 3\\binaries\\ut3.exe"= TCP:c:\program files\unreal tournament 3\binaries\ut3.exe:UT3
"TCP Query User{0660B57A-B60A-4932-B2A5-E667788DA6DF}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{68861914-3D27-4131-83B5-6F3E62455F38}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{2A26E114-8DB4-4D84-A469-7C268B575FAB}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{2CBDD4B1-6190-4248-879E-0742264A04F3}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{93CFE171-3919-42D3-8EDA-936F1E13ECAD}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{F5EBF32B-6B0E-438F-92F5-B2371066DD0B}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{4F26C0C6-9E61-4DE0-BA14-5C121D3CB7DE}"= UDP:c:\program files\Starbreeze Studios\Riddick EFBB\Riddick.exe:The Chronicles of Riddick - Escape From Butcher Bay
"{47BA206A-4752-4E5B-93B6-5D88DD6A6303}"= TCP:c:\program files\Starbreeze Studios\Riddick EFBB\Riddick.exe:The Chronicles of Riddick - Escape From Butcher Bay
"{5FB1EDD3-A168-4F2D-BFE5-D34735438BA8}"= UDP:c:\program files\LucasArts\Star Wars Republic Commando\LaunchRC.exe:Play Star Wars Republic Commando
"{EB6FD7B8-C640-4545-A943-0F82FF35AA36}"= TCP:c:\program files\LucasArts\Star Wars Republic Commando\LaunchRC.exe:Play Star Wars Republic Commando
"{478DCD77-809D-431C-A2BD-9C6EC170DA52}"= UDP:c:\program files\LucasArts\Star Wars JK II Jedi Outcast\JediOutcast.exe:Play Star Wars JK II Jedi Outcast
"{9987ABB6-7444-4117-B806-A36E19CB9F6F}"= TCP:c:\program files\LucasArts\Star Wars JK II Jedi Outcast\JediOutcast.exe:Play Star Wars JK II Jedi Outcast
"{6F70E553-2082-4F15-9BBA-6552DF6AE24A}"= UDP:c:\users\Ron\Documents\CoD4MWDemoSetup_v2.exe:CoD4MWDemoSetup_v2
"{8DDC1897-FD51-4E1A-BF9A-861F0C8749D0}"= TCP:c:\users\Ron\Documents\CoD4MWDemoSetup_v2.exe:CoD4MWDemoSetup_v2
"{0EA8BCE7-AF14-4216-A6D6-58211F666820}"= UDP:c:\program files\Windows Defender\MSASCui.exe:Windows Defender
"{814A73C0-A846-4CF8-BD0A-4775D1C23676}"= TCP:c:\program files\Windows Defender\MSASCui.exe:Windows Defender
"TCP Query User{07A2A222-DA3A-42B0-BBDE-44D8E426CDB3}c:\\program files\\sierra entertainment\\timeshift\\bin\\timeshift.exe"= UDP:c:\program files\sierra entertainment\timeshift\bin\timeshift.exe:TimeShift
"UDP Query User{AFC6C9D2-9FB4-4440-91D8-C213AEF8439F}c:\\program files\\sierra entertainment\\timeshift\\bin\\timeshift.exe"= TCP:c:\program files\sierra entertainment\timeshift\bin\timeshift.exe:TimeShift
"{371DBC0A-2599-4B56-90DD-0891FDD19125}"= UDP:c:\users\Ron\AppData\Local\Temp\7zSD47D.tmp\SymNRT.exe:Norton Removal Tool
"{2FFF5EBD-C7C8-4D42-990B-72529F56BB30}"= TCP:c:\users\Ron\AppData\Local\Temp\7zSD47D.tmp\SymNRT.exe:Norton Removal Tool
"{8DE0625A-5F11-48BC-A6B1-623B8BB494AD}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C21A1C19-30D6-458E-8DAC-70870F74DC08}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D27DA631-2E2E-4C3A-9B98-6ECBED312567}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{71BB7864-CBCA-4070-B577-3D37035A3B50}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{843CADE8-23FD-4A14-B8A5-28C8ED46D999}"= UDP:c:\program files\Sierra\FEAR\FEARMP.exe:FEAR
"{0DD75B9A-012F-4BE8-B46E-23729023DEF1}"= TCP:c:\program files\Sierra\FEAR\FEARMP.exe:FEAR
"{8C9C2618-1B0E-48C8-8F08-F52511E2968C}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{24869F24-F7B9-4241-903A-EA8A96279D01}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"TCP Query User{01308A08-C614-429A-87AD-D80A06AE92D3}c:\\program files\\lucasarts\\star wars battlefront ii\\gamedata\\battlefrontii.exe"= UDP:c:\program files\lucasarts\star wars battlefront ii\gamedata\battlefrontii.exe:BattlefrontII
"UDP Query User{7BDD84E3-29F6-4955-9F29-80A0AD64D272}c:\\program files\\lucasarts\\star wars battlefront ii\\gamedata\\battlefrontii.exe"= TCP:c:\program files\lucasarts\star wars battlefront ii\gamedata\battlefrontii.exe:BattlefrontII
"{3EAB6E2C-8425-4CC3-8E9F-B51B6A2315C7}"= UDP:c:\users\Ron\Desktop\Flash_Disinfector.exe:Flash_Disinfector
"{C696FF47-F7A3-4AB7-A7BE-33836EA259E1}"= TCP:c:\users\Ron\Desktop\Flash_Disinfector.exe:Flash_Disinfector

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)
"DisabledInterfaces"= {51E56691-212E-4998-86F7-41E404B77D20}

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NAV\1002000.007\SymEFA.sys [8/24/2009 7:41 PM 309296]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NAV\1002000.007\BHDrvx86.sys [8/24/2009 7:41 PM 255536]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NAV\1002000.007\cchpx86.sys [8/24/2009 7:41 PM 362544]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090810.001\IDSvix86.sys [8/24/2009 7:52 PM 293424]
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\HP\DVDPlay\000.fcl [12/6/2007 11:58 AM 39408]
R2 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [10/3/2008 11:46 PM 79360]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe [8/24/2009 7:41 PM 115560]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\System32\nvSCPAPISvr.exe [6/10/2009 6:33 AM 232960]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\System32\drivers\HCW85BDA.sys [12/3/2008 11:20 PM 1426304]
R3 t3;Sound Blaster X-Fi Xtreme Audio (Vista);c:\windows\System32\drivers\t3.sys [10/17/2008 2:43 AM 404992]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [6/29/2009 9:05 PM 79360]
S3 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [12/6/2007 12:06 PM 198240]
S3 mr97310c;CIF Dual-Mode Camera;c:\windows\System32\drivers\mr97310c.sys [3/27/2008 7:14 AM 116992]
S3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\System32\drivers\netr73.sys [2/26/2008 9:17 AM 493568]

— Other Services/Drivers In Memory —

*NewlyCreated* - BHDRVX86
*NewlyCreated* - CCHP
*NewlyCreated* - NAVENG
*NewlyCreated* - NAVEX15
*NewlyCreated* - SRTSP
*NewlyCreated* - SRTSPX
*NewlyCreated* - SYMEVENT
*NewlyCreated* - SYMIM
*Deregistered* - EraserUtilDrv10910
*Deregistered* - EraserUtilDrvI7
*Deregistered* - SYMDNS
*Deregistered* - SYMFW
*Deregistered* - SYMNDISV
*Deregistered* - SYMREDRV
.
Contents of the 'Scheduled Tasks' folder

2009-08-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-14 21:39]

2009-03-10 c:\windows\Tasks\HPCeeScheduleForDylan.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-12-06 00:34]

2009-08-06 c:\windows\Tasks\HPCeeScheduleForKellie.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-12-06 00:34]

2009-08-16 c:\windows\Tasks\HPCeeScheduleForRon.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2007-12-06 00:34]

2009-05-20 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-06-23 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-08-09 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=81&bd;=Pavilion&pf;=desktop
uInternet Settings,ProxyOverride = *.local
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-24 20:16
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\c:\program files\HP\DVDPlay\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-26859080-1141177850-1269440115-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b9,0e,8c,53,54,4f,e7,35,c6,81,bf,83,02,07,4f,41,a1,9b,c9,ba,8c,b9,fc,
f1,d7,c0,46,1c,62,1f,08,7c,4e,ee,47,3a,26,0c,0a,7b,66,78,50,7b,2c,0b,ae,2b,\
"??"=hex:4a,24,e8,9a,b7,34,f2,03,22,42,1b,d3,15,81,54,81

[HKEY_USERS\S-1-5-21-26859080-1141177850-1269440115-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:ed,e3,fe,bc,0c,7f,55,cd,5f,33,99,9b,92,fc,d6,d9,ee,fa,42,7f,02,
87,9a,1a,e2,2a,50,ad,34,92,c1,ad,41,e7,68,b0,88,06,7f,cf,94,ff,fc,69,ff,65,\
"rkeysecu"=hex:eb,c1,0a,bf,23,e0,a2,5f,4e,7c,b5,ad,0d,84,0a,a5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-08-25 20:18
ComboFix-quarantined-files.txt 2009-08-25 00:18

Pre-Run: 265,927,405,568 bytes free
Post-Run: 265,958,060,032 bytes free
easyriter,

I ran a scan, and deleted a detected cookie. Could that be "C:\Users\kellie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FJJJ5FG1\fi36le[1].pdf Infected: Exploit.Win32.Pidief.bjx 1" found by the Kaspersky scan?

Could have been. Also, if you looked after ComboFix ran, it would have emptied them.

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
TomK, I ran the OTC and everything looks fine. I've added your recommended reading to my favorites list, and you better believe I'll be reading all of it! I've noticed some improvement in startup, and I feel a whole lot better about the condition and security of my computer. I want to thank you for all your help. I've learned a lot from this, I can tell you. A greatly appreciative, easyriter
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI