This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Google redirecting to other links

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello folks. Sometimes when I do a search using google and click on a link it will redirect me to some advertising sites.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:09:49 PM, on 8/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
E:\WINDOWS2\System32\smss.exe
E:\WINDOWS2\system32\winlogon.exe
E:\WINDOWS2\system32\services.exe
E:\WINDOWS2\system32\lsass.exe
E:\WINDOWS2\System32\Ati2evxx.exe
E:\WINDOWS2\system32\svchost.exe
E:\WINDOWS2\System32\svchost.exe
E:\WINDOWS2\system32\Ati2evxx.exe
E:\WINDOWS2\Explorer.EXE
E:\WINDOWS2\system32\spoolsv.exe
E:\Program Files\Creative\Shared Files\CTAudSvc.exe
E:\WINDOWS2\system32\CTHELPER.EXE
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Java\jre6\bin\jusched.exe
E:\PROGRA~1\AVG\AVG8\avgtray.exe
E:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
E:\WINDOWS2\system32\ctfmon.exe
D:\Program Files\DAP\DAP.EXE
E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
E:\Program Files\AskBarDis\bar\bin\AskService.exe
E:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
E:\PROGRA~1\AVG\AVG8\avgfws8.exe
E:\Program Files\Bonjour\mDNSResponder.exe
E:\WINDOWS2\System32\CTsvcCDA.EXE
D:\Program Files\FileZilla Server\FileZilla Server.exe
E:\PROGRA~1\AVG\AVG8\avgam.exe
E:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\WINDOWS2\System32\svchost.exe
E:\Program Files\Mozilla Firefox\firefox.exe
D:\PROGRA~1\MICROS~4\Office12\OUTLOOK.EXE
E:\Program Files\AVG\AVG8\avgcsrvx.exe
D:\Program Files\Microsoft Office\Office12\EXCEL.EXE
E:\Program Files\AVG\AVG8\avgcsrvx.exe
E:\PROGRA~1\AVG\AVG8\avgnsx.exe
D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
D:\Program Files\iTunes\iTunes.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - E:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - D:\PROGRA~1\DAP\DAPIEL~1.DLL
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - E:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "E:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] E:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [FileZilla Server Interface] "D:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "D:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS2\system32\ctfmon.exe
O4 - HKCU\..\Run: [DownloadAccelerator] "D:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - Global Startup: Desktop Manager.lnk = D:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O8 - Extra context menu item: &Clean Traces - D:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - D:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS2\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS2\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://F:\content\include\XPPatchInstaller.CAB
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15108/CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - E:\WINDOWS2\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - E:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - E:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS2\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS2\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - E:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Bonjour Service - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - E:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - E:\WINDOWS2\System32\CTsvcCDA.EXE
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - E:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - D:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - E:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - E:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - E:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - E:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - E:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

–
End of file - 8718 bytes
Due, in part, to the large numbers of HJT logs being posted, there are four things that you need to be aware of.

1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.

2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!

3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.

4) Back-ups can get lost or damaged, so make two if the files are that important to you!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pay a visit to the Kaspersky Online Scanner 7 - I.E. is preferred for this scan.
  • Read the Information panel and then click Accept.
  • Allow the ActiveX download if necessary.
  • Both the anti-virus engine and database will need to be downloaded, which may take a little time.
  • Once this has been completed, select My Computer from the Scan section on the left hand side.
  • Put the kettle on!
  • Although it is recommended by Kaspersky that you should disable your anti-virus scanner before starting this scan, it should work OK with it still active - it does on my PC.
    Although you may find the scan speed increases if you carry out this step, I never like to disable my resident scanner while online, so I don't.
  • When the scan has completed, click View scan report at the bottom.
  • Click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save and pick a location for the file - the Desktop is always handy.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Sec-Info2.zip from here and save it to your Desktop. You will need to extract the file.

Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see a folder with a file in it - double click Sec-info2.vbs to run it.
Once you have been informed that the script has completed, a text file called Sec-Info.txt should be created in the same folder - you may need to wait a couple of seconds for it to appear..
Please copy and paste the contents of the text file into your next reply and then you can delete both of the folders and their contents.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Rooter.exe from here and save it to your Desktop.
  • Double-click it to start the tool.
  • Click the Scan button to… well… scan - obvious really!
  • Once complete, a Notepad file containing the report will open; a copy of which can be found at C:\Rooter$\Rooter.txt - assuming your main drive is C: of course.
  • Please post the contents of Rooter.txt in your next reply.
Kaspersky would not start. I tried a quite a few times in Firefox and IE and rebooted a few time and ..nothing. Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully … . Windows XP . (5.1.2600) Service Pack 3 [32_bits] - x86 Family 15 Model 2 Stepping 9, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [SharedAccess] RUNNING (state:4) Windows Firewall -> Disabled ! . Internet Explorer 8.0.6001.18702 Mozilla Firefox 3.5.2 (en-US) . A:\ [Removable] C:\ [Fixed-NTFS] .. ( Total:0 Go - Free:0 Go ) D:\ [Fixed-NTFS] .. ( Total:298 Go - Free:166 Go ) E:\ [Fixed-NTFS] .. ( Total:74 Go - Free:19 Go ) F:\ [CD_Rom] . Scan : 12:51.26 Path : D:\Documents and Settings\kuldip.KULDIP-WP3MGP0C\Desktop\DAP\Rooter.exe User : Deep ( Administrator -> YES ) . ———————-\\ Processes . Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (716) ______ \??\E:\WINDOWS2\system32\csrss.exe (772) ______ \??\E:\WINDOWS2\system32\winlogon.exe (816) ______ E:\WINDOWS2\system32\services.exe (864) ______ E:\WINDOWS2\system32\lsass.exe (876) ______ E:\WINDOWS2\System32\Ati2evxx.exe (1052) ______ E:\WINDOWS2\system32\svchost.exe (1072) ______ E:\WINDOWS2\system32\svchost.exe (1188) ______ E:\WINDOWS2\System32\svchost.exe (1316) ______ E:\WINDOWS2\system32\Ati2evxx.exe (1388) ______ E:\WINDOWS2\System32\svchost.exe (1396) ______ E:\WINDOWS2\System32\svchost.exe (1680) ______ E:\WINDOWS2\Explorer.EXE (1760) ______ E:\WINDOWS2\system32\spoolsv.exe (1896) ______ E:\Program Files\Creative\Shared Files\CTAudSvc.exe (1964) ______ E:\WINDOWS2\system32\CTHELPER.EXE (456) ______ D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (468) ______ D:\Program Files\iTunes\iTunesHelper.exe (488) ______ D:\Program Files\Java\jre6\bin\jusched.exe (500) ______ E:\PROGRA~1\AVG\AVG8\avgtray.exe (512) ______ E:\Program Files\Messenger\msmsgs.exe (552) ______ D:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (588) ______ E:\WINDOWS2\system32\ctfmon.exe (616) ______ D:\Program Files\DAP\DAP.EXE (436) ______ E:\WINDOWS2\System32\svchost.exe (1380) ______ E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (1480) ______ E:\Program Files\AskBarDis\bar\bin\AskService.exe (932) ______ E:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe (1572) ______ E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (1696) ______ E:\PROGRA~1\AVG\AVG8\avgfws8.exe (1944) ______ E:\Program Files\Bonjour\mDNSResponder.exe (2108) ______ E:\WINDOWS2\System32\CTsvcCDA.EXE (2204) ______ D:\Program Files\FileZilla Server\FileZilla Server.exe (2448) ______ E:\PROGRA~1\AVG\AVG8\avgam.exe (2500) ______ E:\PROGRA~1\AVG\AVG8\avgrsx.exe (2512) ______ D:\Program Files\Java\jre6\bin\jqs.exe (2688) ______ E:\WINDOWS2\system32\wdfmgr.exe (3520) ______ E:\Program Files\iPod\bin\iPodService.exe (4004) ______ E:\WINDOWS2\System32\alg.exe (2156) ______ E:\WINDOWS2\System32\svchost.exe (3128) ______ D:\PROGRA~1\MICROS~4\Office12\OUTLOOK.EXE (784) ______ E:\Program Files\AVG\AVG8\avgcsrvx.exe (3340) ______ D:\Program Files\Microsoft Office\Office12\EXCEL.EXE (2444) ______ E:\Program Files\AVG\AVG8\avgcsrvx.exe (2284) ______ E:\PROGRA~1\AVG\AVG8\avgnsx.exe (3164) ______ E:\Program Files\Mozilla Firefox\firefox.exe (5448) ______ E:\WINDOWS2\system32\NOTEPAD.EXE (5892) ______ E:\WINDOWS2\system32\notepad.exe (6040) ______ D:\Documents and Settings\kuldip.KULDIP-WP3MGP0C\Desktop\DAP\Rooter.exe (3224) . ———————-\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:32256 | Length:8193024) \Device\Harddisk0\Partition0 (Start_Offset:8225280 | Length:80015523840) \Device\Harddisk0\Partition2 (Start_Offset:8257536 | Length:80015491584) . ———————-\\ Scheduled Tasks . E:\WINDOWS2\Tasks\AppleSoftwareUpdate.job E:\WINDOWS2\Tasks\desktop.ini E:\WINDOWS2\Tasks\SA.DAT . ———————-\\ Registry . . ———————-\\ Files & Folders . ———————-\\ Scan completed at 12:51.30 . E:\Rooter$\Rooter_1.txt - (17/08/2009 | 12:51.30) Adobe Flash Player 10 Plugin Adobe Reader 9.1.3 Apple Mobile Device Support Apple Software Update ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver AVG 8.5 BlackBerry Desktop Software 4.3 BlackBerry Desktop Software 4.3 Bonjour Catalyst Control Center - Branding Creative Audio Console Creative MediaSource Creative Software AutoUpdate Download Accelerator Plus (DAP) FileZilla Server (remove only) HijackThis 2.0.2 Hotfix for Windows XP (KB952287) iTunes Java™ 6 Update 15 Malwarebytes' Anti-Malware Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.5.2) MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser QuickTime Roxio Media Manager Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB973540) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) SoundFont Bank Manager Update for Windows Internet Explorer 8 (KB972636) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB973815) Vuze Vuze Toolbar Windows Internet Explorer 8 Windows Media Format Runtime Windows XP Service Pack 3 Script run: 8/17/2009 12:48:52 PM ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: AVG Technologies AV Name: AVG Internet Security 3-pack Version Number: 8.5 On-Access Scanning Enabled: Yes Product up-to-date: Yes ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: AVG Technologies CZ, s.r.o. Firewall Name: AVG Firewall Version Number: 8.5 Enabled: Yes ~~~~~~~~~~~~~~~~~~~~~~~~ The Windows Firewall is disabled. ~~~~~~~~~~~~~~~~~~~~~~~~ The Security Center Anti-Virus Alerts are enabled. The Security Center Firewall Alerts are enabled. ~~~~~~~~~~~~~~~~~~~~~~~~ Number of Restore Points found: 0 ~~~~~~~~~~~~~~~~~~~~~~~~
Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix *
  • Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
  • Post a fresh HJT log as well.
  • Let me know how the PC is behaving.
* There are two points to note from the instructions page:

1) The Recovery Console.

It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete some, but not all, of it's removal tasks without the installation of the Console, so you are free to choose whether you want to complete this step, but it is in your interests to do so.

2) Disabling your Anti-Virus.

CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download RootRepeal from one of the locations below and save it to your Desktop:
Location 1
Location 2
Location 4
(Location 3 is taking a fortnight off in Teneriffe but did send a postcard!)

You will need to unzip it before you run it.

To do this: Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish

  • Double click RootRepeal.exe to fire up the tool and OK any Windows confirmation if necessary.
  • Ensure that the Report Tab is selected at the bottom.
  • Click the Scan button, check all the boxes in the window that appears and then click OK.
  • Check the box next to your main hard drive - usually C: and click OK
  • Put the kettle on and perhaps open a packet of biscuits - the scan will take some time.
  • The results will be saved to the root of your main drive as \RootRepeal report date time.txt
Let me have a copy of the contents in your next reply.
ComboFix 09-08-10.06 - Deep 08/18/2009 14:38.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1791.1333 [GMT -7:00]
Running from: e:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Internet Security 3-pack *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

E:\_NIM4711.TMP
E:\ALCXDEV.EXE
e:\recycler\S-1-5-21-1547161642-1078081533-725345543-1003
e:\recycler\S-1-5-21-1757981266-1972579041-725345543-1003
e:\recycler\S-1-5-21-3757435101-3305645547-1862811806-1006
e:\windows2\system32\drivers\SKYNETavqbbprq.sys
e:\windows2\system32\SKYNETnswrqpgt.dat
e:\windows2\system32\SKYNETplhonvtr.dll
e:\windows2\system32\SKYNETtonkrjoo.dll
e:\windows2\system32\SKYNETwpuyfqjw.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SKYNETotsniqlt
——-\Legacy_SKYNETotsniqlt
——-\Legacy_6TO4
——-\Legacy_IAS
——-\Legacy_NETCARD


((((((((((((((((((((((((( Files Created from 2009-07-18 to 2009-08-18 )))))))))))))))))))))))))))))))
.

2009-08-18 15:29 . 2009-08-18 21:01 ——– d—–w- e:\documents and settings\Deep\Application Data\.purple
2009-08-18 05:53 . 2008-10-16 21:06 268648 —-a-w- e:\windows2\system32\mucltui.dll
2009-08-18 05:53 . 2008-10-16 21:06 208744 —-a-w- e:\windows2\system32\muweb.dll
2009-08-17 19:51 . 2009-08-17 19:51 ——– d—–w- E:\Rooter$
2009-08-16 22:36 . 2009-08-16 22:36 ——– d-sh–w- e:\documents and settings\Deep\PrivacIE
2009-08-16 22:33 . 2009-08-16 22:34 ——– d—–w- e:\documents and settings\Deep\Local Settings\Application Data\Adobe
2009-08-14 16:46 . 2009-08-14 16:46 ——– d—–w- e:\documents and settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\Apple
2009-08-13 17:57 . 2009-08-13 17:57 ——– d-sh–w- e:\documents and settings\NetworkService.NT AUTHORITY.000\IETldCache
2009-08-11 21:09 . 2009-07-10 13:27 1315328 -c—-w- e:\windows2\system32\dllcache\msoe.dll
2009-08-10 13:33 . 2009-08-10 13:33 ——– d-sh–w- e:\windows2\system32\config\systemprofile\IETldCache
2009-08-08 21:30 . 2009-08-03 20:36 38160 —-a-w- e:\windows2\system32\drivers\mbamswissarmy.sys
2009-08-08 21:30 . 2009-08-08 21:30 ——– d—–w- e:\documents and settings\Deep\Application Data\Malwarebytes
2009-08-08 21:30 . 2009-08-08 21:30 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\Malwarebytes
2009-08-08 21:30 . 2009-08-03 20:36 19096 —-a-w- e:\windows2\system32\drivers\mbam.sys
2009-08-08 19:29 . 2009-08-18 21:48 ——– d—a-w- e:\documents and settings\All Users.WINDOWS2\Application Data\TEMP
2009-08-08 19:29 . 2009-08-08 19:29 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\SpeedBit
2009-08-08 19:29 . 2009-08-08 19:29 50688 —-a-w- e:\windows2\system32\wbhelp2.dll
2009-08-07 04:12 . 2009-08-07 04:12 ——– d-sh–w- e:\documents and settings\Deep\IETldCache
2009-08-07 04:12 . 2009-08-07 04:12 ——– d-sh–w- e:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache
2009-08-07 04:09 . 2009-08-07 04:09 ——– d—–w- e:\windows2\system32\LogFiles
2009-08-07 04:05 . 2009-07-20 01:48 11067392 -c—-w- e:\windows2\system32\dllcache\ieframe.dll
2009-08-07 04:05 . 2009-07-03 17:09 12800 -c—-w- e:\windows2\system32\dllcache\xpshims.dll
2009-08-07 04:05 . 2009-07-03 17:09 594432 -c—-w- e:\windows2\system32\dllcache\msfeeds.dll
2009-08-07 04:05 . 2009-07-03 17:09 55296 -c—-w- e:\windows2\system32\dllcache\msfeedsbs.dll
2009-08-07 04:05 . 2009-07-03 17:09 1985536 -c—-w- e:\windows2\system32\dllcache\iertutil.dll
2009-08-07 04:05 . 2009-07-03 17:09 246272 -c—-w- e:\windows2\system32\dllcache\ieproxy.dll
2009-08-07 04:04 . 2009-08-07 04:04 ——– d—–w- e:\windows2\ie8updates
2009-08-07 04:04 . 2009-07-01 07:08 101376 -c—-w- e:\windows2\system32\dllcache\iecompat.dll
2009-08-07 04:03 . 2009-08-07 04:04 ——– dc-h–w- e:\windows2\ie8
2009-08-07 02:51 . 2008-04-14 12:40 102912 -c—-w- e:\windows2\system32\dllcache\dpcdll.dll
2009-08-07 02:50 . 2008-04-14 12:42 32768 —-a-w- e:\windows2\system32\setupn.exe
2009-08-07 02:47 . 2008-04-14 12:41 33792 -c—-w- e:\windows2\system32\dllcache\custsat.dll
2009-08-07 02:44 . 2008-04-14 05:06 144384 ——w- e:\windows2\system32\drivers\hdaudbus.sys
2009-08-07 02:44 . 2008-04-14 07:10 10240 ——w- e:\windows2\system32\drivers\sffp_mmc.sys
2009-08-06 17:02 . 2009-08-18 12:22 ——– d–h–w- E:\$AVG8.VAULT$
2009-08-06 16:29 . 2009-08-06 16:29 11952 —-a-w- e:\windows2\system32\avgrsstx.dll
2009-08-06 16:29 . 2009-08-06 16:29 12552 —-a-w- e:\windows2\system32\drivers\avgrkx86.sys
2009-08-06 16:29 . 2009-08-06 16:29 108552 —-a-w- e:\windows2\system32\drivers\avgtdix.sys
2009-08-06 16:29 . 2009-08-06 16:29 335240 —-a-w- e:\windows2\system32\drivers\avgldx86.sys
2009-08-06 16:29 . 2009-08-06 16:29 27784 —-a-w- e:\windows2\system32\drivers\avgmfx86.sys
2009-08-06 16:29 . 2009-08-18 09:52 ——– d—–w- e:\windows2\system32\drivers\Avg
2009-08-06 16:27 . 2009-08-06 16:27 50968 —-a-w- e:\windows2\system32\avgfwdx.dll
2009-08-06 16:27 . 2009-08-06 16:27 29208 —-a-w- e:\windows2\system32\drivers\avgfwdx.sys
2009-08-06 16:27 . 2009-08-06 16:27 ——– d—–w- e:\program files\AVG
2009-08-06 16:27 . 2009-08-14 05:15 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\avg8
2009-08-06 16:25 . 2009-08-06 16:25 ——– d—–w- e:\documents and settings\Deep\Application Data\AVG8
2009-08-06 16:00 . 2008-04-14 12:42 221184 —-a-w- e:\windows2\system32\wmpns.dll
2009-08-06 15:36 . 2009-08-06 15:36 102664 —-a-w- e:\windows2\system32\drivers\tmcomm.sys
2009-08-06 15:36 . 2009-08-06 17:07 ——– d—–w- e:\documents and settings\Deep\.housecall6.6
2009-08-06 15:36 . 2009-08-06 15:36 ——– d—–w- e:\windows2\Sun
2009-08-06 15:30 . 2009-08-06 15:30 411368 —-a-w- e:\windows2\system32\deploytk.dll
2009-08-06 15:07 . 2009-08-06 15:07 ——– d—–w- e:\documents and settings\Deep\Application Data\Apple Computer
2009-08-06 15:06 . 2009-03-19 23:32 23400 —-a-w- e:\windows2\system32\drivers\GEARAspiWDM.sys
2009-08-06 15:06 . 2008-04-17 19:12 107368 —-a-w- e:\windows2\system32\GEARAspi.dll
2009-08-06 15:06 . 2009-08-06 15:06 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-06 15:04 . 2009-08-06 15:06 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\Apple Computer
2009-08-06 15:04 . 2009-08-06 15:04 ——– d—–w- e:\documents and settings\Deep\Local Settings\Application Data\Apple
2009-08-06 15:03 . 2009-08-06 15:03 ——– d—–w- e:\program files\Apple Software Update
2009-08-06 15:03 . 2009-08-06 15:06 ——– dc—-w- e:\windows2\system32\DRVSTORE
2009-08-06 15:03 . 2009-08-06 15:03 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\Apple
2009-08-06 15:00 . 2009-08-06 15:07 ——– d—–w- e:\documents and settings\Deep\Local Settings\Application Data\Apple Computer
2009-08-06 01:06 . 2009-08-06 01:06 ——– d—–w- e:\documents and settings\Deep\Application Data\Blackberry Desktop
2009-08-06 00:46 . 2008-06-13 11:05 272128 -c—-w- e:\windows2\system32\dllcache\bthport.sys
2009-08-06 00:43 . 2009-02-06 11:08 2189056 -c—-w- e:\windows2\system32\dllcache\ntoskrnl.exe
2009-08-06 00:43 . 2009-02-06 10:32 2023936 -c—-w- e:\windows2\system32\dllcache\ntkrpamp.exe
2009-08-06 00:43 . 2008-10-24 11:21 455296 -c—-w- e:\windows2\system32\dllcache\mrxsmb.sys
2009-08-06 00:42 . 2008-10-15 16:34 337408 -c—-w- e:\windows2\system32\dllcache\netapi32.dll
2009-08-06 00:41 . 2008-09-04 17:15 1106944 -c—-w- e:\windows2\system32\dllcache\msxml3.dll
2009-08-06 00:39 . 2008-05-03 11:55 2560 ——w- e:\windows2\system32\xpsp4res.dll
2009-08-06 00:39 . 2008-04-21 12:08 215552 -c—-w- e:\windows2\system32\dllcache\wordpad.exe
2009-08-06 00:26 . 2009-08-14 01:34 ——– d–h–w- e:\windows2\$hf_mig$
2009-08-06 00:24 . 2008-04-14 07:15 32128 —-a-w- e:\windows2\system32\drivers\usbccgp.sys
2009-08-05 19:12 . 2009-08-18 21:49 256 —-a-w- e:\windows2\system32\pool.bin
2009-08-05 19:12 . 2009-08-05 19:12 ——– d—–w- e:\documents and settings\Deep\Application Data\Research In Motion
2009-08-05 19:07 . 2009-08-05 19:07 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\InstallShield
2009-08-05 19:07 . 2009-08-05 19:07 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\Sonic
2009-08-05 18:57 . 2009-08-05 19:11 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\Roxio
2009-08-05 18:45 . 2007-01-18 17:24 26496 —-a-r- e:\windows2\system32\drivers\RimSerial.sys
2009-08-05 18:35 . 2009-08-05 18:35 ——– d-sh–w- e:\windows2\ftpcache
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c—-w- e:\windows2\system32\dllcache\mswebdvd.dll
2009-08-05 06:06 . 2006-10-27 02:56 32592 —-a-w- e:\windows2\system32\msonpmon.dll
2009-08-05 05:50 . 2009-08-05 05:56 ——– d—–w- e:\windows2\SHELLNEW
2009-08-05 05:49 . 2009-08-05 05:49 ——– d—–w- e:\documents and settings\Deep\Local Settings\Application Data\Microsoft Help
2009-08-05 05:49 . 2009-08-05 15:02 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\Microsoft Help
2009-08-05 05:35 . 2009-08-07 02:54 ——– d—–w- e:\windows2\system32\wbem\AutoRecover
2009-08-05 05:35 . 2009-08-05 05:35 ——– d-s—w- e:\windows2\system32\Microsoft
2009-08-05 05:24 . 2009-08-07 02:50 ——– d—–w- e:\windows2\peernet
2009-08-05 05:24 . 2009-08-05 05:24 ——– d—–w- e:\windows2\provisioning
2009-08-05 05:22 . 2009-08-05 05:22 ——– d—–w- e:\windows2\ServicePackFiles
2009-08-05 05:19 . 2009-01-08 01:21 26144 —-a-w- e:\windows2\system32\spupdsvc.exe
2009-08-05 05:18 . 2009-08-07 02:39 ——– d—–w- e:\windows2\EHome
2009-08-05 05:13 . 2008-04-14 12:42 11264 —-a-w- e:\windows2\system32\spnpinst.exe
2009-08-05 05:13 . 2004-08-02 21:20 4569 —-a-w- e:\windows2\system32\secupd.dat
2009-08-05 04:57 . 2008-04-14 12:42 239104 —-a-w- e:\windows2\system32\srrstr.dll
2009-08-05 04:55 . 2009-08-05 05:00 ——– dc-h–w- e:\windows2\$xpsp1hfm$
2009-08-05 04:55 . 2003-08-02 04:14 25600 —-a-w- e:\windows2\system32\xpsp1hfm.exe
2009-08-05 04:52 . 1999-12-13 08:01 44032 —-a-w- e:\windows2\system32\CTSVCCDA.EXE
2009-08-05 04:52 . 1999-11-18 08:00 25088 —-a-w- e:\windows2\system32\CTSVCCTL.EXE
2009-08-05 04:20 . 2009-08-05 04:20 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\Creative
2009-08-05 04:17 . 2009-08-05 04:20 ——– d—–w- e:\windows2\system32\Defaults
2009-08-05 04:15 . 2008-04-14 07:15 10624 —-a-w- e:\windows2\system32\drivers\gameenum.sys
2009-08-05 04:15 . 2009-08-05 04:15 ——– d—–w- e:\program files\Common Files\Creative Labs Shared
2009-08-05 04:13 . 2008-04-14 12:42 23552 —-a-w- e:\windows2\system32\wdmaud.drv
2009-08-05 04:13 . 2008-04-14 12:41 4096 —-a-w- e:\windows2\system32\ksuser.dll
2009-08-05 04:13 . 2008-04-14 07:49 146048 —-a-w- e:\windows2\system32\drivers\portcls.sys
2009-08-05 04:13 . 2008-04-14 07:46 141056 —-a-w- e:\windows2\system32\drivers\ks.sys
2009-08-05 04:13 . 2008-04-14 07:15 60160 —-a-w- e:\windows2\system32\drivers\drmk.sys
2009-08-05 04:13 . 2008-04-14 07:15 49408 —-a-w- e:\windows2\system32\drivers\stream.sys
2009-08-05 04:13 . 2009-08-05 04:13 ——– d—–w- e:\windows2\system32\Data
2009-08-05 04:09 . 2009-08-07 02:50 ——– d—–w- e:\windows2\system32\bits
2009-08-05 04:06 . 2008-12-16 12:30 354304 —-a-w- e:\windows2\system32\winhttp.dll
2009-08-05 04:06 . 2008-04-14 12:42 18944 —-a-w- e:\windows2\system32\qmgrprxy.dll
2009-08-05 04:06 . 2008-04-14 12:41 8192 —-a-w- e:\windows2\system32\bitsprx2.dll
2009-08-05 04:06 . 2008-04-14 12:41 7168 —-a-w- e:\windows2\system32\bitsprx3.dll
2009-08-05 04:06 . 2008-04-14 06:09 438784 —-a-w- e:\windows2\system32\xpob2res.dll
2009-08-05 03:48 . 2009-08-05 03:48 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\Office Genuine Advantage
2009-08-05 03:31 . 2009-08-06 01:03 85128 —-a-w- e:\documents and settings\Deep\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 03:31 . 2009-08-05 03:31 ——– d—–w- e:\documents and settings\All Users.WINDOWS2\Application Data\Azureus
2009-08-05 03:31 . 2009-08-10 06:02 ——– d—–w- e:\documents and settings\Deep\Application Data\Azureus
2009-08-05 03:31 . 2009-08-05 03:31 ——– d—–w- e:\program files\Vuze
2009-08-05 03:31 . 2009-08-05 03:31 ——– d—–w- e:\program files\Common Files\i4j_jres
2009-08-05 03:30 . 2009-08-05 03:30 ——– d—–w- e:\program files\AskBarDis
2009-08-05 03:20 . 2009-08-05 03:20 0 —-a-w- e:\windows2\ativpsrm.bin
2009-08-05 03:07 . 2009-04-28 04:20 593920 —-a-w- e:\windows2\system32\ati2sgag.exe
2009-08-05 02:52 . 2009-08-05 02:52 ——– dc-h–w- e:\windows2\$MSI30UninstallMSI30-KB884016$

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-07 02:58 . 2009-08-05 01:03 86333 —-a-w- e:\windows2\PCHEALTH\HELPCTR\OfflineCache\index.dat
2009-08-06 15:05 . 2006-05-03 04:21 ——– d—–w- e:\program files\QuickTime
2009-08-05 19:05 . 2008-09-03 23:24 ——– d—–w- e:\program files\Common Files\Sonic Shared
2009-08-05 19:04 . 2008-09-03 23:24 ——– d—–w- e:\program files\Roxio
2009-08-05 09:01 . 2001-08-23 12:00 204800 —-a-w- e:\windows2\system32\mswebdvd.dll
2009-08-05 04:53 . 2005-02-24 05:31 ——– d–h–w- e:\program files\InstallShield Installation Information
2009-08-05 04:17 . 2005-07-21 02:03 ——– d—–w- e:\program files\Common Files\Macromedia
2009-08-05 04:17 . 2005-05-23 05:18 ——– d—–w- e:\program files\Common Files\InterVideo
2009-08-05 04:17 . 2008-03-13 01:00 ——– dcsh–w- e:\program files\Common Files\WindowsLiveInstaller
2009-08-05 04:17 . 2005-02-23 02:03 ——– d—–w- e:\program files\Google
2009-08-05 04:17 . 2006-08-20 01:31 ——– d—–w- e:\program files\HP
2009-08-05 04:17 . 2008-03-04 01:00 ——– d—–w- e:\program files\Microsoft Visual Studio 8
2009-08-05 04:17 . 2005-02-24 06:12 ——– d—–w- e:\program files\OfficeUpdate11
2009-08-05 04:17 . 2005-02-23 15:00 ——– d—–w- e:\program files\MSN Messenger
2009-08-05 04:17 . 2006-09-09 19:36 ——– d—–w- e:\program files\The Playa
2009-08-05 04:17 . 2006-07-14 00:27 ——– d—–w- e:\program files\Yahoo!
2009-08-05 04:17 . 2005-05-23 00:36 ——– d—–w- e:\program files\vso
2009-08-05 04:14 . 2005-02-24 05:21 ——– d—–w- e:\program files\Creative
2009-08-05 04:14 . 2009-08-05 04:14 444952 —-a-w- e:\windows2\system32\wrap_oal.dll
2009-08-05 04:14 . 2009-08-05 04:14 109080 —-a-w- e:\windows2\system32\OpenAL32.dll
2009-08-05 04:14 . 2009-08-05 04:14 ——– d—–w- e:\documents and settings\Deep\Application Data\Creative
2009-08-05 01:00 . 2009-08-05 01:00 21640 —-a-w- e:\windows2\system32\emptyregdb.dat
2009-07-31 15:57 . 2009-04-15 01:08 ——– d—–w- e:\program files\Microsoft Silverlight
2009-07-20 13:29 . 2006-10-06 00:42 ——– d—–w- d:\documents and settings\kuldip.KULDIP-WP3MGP0C\Application Data\Azureus
2009-07-17 19:01 . 2001-08-23 12:00 58880 —-a-w- e:\windows2\system32\atl.dll
2009-07-12 19:21 . 2004-08-04 07:56 233472 —-a-w- e:\windows2\system32\wmpdxm.dll
2009-07-03 17:09 . 2001-08-23 12:00 915456 —-a-w- e:\windows2\system32\wininet.dll
2009-06-26 16:50 . 2009-06-26 16:50 81920 ——w- e:\windows2\system32\ieencode.dll
2009-06-23 20:38 . 2009-06-23 20:38 15896 —-a-w- e:\windows2\system32\drivers\pfmodnt.sys
2009-06-23 20:38 . 2009-06-23 20:38 189464 —-a-w- e:\windows2\system32\drivers\haP17v2k.sys
2009-06-23 20:38 . 2009-06-23 20:38 162840 —-a-w- e:\windows2\system32\drivers\haP16v2k.sys
2009-06-23 20:38 . 2009-06-23 20:38 798744 —-a-w- e:\windows2\system32\drivers\ha10kx2k.sys
2009-06-23 20:37 . 2009-06-23 20:37 92696 —-a-w- e:\windows2\system32\drivers\emupia2k.sys
2009-06-23 20:37 . 2009-06-23 20:37 157208 —-a-w- e:\windows2\system32\drivers\ctsfm2k.sys
2009-06-23 20:37 . 2009-06-23 20:37 14360 —-a-w- e:\windows2\system32\drivers\ctprxy2k.sys
2009-06-23 20:37 . 2009-06-23 20:37 127512 —-a-w- e:\windows2\system32\drivers\ctoss2k.sys
2009-06-23 20:37 . 2009-06-23 20:37 1396120 —-a-w- e:\windows2\system32\drivers\CTMMFILT.SYS
2009-06-23 20:36 . 2009-06-23 20:36 18840 —-a-w- e:\windows2\system32\drivers\CTGAME.SYS
2009-06-23 20:36 . 2009-06-23 20:36 347080 —-a-w- e:\windows2\system32\drivers\ctdvda2k.sys
2009-06-23 20:36 . 2009-06-23 20:36 528408 —-a-w- e:\windows2\system32\drivers\ctaud2k.sys
2009-06-23 20:36 . 2009-06-23 20:36 511000 —-a-w- e:\windows2\system32\drivers\ctac32k.sys
2009-06-23 20:36 . 2009-06-23 20:36 1366424 —-a-w- e:\windows2\system32\drivers\CT0531FL.SYS
2009-06-23 20:35 . 2009-06-23 20:35 100888 —-a-w- e:\windows2\system32\drivers\CTERFXFX.sys
2009-06-23 20:34 . 2009-06-23 20:34 566296 —-a-w- e:\windows2\system32\drivers\CTSBLFX.sys
2009-06-23 20:34 . 2009-06-23 20:34 555032 —-a-w- e:\windows2\system32\drivers\CTAUDFX.sys
2009-06-23 20:34 . 2009-06-23 20:34 99352 —-a-w- e:\windows2\system32\drivers\COMMONFX.sys
2009-06-23 18:51 . 2009-06-23 18:51 43520 —-a-w- e:\windows2\system32\CTBurst.dll
2009-06-23 18:50 . 2009-06-23 18:50 11776 —-a-w- e:\windows2\system32\inres.dll
2009-06-23 18:50 . 2009-06-23 18:50 11776 —-a-w- e:\windows2\INRES.DLL
2009-06-23 18:50 . 2009-06-23 18:50 86528 —-a-w- e:\windows2\system32\ctcoinst.dll
2009-06-23 18:50 . 2009-06-23 18:50 182272 —-a-w- e:\windows2\system32\ctdvinst.dll
2009-06-23 18:49 . 2009-06-23 18:49 10752 —-a-w- e:\windows2\system32\a3d.dll
2009-06-23 18:48 . 2009-06-23 18:48 11776 —-a-w- e:\windows2\system32\ac3api.dll
2009-06-23 18:48 . 2009-06-23 18:48 38400 —-a-w- e:\windows2\system32\readreg.exe
2009-06-23 18:48 . 2009-06-23 18:48 37888 —-a-w- e:\windows2\system32\psconv.exe
2009-06-23 18:48 . 2009-06-23 18:48 19456 —-a-w- e:\windows2\system32\CtHelper.exe
2009-06-23 18:48 . 2009-06-23 18:48 8704 —-a-w- e:\windows2\system32\ctagent.dll
2009-06-23 18:48 . 2009-06-23 18:48 45568 —-a-w- e:\windows2\system32\ctspkhlp.dll
2009-06-23 18:47 . 2009-06-23 18:47 56832 —-a-w- e:\windows2\system32\CTpcmcia.dll
2009-06-23 18:47 . 2009-06-23 18:47 12800 —-a-w- e:\windows2\system32\ctmmep.dll
2009-06-23 18:46 . 2009-06-23 18:46 9216 —-a-w- e:\windows2\system32\ctpres.dll
2009-06-23 18:46 . 2009-06-23 18:46 9216 —-a-w- e:\windows2\CTPRES.DLL
2009-06-23 18:46 . 2009-06-23 18:46 32768 —-a-w- e:\windows2\system32\ctthxcal.dll
2009-06-23 18:46 . 2009-06-23 18:46 41472 —-a-w- e:\windows2\system32\ctscal.dll
2009-06-23 18:46 . 2009-06-23 18:46 131072 —-a-w- e:\windows2\system32\ctdcifce.dll
2009-06-23 18:46 . 2009-06-23 18:46 330752 —-a-w- e:\windows2\system32\ctdc0001.dll
2009-06-23 18:46 . 2009-06-23 18:46 227840 —-a-w- e:\windows2\system32\ctdc0000.dll
2009-06-23 18:46 . 2009-06-23 18:46 10240 —-a-w- e:\windows2\system32\ctdcres.dll
2009-06-23 18:46 . 2009-06-23 18:46 10240 —-a-w- e:\windows2\CTDCRES.DLL
2009-06-23 18:28 . 2009-06-23 18:28 51787 —-a-w- e:\windows2\system32\ctdlang.dat
2009-06-23 18:28 . 2009-06-23 18:28 386852 —-a-w- e:\windows2\system32\ctdnlstr.dat
2009-06-23 18:28 . 2009-06-23 18:28 196096 —-a-w- e:\windows2\system32\ctemupia.dll
2009-06-23 18:24 . 2009-06-23 18:24 176128 —-a-w- e:\windows2\system32\ct_oal.dll
2009-06-23 18:24 . 2009-06-23 18:24 46592 —-a-w- e:\windows2\system32\ctasio.dll
2009-06-23 18:24 . 2009-06-23 18:24 49152 —-a-w- e:\windows2\system32\ctdproxy.dll
2009-06-23 18:23 . 2009-06-23 18:23 69632 —-a-w- e:\windows2\system32\ctosuser.dll
2009-06-23 18:23 . 2009-06-23 18:23 6144 —-a-w- e:\windows2\system32\sfman32.dll
2009-06-23 18:23 . 2009-06-23 18:23 125952 —-a-w- e:\windows2\system32\sfms32.dll
2009-06-23 18:23 . 2009-06-23 18:23 13312 —-a-w- e:\windows2\system32\regplib.exe
2009-06-23 18:23 . 2009-06-23 18:23 64512 —-a-w- e:\windows2\system32\piaproxy.dll
2009-06-23 18:22 . 2009-06-23 18:22 149838 —-a-w- e:\windows2\system32\ctbas2w.dat
2009-06-23 18:20 . 2009-06-23 18:20 274587 —-a-w- e:\windows2\system32\ctsbas2w.dat
2009-06-23 18:20 . 2009-06-23 18:20 241084 —-a-w- e:\windows2\system32\CTSBASW.DAT
2009-06-23 18:20 . 2009-06-23 18:20 115166 —-a-w- e:\windows2\system32\CTBASICW.DAT
2009-06-23 18:20 . 2009-06-23 18:20 53932 —-a-w- e:\windows2\system32\ctdaught.dat
2009-06-23 18:20 . 2009-06-23 18:20 313207 —-a-w- e:\windows2\system32\ctstatic.dat
2009-06-23 18:20 . 2009-06-23 18:20 5120 —-a-w- e:\windows2\system32\enlocstr.exe
2009-06-23 18:20 . 2009-06-23 18:20 10240 —-a-w- e:\windows2\system32\killapps.exe
2009-06-23 18:19 . 2009-06-23 18:19 28672 —-a-w- e:\windows2\system32\MIDIDEF.EXE
2009-06-23 18:19 . 2009-06-23 18:19 33792 —-a-w- e:\windows2\system32\devreg.dll
2009-06-16 14:36 . 2001-08-23 12:00 81920 —-a-w- e:\windows2\system32\fontsub.dll
2009-06-16 14:36 . 2001-08-23 12:00 119808 —-a-w- e:\windows2\system32\t2embed.dll
2009-06-12 12:31 . 2001-08-23 12:00 80896 —-a-w- e:\windows2\system32\tlntsess.exe
2009-06-12 12:31 . 2001-08-23 12:00 76288 —-a-w- e:\windows2\system32\telnet.exe
2009-06-12 04:10 . 2009-06-12 04:10 47104 —-a-w- e:\windows2\system32\udapld32.dll
2009-06-12 04:10 . 2009-06-12 04:10 508928 —-a-w- e:\windows2\system32\UDAAPO32.dll
2009-06-10 16:19 . 2009-08-05 00:59 2066432 —-a-w- e:\windows2\system32\mstscax.dll
2009-06-10 14:13 . 2001-08-23 12:00 84992 —-a-w- e:\windows2\system32\avifil32.dll
2009-06-10 06:14 . 2001-08-23 12:00 132096 —-a-w- e:\windows2\system32\wkssvc.dll
2009-06-03 19:09 . 2001-08-23 12:00 1291264 —-a-w- e:\windows2\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 19:47 333192 —-a-w- e:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "e:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "e:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="e:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Creative Detector"="d:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-03 102400]
"DownloadAccelerator"="d:\program files\DAP\DAP.EXE" [2009-08-08 2754048]
"ctfmon.exe"="e:\windows2\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"RoxWatchTray"="e:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-08-06 149280]
"AVG8_TRAY"="e:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-12 2007832]
"FileZilla Server Interface"="d:\program files\FileZilla Server\FileZilla Server Interface.exe" [2009-06-21 1226240]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"CTHelper"="CTHELPER.EXE" - e:\windows2\system32\CtHelper.exe [2009-06-23 19456]

e:\documents and settings\All Users.WINDOWS2\Start Menu\Programs\Startup\
Desktop Manager.lnk - d:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2007-11-12 1447184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-06 16:29 11952 —-a-w- e:\windows2\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"e:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"e:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"e:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"e:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Program Files\\Messenger\\msmsgs.exe"=

R0 AvgRkx86;avgrkx86.sys;e:\windows2\system32\drivers\avgrkx86.sys [8/6/2009 9:29 AM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;e:\windows2\system32\drivers\avgldx86.sys [8/6/2009 9:29 AM 335240]
R1 AvgTdiX;AVG8 Network Redirector;e:\windows2\system32\drivers\avgtdix.sys [8/6/2009 9:29 AM 108552]
R2 ASKService;ASKService;e:\program files\AskBarDis\bar\bin\AskService.exe [8/4/2009 8:30 PM 464264]
R2 ASKUpgrade;ASKUpgrade;e:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [8/4/2009 8:31 PM 234888]
R2 avg8wd;AVG8 WatchDog;e:\progra~1\AVG\AVG8\avgwdsvc.exe [8/6/2009 9:28 AM 297752]
R2 avgfws8;AVG8 Firewall;e:\progra~1\AVG\AVG8\avgfws8.exe [8/6/2009 9:28 AM 1370488]
R3 Avgfwdx;Avgfwdx;e:\windows2\system32\drivers\avgfwdx.sys [8/6/2009 9:27 AM 29208]
R3 COMMONFX.SYS;COMMONFX.SYS;e:\windows2\system32\drivers\COMMONFX.sys [6/23/2009 1:34 PM 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;e:\windows2\system32\drivers\CTAUDFX.sys [6/23/2009 1:34 PM 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;e:\windows2\system32\drivers\CTSBLFX.sys [6/23/2009 1:34 PM 566296]
S3 Avgfwfd;AVG network filter service;e:\windows2\system32\drivers\avgfwdx.sys [8/6/2009 9:27 AM 29208]
S3 COMMONFX;COMMONFX;e:\windows2\system32\drivers\COMMONFX.sys [6/23/2009 1:34 PM 99352]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;e:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [8/4/2009 9:15 PM 79360]
S3 CTAUDFX;CTAUDFX;e:\windows2\system32\drivers\CTAUDFX.sys [6/23/2009 1:34 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;e:\windows2\system32\drivers\CTERFXFX.sys [6/23/2009 1:35 PM 100888]
S3 CTERFXFX;CTERFXFX;e:\windows2\system32\drivers\CTERFXFX.sys [6/23/2009 1:35 PM 100888]
S3 CTSBLFX;CTSBLFX;e:\windows2\system32\drivers\CTSBLFX.sys [6/23/2009 1:34 PM 566296]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"e:\windows2\system32\rundll32.exe" "e:\windows2\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-14 e:\windows2\Tasks\AppleSoftwareUpdate.job
- e:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Clean Traces - d:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - d:\program files\DAP\dapextie.htm
IE: Download &all with DAP - d:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} - file://f:\content\include\XPPatchInstaller.CAB
FF - ProfilePath - e:\documents and settings\Deep\Application Data\Mozilla\Firefox\Profiles\fuq9teiy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.cbc.ca/
FF - component: d:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - component: e:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: d:\program files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: d:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: d:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npmozax.dll

—- FIREFOX POLICIES —-
e:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
e:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
e:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
e:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-18 14:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(800)
e:\windows2\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2852)
e:\windows2\system32\WININET.dll
e:\windows2\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
e:\windows2\system32\ieframe.dll
e:\windows2\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
e:\windows2\system32\ati2evxx.exe
e:\windows2\system32\ati2evxx.exe
e:\program files\Creative\Shared Files\CTAudSvc.exe
e:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
e:\program files\Bonjour\mDNSResponder.exe
e:\windows2\system32\CTSVCCDA.EXE
d:\program files\FileZilla Server\FileZilla Server.exe
d:\program files\Java\jre6\bin\jqs.exe
e:\progra~1\AVG\AVG8\avgam.exe
e:\progra~1\AVG\AVG8\avgrsx.exe
e:\windows2\system32\wdfmgr.exe
e:\program files\iPod\bin\iPodService.exe
e:\program files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
e:\program files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
e:\progra~1\AVG\AVG8\avgnsx.exe
.
**************************************************************************
.
Completion time: 2009-08-18 14:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-18 21:52

Pre-Run: 20,897,419,264 bytes free
Post-Run: 21,239,025,664 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS2
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS2="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect

453
RootRepeal will not run. I have downloaded from all three locations and have tried. I get a low virtual memory error.
Pay a visit to the ESET Online Scanner - IE is preferred for this.
  • Click the ESET Online Scanner button, read the info in the new window, check the appropriate box and click Start.
  • Accept the ActiveX download, and allow it to install.
  • Once this has been completed, you will see the Computer Scan settings page - ensure that you uncheck the "Remove found threats" box and then click Start.
  • The virus signature database will now need to be downloaded, so don't forget to instruct your firewall to permit it if it asks.
  • The above will take a little time, so now is a good time to fire up the kettle and open the biccies.
  • Once the scan has completed you will be shown the results - assuming that the scanner has found anything.
  • Click List of found threats and then Export to text file… and save the log somewhere convenient.
  • You can then close out the scanner - don't bother uninstalling it as you may need to use it again.
  • Please post the contents of this file in your next reply, or let me know that nothing was identified.
Given that you have MBAM already installed, i'd like one last check of your system and then that should be you done.
  • Make sure that you have updated MBAM before you scan - seems a shame not to have the latest defs.
  • Once the program has loaded, select Perform full scan and then Scan.
  • When the scan has finished, click OK and then Show Results to view the results - no surprise there!
  • If MBAM finds anything, check the box(es) and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Let me have the MBAM log, a fresh HJT log (run in Normal Mode) AND a description of how your PC is behaving.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI