This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Slow internet connection and update

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

In the past couple of days my internet connection has been running lethargically slow. In the past month or so I've not been able to connect to Windows Update at all to update my OS and have been having severe intermittent problems when connecting to Yahoo! to check mail and such.

Below you can find my log from HiJack This and thanks in advance for any help you can give me. Feel free to e-mail me directly if needed.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:55:20 AM, on 8/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Program Files\Cricket\QuickLink Mobile\QuickLink Mobile.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\BOINC\boinc.exe
C:\DOCUME~1\Steve\LOCALS~1\Temp\zauninst.exe
C:\DOCUME~1\Steve\LOCALS~1\Temp\GLB89.tmp
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\GetRight\GetRight.exe
C:\Documents and Settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: {C7E37AC6-FFE7-4D90-BE70-CF7E3456DFB4} - - (no file)
R3 - URLSearchHook: (no name) - 03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
R3 - URLSearchHook: (no name) - EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - 06663B56-0D73-4f9f-BCC5-4AA941470AFD} - (no file)
R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Pando Search Assistant BHO - {06663B51-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: EmailBHO - {647FD14A-C4F1-46F4-8FC3-0B40F54226F7} - C:\Program Files\jZip\WebmailPlugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Pando Toolbar BHO - {E3EA4FD1-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Pando Toolbar - {E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\Program Files\Webshots\WSToolbar4IE.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O4 - HKLM\..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [boinctray] "C:\Program Files\BOINC\boinctray.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Startup: QuickLink Mobile.lnk = C:\Program Files\Cricket\QuickLink Mobile\QuickLink Mobile.exe
O4 - Global Startup: GetRight.lnk = C:\Program Files\GetRight\GetRight.exe
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstall…&expId=6211
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Elf%20Bowling%20Holiday%20Pack/Images/stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233774010406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233773870562
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Elf%20Bowling%20Holiday%20Pack/Images/armhelper.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://l.yimg.com/jh/games/web_games/popca…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1CC25AA2-E1AA-4532-BD88-5194DB967928}: NameServer = 172.28.221.53 172.28.221.54
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c9ac3fd88d18d4) (gupdate1c9ac3fd88d18d4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IS360service - Unknown owner - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 1: Amazon.com: Books: How to Remodel a Man : Tips and Techniques on Accomplishing Something You Know Is Impossible but Want to Try Anyway - http://www.amazon.com/gp/reader/031233317X…124#reader-page

–
End of file - 15669 bytes
Please do the following:

NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi,

Please do the following:

Download ComboFix from either of these locations:
Link 1
Link 2


VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Ran ComboFix. Please find the results attached below. Connection is still running slow and unable to access Windows Update.

ComboFix 09-08-25.05 - Steve 08/26/2009 18:37.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.759.231 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix-001.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common Files\Real\WeatherBug\MiniBugTransporter.dll
c:\program files\PandoBar
c:\program files\PandoBar\bar\1.bin\NPPANDBR.DLL
c:\program files\PandoBar\bar\1.bin\P4FFXTBR.JAR
c:\program files\PandoBar\bar\1.bin\P4FFXTBR.MANIFEST
c:\program files\PandoBar\bar\1.bin\P4HIGHIN.EXE
c:\program files\PandoBar\bar\1.bin\P4NTSTBR.JAR
c:\program files\PandoBar\bar\1.bin\P4NTSTBR.MANIFEST
c:\program files\PandoBar\bar\1.bin\P4PLUGIN.DLL
c:\program files\PandoBar\bar\1.bin\PANDOBAR.DLL
c:\program files\PandoBar\bar\Cache\000D7CE1
c:\program files\PandoBar\bar\Cache\007F29A6
c:\program files\PandoBar\bar\Cache\01D41C0F.bin
c:\program files\PandoBar\bar\Cache\01D42016.bin
c:\program files\PandoBar\bar\Cache\01D423FE.bin
c:\program files\PandoBar\bar\Cache\01D427E6.bin
c:\program files\PandoBar\bar\Cache\01D42B9F.bin
c:\program files\PandoBar\bar\Cache\01D43052.bin
c:\program files\PandoBar\bar\Cache\01D4337F.bin
c:\program files\PandoBar\bar\Cache\files.ini
c:\program files\PandoBar\bar\History\search2
c:\program files\PandoBar\bar\Settings\prevcfg2.htm
c:\program files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL
c:\recycler\S-1-5-21-3988116235-3883230983-1993404451-1003
c:\windows\cdmxtras
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Fonts\acrsec.fon
c:\windows\Installer\13704efb.msi
c:\windows\Installer\13c58.msi
c:\windows\Installer\245a382.msi
c:\windows\Installer\245a383.msp
c:\windows\Installer\245a384.msp
c:\windows\Installer\245a385.msp
c:\windows\Installer\245a386.msp
c:\windows\Installer\245a387.msp
c:\windows\Installer\245a388.msp
c:\windows\Installer\245a389.msp
c:\windows\Installer\245a38a.msp
c:\windows\Installer\245a38b.msp
c:\windows\Installer\b13dece.msi
c:\windows\Ir5_ad.dll
c:\windows\iwlufklg.dll
c:\windows\system32\cache329
c:\windows\system32\cache329\B_329_0_0_106800.htm
c:\windows\system32\cache329\B_329_0_0_107400.htm
c:\windows\system32\cache329\B_329_0_1_503300.htm
c:\windows\system32\cache329\B_329_0_1_503300.swf
c:\windows\system32\cache329\B_329_0_1_515400.htm
c:\windows\system32\cache329\B_329_0_1_515400.swf
c:\windows\system32\cache329\B_329_0_1_516600.htm
c:\windows\system32\cache329\B_329_0_1_516600.swf
c:\windows\system32\cache329\B_329_0_1_517400.htm
c:\windows\system32\cache329\B_329_0_1_517400.swf
c:\windows\system32\cache329\B_329_0_1_518400.htm
c:\windows\system32\cache329\B_329_0_1_518400.swf
c:\windows\system32\cache329\B_329_0_1_519100.htm
c:\windows\system32\cache329\B_329_0_1_519100.swf
c:\windows\system32\cache329\B_329_0_1_519600.htm
c:\windows\system32\cache329\B_329_0_1_519600.swf
c:\windows\system32\cache329\B_329_0_1_521100.htm
c:\windows\system32\cache329\B_329_0_1_521100.swf
c:\windows\system32\cache329\B_329_0_1_523600.htm
c:\windows\system32\cache329\B_329_0_1_523600.swf
c:\windows\system32\cache329\B_329_0_1_526100.htm
c:\windows\system32\cache329\B_329_0_1_526100.swf
c:\windows\system32\cache329\B_329_0_1_526300.htm
c:\windows\system32\cache329\B_329_0_1_526300.swf
c:\windows\system32\cache329\B_329_0_1_526700.htm
c:\windows\system32\cache329\B_329_0_1_526700.swf
c:\windows\system32\cache329\B_329_0_1_526900.htm
c:\windows\system32\cache329\B_329_0_1_526900.swf
c:\windows\system32\cache329\B_329_0_1_527900.htm
c:\windows\system32\cache329\B_329_0_1_527900.swf
c:\windows\system32\cache329\B_329_0_1_529300.htm
c:\windows\system32\cache329\B_329_0_1_529300.swf
c:\windows\system32\cache329\B_329_0_1_531800.htm
c:\windows\system32\cache329\B_329_0_1_531800.swf
c:\windows\system32\cache329\B_329_0_1_554500.htm
c:\windows\system32\cache329\B_329_0_1_554500.swf
c:\windows\system32\cache329\B_329_0_1_559500.htm
c:\windows\system32\cache329\B_329_0_1_559500.swf
c:\windows\system32\cache329\B_329_0_1_561500.htm
c:\windows\system32\cache329\B_329_0_1_561500.swf
c:\windows\system32\cache329\B_329_0_1_569900.htm
c:\windows\system32\cache329\B_329_0_1_569900.swf
c:\windows\system32\cache329\B_329_0_1_570100.htm
c:\windows\system32\cache329\B_329_0_1_570100.swf
c:\windows\system32\cache329\B_329_0_1_571100.htm
c:\windows\system32\cache329\B_329_0_1_571100.swf
c:\windows\system32\cache329\B_329_0_1_572700.htm
c:\windows\system32\cache329\B_329_0_1_572700.swf
c:\windows\system32\cache329\B_329_0_1_572900.htm
c:\windows\system32\cache329\B_329_0_1_572900.swf
c:\windows\system32\cache329\B_329_0_1_573100.htm
c:\windows\system32\cache329\B_329_0_1_573100.swf
c:\windows\system32\cache329\B_329_0_1_574200.htm
c:\windows\system32\cache329\B_329_0_1_574200.swf
c:\windows\system32\cache329\B_329_0_1_586100.gif
c:\windows\system32\cache329\B_329_0_1_591600.htm
c:\windows\system32\cache329\B_329_0_1_591600.swf
c:\windows\system32\cache329\B_329_0_1_599300.gif
c:\windows\system32\cache329\B_329_0_1_602100.htm
c:\windows\system32\cache329\B_329_0_1_602100.swf
c:\windows\system32\cache329\B_329_0_1_604400.htm
c:\windows\system32\cache329\B_329_0_1_604400.swf
c:\windows\system32\cache329\B_329_0_1_605500.htm
c:\windows\system32\cache329\B_329_0_1_605500.swf
c:\windows\system32\cache329\B_329_0_1_611400.htm
c:\windows\system32\cache329\B_329_0_1_611400.swf
c:\windows\system32\cache329\B_329_0_1_618300.htm
c:\windows\system32\cache329\B_329_0_1_618300.swf
c:\windows\system32\cache329\B_329_0_1_621600.htm
c:\windows\system32\cache329\B_329_0_1_621600.swf
c:\windows\system32\cache329\B_329_0_1_622000.htm
c:\windows\system32\cache329\B_329_0_1_622000.swf
c:\windows\system32\cache329\B_329_0_1_623500.gif
c:\windows\system32\cache329\B_329_0_1_630000.htm
c:\windows\system32\cache329\B_329_0_1_630000.swf
c:\windows\system32\cache329\B_329_0_1_630600.htm
c:\windows\system32\cache329\B_329_0_1_630600.swf
c:\windows\system32\cache329\B_329_0_1_630700.htm
c:\windows\system32\cache329\B_329_0_1_630700.swf
c:\windows\system32\cache329\B_329_0_1_630800.htm
c:\windows\system32\cache329\B_329_0_1_630800.swf
c:\windows\system32\cache329\B_329_0_1_630900.htm
c:\windows\system32\cache329\B_329_0_1_630900.swf
c:\windows\system32\cache329\B_329_0_1_631100.htm
c:\windows\system32\cache329\B_329_0_1_631100.swf
c:\windows\system32\cache329\B_329_0_1_639000.htm
c:\windows\system32\cache329\B_329_0_1_639000.swf
c:\windows\system32\cache329\B_329_0_1_639200.htm
c:\windows\system32\cache329\B_329_0_1_639200.swf
c:\windows\system32\cache329\B_329_0_1_639500.htm
c:\windows\system32\cache329\B_329_0_1_639500.swf
c:\windows\system32\cache329\B_329_0_1_639600.htm
c:\windows\system32\cache329\B_329_0_1_639600.swf
c:\windows\system32\cache329\B_329_0_1_647600.gif
c:\windows\system32\cache329\B_329_0_1_651200.htm
c:\windows\system32\cache329\B_329_0_1_651200.swf
c:\windows\system32\cache329\B_329_0_1_653300.htm
c:\windows\system32\cache329\B_329_0_1_653300.swf
c:\windows\system32\cache329\B_329_0_1_653400.htm
c:\windows\system32\cache329\B_329_0_1_653400.swf
c:\windows\system32\cache329\B_329_0_1_653800.gif
c:\windows\system32\cache329\B_329_0_1_657200.gif
c:\windows\system32\cache329\B_329_0_1_659200.htm
c:\windows\system32\cache329\B_329_0_1_659200.swf
c:\windows\system32\cache329\B_329_0_1_659700.htm
c:\windows\system32\cache329\B_329_0_1_659700.swf
c:\windows\system32\cache329\B_329_0_1_659800.htm
c:\windows\system32\cache329\B_329_0_1_659800.swf
c:\windows\system32\cache329\B_329_0_1_660300.htm
c:\windows\system32\cache329\B_329_0_1_660300.swf
c:\windows\system32\cache329\B_329_0_1_660800.htm
c:\windows\system32\cache329\B_329_0_1_660800.swf
c:\windows\system32\cache329\B_329_0_1_668900.htm
c:\windows\system32\cache329\B_329_0_1_668900.swf
c:\windows\system32\cache329\B_329_0_1_672100.htm
c:\windows\system32\cache329\B_329_0_1_672100.swf
c:\windows\system32\cache329\B_329_0_1_672300.htm
c:\windows\system32\cache329\B_329_0_1_672300.swf
c:\windows\system32\cache329\B_329_0_1_672600.htm
c:\windows\system32\cache329\B_329_0_1_672600.swf
c:\windows\system32\cache329\B_329_0_1_673700.htm
c:\windows\system32\cache329\B_329_0_1_673700.swf
c:\windows\system32\cache329\B_329_0_1_674500.htm
c:\windows\system32\cache329\B_329_0_1_674500.swf
c:\windows\system32\cache329\B_329_0_1_678600.htm
c:\windows\system32\cache329\B_329_0_1_678600.swf
c:\windows\system32\cache329\B_329_0_1_688200.htm
c:\windows\system32\cache329\B_329_0_1_688200.swf
c:\windows\system32\cache329\B_329_0_1_697700.htm
c:\windows\system32\cache329\B_329_0_1_697700.swf
c:\windows\system32\cache329\B_329_0_1_699800.htm
c:\windows\system32\cache329\B_329_0_1_699800.swf
c:\windows\system32\cache329\B_329_0_1_708400.htm
c:\windows\system32\cache329\B_329_0_1_708400.swf
c:\windows\system32\cache329\B_329_0_2_591600.htm
c:\windows\system32\cache329\B_329_0_2_591600.swf
c:\windows\system32\cache329\B_329_0_2_599500.gif
c:\windows\system32\cache329\B_329_0_2_599600.htm
c:\windows\system32\cache329\B_329_0_2_599600.swf
c:\windows\system32\cache329\B_329_0_2_600800.gif
c:\windows\system32\cache329\B_329_0_2_611400.htm
c:\windows\system32\cache329\B_329_0_2_611400.swf
c:\windows\system32\cache329\B_329_0_2_658500.gif
c:\windows\system32\cache329\B_329_0_2_668500.htm
c:\windows\system32\cache329\B_329_0_2_668500.swf
c:\windows\system32\cache329\B_329_0_2_674300.htm
c:\windows\system32\cache329\B_329_0_2_674300.swf
c:\windows\system32\cache329\B_329_0_2_775900.htm
c:\windows\system32\cache329\B_329_0_2_775900.swf
c:\windows\system32\cache329\B_329_0_3_621800.htm
c:\windows\system32\cache329\B_329_0_3_621800.swf
c:\windows\system32\cache329\B_329_0_4_617800.htm
c:\windows\system32\cache329\B_329_0_4_617800.swf
c:\windows\system32\cache329\B_329_0_4_618100.htm
c:\windows\system32\cache329\B_329_0_4_618100.swf
c:\windows\system32\cache329\B_329_0_4_625100.htm
c:\windows\system32\cache329\B_329_0_4_625100.swf
c:\windows\system32\cache329\B_329_0_4_650500.htm
c:\windows\system32\cache329\B_329_0_4_650500.swf
c:\windows\system32\cache329\B_329_1_0_449200.gif
c:\windows\system32\cache329\B_329_1_0_449600.gif
c:\windows\system32\cache329\B_329_1_0_454300.gif
c:\windows\system32\cache329\B_329_2_0_106800.htm
c:\windows\system32\cache329\B_329_2_0_107400.htm
c:\windows\system32\cache329\B_329_2_1_515400.htm
c:\windows\system32\cache329\B_329_2_1_515400.swf
c:\windows\system32\cache329\B_329_2_1_517400.htm
c:\windows\system32\cache329\B_329_2_1_517400.swf
c:\windows\system32\cache329\B_329_2_1_521400.htm
c:\windows\system32\cache329\B_329_2_1_521400.swf
c:\windows\system32\cache329\B_329_2_1_522900.htm
c:\windows\system32\cache329\B_329_2_1_522900.swf
c:\windows\system32\cache329\B_329_2_1_523600.htm
c:\windows\system32\cache329\B_329_2_1_523600.swf
c:\windows\system32\cache329\B_329_2_1_523700.htm
c:\windows\system32\cache329\B_329_2_1_523700.swf
c:\windows\system32\cache329\B_329_2_1_524200.htm
c:\windows\system32\cache329\B_329_2_1_524200.swf
c:\windows\system32\cache329\B_329_2_1_526100.htm
c:\windows\system32\cache329\B_329_2_1_526100.swf
c:\windows\system32\cache329\B_329_2_1_526300.htm
c:\windows\system32\cache329\B_329_2_1_526300.swf
c:\windows\system32\cache329\B_329_2_1_526700.htm
c:\windows\system32\cache329\B_329_2_1_526700.swf
c:\windows\system32\cache329\B_329_2_1_526900.htm
c:\windows\system32\cache329\B_329_2_1_526900.swf
c:\windows\system32\cache329\B_329_2_1_527900.htm
c:\windows\system32\cache329\B_329_2_1_527900.swf
c:\windows\system32\cache329\B_329_2_1_529300.htm
c:\windows\system32\cache329\B_329_2_1_529300.swf
c:\windows\system32\cache329\B_329_2_1_531800.htm
c:\windows\system32\cache329\B_329_2_1_531800.swf
c:\windows\system32\cache329\B_329_2_1_554500.htm
c:\windows\system32\cache329\B_329_2_1_554500.swf
c:\windows\system32\cache329\B_329_2_1_559500.htm
c:\windows\system32\cache329\B_329_2_1_559500.swf
c:\windows\system32\cache329\B_329_2_1_561500.htm
c:\windows\system32\cache329\B_329_2_1_561500.swf
c:\windows\system32\cache329\B_329_2_1_569900.htm
c:\windows\system32\cache329\B_329_2_1_569900.swf
c:\windows\system32\cache329\B_329_2_1_570100.htm
c:\windows\system32\cache329\B_329_2_1_570100.swf
c:\windows\system32\cache329\B_329_2_1_571100.htm
c:\windows\system32\cache329\B_329_2_1_571100.swf
c:\windows\system32\cache329\B_329_2_1_572700.htm
c:\windows\system32\cache329\B_329_2_1_572700.swf
c:\windows\system32\cache329\B_329_2_1_572900.htm
c:\windows\system32\cache329\B_329_2_1_572900.swf
c:\windows\system32\cache329\B_329_2_1_574200.htm
c:\windows\system32\cache329\B_329_2_1_574200.swf
c:\windows\system32\cache329\B_329_2_1_586100.gif
c:\windows\system32\cache329\B_329_2_1_591600.htm
c:\windows\system32\cache329\B_329_2_1_591600.swf
c:\windows\system32\cache329\B_329_2_1_599300.gif
c:\windows\system32\cache329\B_329_2_1_602100.htm
c:\windows\system32\cache329\B_329_2_1_602100.swf
c:\windows\system32\cache329\B_329_2_1_611400.htm
c:\windows\system32\cache329\B_329_2_1_611400.swf
c:\windows\system32\cache329\B_329_2_1_630700.htm
c:\windows\system32\cache329\B_329_2_1_630700.swf
c:\windows\system32\cache329\B_329_2_1_630800.htm
c:\windows\system32\cache329\B_329_2_1_630800.swf
c:\windows\system32\cache329\B_329_2_1_630900.htm
c:\windows\system32\cache329\B_329_2_1_630900.swf
c:\windows\system32\cache329\B_329_2_1_631100.htm
c:\windows\system32\cache329\B_329_2_1_631100.swf
c:\windows\system32\cache329\B_329_2_1_639000.htm
c:\windows\system32\cache329\B_329_2_1_639000.swf
c:\windows\system32\cache329\B_329_2_1_639200.htm
c:\windows\system32\cache329\B_329_2_1_639200.swf
c:\windows\system32\cache329\B_329_2_1_639500.htm
c:\windows\system32\cache329\B_329_2_1_639500.swf
c:\windows\system32\cache329\B_329_2_1_639600.htm
c:\windows\system32\cache329\B_329_2_1_639600.swf
c:\windows\system32\cache329\B_329_2_1_651200.htm
c:\windows\system32\cache329\B_329_2_1_651200.swf
c:\windows\system32\cache329\B_329_2_1_653300.htm
c:\windows\system32\cache329\B_329_2_1_653300.swf
c:\windows\system32\cache329\B_329_2_1_653400.htm
c:\windows\system32\cache329\B_329_2_1_653400.swf
c:\windows\system32\cache329\B_329_2_1_653800.gif
c:\windows\system32\cache329\B_329_2_1_659200.htm
c:\windows\system32\cache329\B_329_2_1_659200.swf
c:\windows\system32\cache329\B_329_2_1_659700.htm
c:\windows\system32\cache329\B_329_2_1_659700.swf
c:\windows\system32\cache329\B_329_2_1_659800.htm
c:\windows\system32\cache329\B_329_2_1_659800.swf
c:\windows\system32\cache329\B_329_2_1_660300.htm
c:\windows\system32\cache329\B_329_2_1_660300.swf
c:\windows\system32\cache329\B_329_2_1_660800.htm
c:\windows\system32\cache329\B_329_2_1_660800.swf
c:\windows\system32\cache329\B_329_2_1_672600.htm
c:\windows\system32\cache329\B_329_2_1_672600.swf
c:\windows\system32\cache329\B_329_2_1_673700.htm
c:\windows\system32\cache329\B_329_2_1_673700.swf
c:\windows\system32\cache329\B_329_2_1_674500.htm
c:\windows\system32\cache329\B_329_2_1_674500.swf
c:\windows\system32\cache329\B_329_2_1_678600.htm
c:\windows\system32\cache329\B_329_2_1_678600.swf
c:\windows\system32\cache329\B_329_2_1_688200.htm
c:\windows\system32\cache329\B_329_2_1_688200.swf
c:\windows\system32\cache329\B_329_2_1_697700.htm
c:\windows\system32\cache329\B_329_2_1_697700.swf
c:\windows\system32\cache329\B_329_2_1_699800.htm
c:\windows\system32\cache329\B_329_2_1_699800.swf
c:\windows\system32\cache329\B_329_2_1_708400.htm
c:\windows\system32\cache329\B_329_2_1_708400.swf
c:\windows\system32\cache329\B_329_2_2_549100.gif
c:\windows\system32\cache329\B_329_2_2_550200.gif
c:\windows\system32\cache329\B_329_2_2_591600.htm
c:\windows\system32\cache329\B_329_2_2_591600.swf
c:\windows\system32\cache329\B_329_2_2_599500.gif
c:\windows\system32\cache329\B_329_2_2_599600.htm
c:\windows\system32\cache329\B_329_2_2_599600.swf
c:\windows\system32\cache329\B_329_2_2_600800.gif
c:\windows\system32\cache329\B_329_2_2_611400.htm
c:\windows\system32\cache329\B_329_2_2_611400.swf
c:\windows\system32\cache329\B_329_2_2_658500.gif
c:\windows\system32\cache329\B_329_2_2_668500.htm
c:\windows\system32\cache329\B_329_2_2_668500.swf
c:\windows\system32\cache329\B_329_2_2_674300.htm
c:\windows\system32\cache329\B_329_2_2_674300.swf
c:\windows\system32\cache329\B_329_2_2_775900.htm
c:\windows\system32\cache329\B_329_2_2_775900.swf
c:\windows\system32\cache329\B_329_2_3_605100.gif
c:\windows\system32\cache329\B_329_2_3_621800.htm
c:\windows\system32\cache329\B_329_2_3_621800.swf
c:\windows\system32\cache329\B_329_2_4_617800.htm
c:\windows\system32\cache329\B_329_2_4_617800.swf
c:\windows\system32\cache329\B_329_2_4_618100.htm
c:\windows\system32\cache329\B_329_2_4_618100.swf
c:\windows\system32\cache329\B_329_2_4_621900.gif
c:\windows\system32\cache329\B_329_2_4_625100.htm
c:\windows\system32\cache329\B_329_2_4_625100.swf
c:\windows\system32\cache329\B_329_2_4_650500.htm
c:\windows\system32\cache329\B_329_2_4_650500.swf
c:\windows\system32\cache329\B_329_2_4_700300.htm
c:\windows\system32\cache329\B_329_2_4_700300.jpg
c:\windows\system32\cache329\B_329_3_0_106800.htm
c:\windows\system32\cache329\B_329_3_0_107400.htm
c:\windows\system32\cache329\B_329_3_1_515400.htm
c:\windows\system32\cache329\B_329_3_1_515400.swf
c:\windows\system32\cache329\B_329_3_1_517400.htm
c:\windows\system32\cache329\B_329_3_1_517400.swf
c:\windows\system32\cache329\B_329_3_1_518400.htm
c:\windows\system32\cache329\B_329_3_1_518400.swf
c:\windows\system32\cache329\B_329_3_1_519100.htm
c:\windows\system32\cache329\B_329_3_1_519100.swf
c:\windows\system32\cache329\B_329_3_1_521100.htm
c:\windows\system32\cache329\B_329_3_1_521100.swf
c:\windows\system32\cache329\B_329_3_1_526300.htm
c:\windows\system32\cache329\B_329_3_1_526300.swf
c:\windows\system32\cache329\B_329_3_1_527900.htm
c:\windows\system32\cache329\B_329_3_1_527900.swf
c:\windows\system32\cache329\B_329_3_1_531800.htm
c:\windows\system32\cache329\B_329_3_1_531800.swf
c:\windows\system32\cache329\B_329_3_1_586100.gif
c:\windows\system32\cache329\B_329_3_1_604400.htm
c:\windows\system32\cache329\B_329_3_1_604400.swf
c:\windows\system32\cache329\B_329_3_1_605500.htm
c:\windows\system32\cache329\B_329_3_1_605500.swf
c:\windows\system32\cache329\B_329_3_1_618300.htm
c:\windows\system32\cache329\B_329_3_1_618300.swf
c:\windows\system32\cache329\B_329_3_1_621600.htm
c:\windows\system32\cache329\B_329_3_1_621600.swf
c:\windows\system32\cache329\B_329_3_1_622000.htm
c:\windows\system32\cache329\B_329_3_1_622000.swf
c:\windows\system32\cache329\B_329_3_1_623500.gif
c:\windows\system32\cache329\B_329_3_1_630000.htm
c:\windows\system32\cache329\B_329_3_1_630000.swf
c:\windows\system32\cache329\B_329_3_1_630600.htm
c:\windows\system32\cache329\B_329_3_1_630600.swf
c:\windows\system32\cache329\B_329_3_1_647600.gif
c:\windows\system32\cache329\B_329_3_1_651200.htm
c:\windows\system32\cache329\B_329_3_1_651200.swf
c:\windows\system32\cache329\B_329_3_1_659200.htm
c:\windows\system32\cache329\B_329_3_1_659200.swf
c:\windows\system32\cache329\B_329_3_1_659800.htm
c:\windows\system32\cache329\B_329_3_1_659800.swf
c:\windows\system32\cache329\B_329_3_1_668900.htm
c:\windows\system32\cache329\B_329_3_1_668900.swf
c:\windows\system32\cache329\B_329_3_1_672100.htm
c:\windows\system32\cache329\B_329_3_1_672100.swf
c:\windows\system32\cache329\B_329_3_1_672300.htm
c:\windows\system32\cache329\B_329_3_1_672300.swf
c:\windows\system32\cache329\B_329_3_1_672600.htm
c:\windows\system32\cache329\B_329_3_1_672600.swf
c:\windows\system32\cache329\B_329_3_1_673700.htm
c:\windows\system32\cache329\B_329_3_1_673700.swf
c:\windows\system32\cache329\B_329_3_1_674500.htm
c:\windows\system32\cache329\B_329_3_1_674500.swf
c:\windows\system32\cache329\B_329_3_1_678600.htm
c:\windows\system32\cache329\B_329_3_1_678600.swf
c:\windows\system32\cache329\B_329_3_1_688200.htm
c:\windows\system32\cache329\B_329_3_1_688200.swf
c:\windows\system32\cache329\B_329_3_1_697700.htm
c:\windows\system32\cache329\B_329_3_1_697700.swf
c:\windows\system32\cache329\B_329_3_1_699800.htm
c:\windows\system32\cache329\B_329_3_1_699800.swf
c:\windows\system32\cache329\B_329_3_1_708400.htm
c:\windows\system32\cache329\B_329_3_1_708400.swf
c:\windows\system32\cache329\B_329_3_2_549100.gif
c:\windows\system32\cache329\B_329_3_2_550200.gif
c:\windows\system32\cache329\B_329_3_2_591600.htm
c:\windows\system32\cache329\B_329_3_2_591600.swf
c:\windows\system32\cache329\B_329_3_2_611400.htm
c:\windows\system32\cache329\B_329_3_2_611400.swf
c:\windows\system32\cache329\B_329_3_3_605100.gif
c:\windows\system32\cache329\B_329_3_4_621900.gif
c:\windows\system32\cache329\B_329_3_4_700300.htm
c:\windows\system32\cache329\B_329_3_4_700300.jpg
c:\windows\system32\cache329\B_329_4_0_111600.htm
c:\windows\system32\cache329\B_329_4_0_152400.htm
c:\windows\system32\cache329\B_329_4_0_155300.htm
c:\windows\system32\cache329\B_329_4_0_164100.htm
c:\windows\system32\cache329\B_329_4_1_534000.htm
c:\windows\system32\cache329\B_329_4_1_534000.swf
c:\windows\system32\cache329\B_329_4_1_646800.htm
c:\windows\system32\cache329\B_329_4_1_683100.gif
c:\windows\system32\cache329\B_329_4_1_683100.htm
c:\windows\system32\cache329\B_329_4_1_713900.htm
c:\windows\system32\cache329\B_329_4_2_550300.htm
c:\windows\system32\cache329\B_329_4_2_550300.swf
c:\windows\system32\cache329\B_329_4_2_576700.gif
c:\windows\system32\cache329\B_329_4_2_576700.htm
c:\windows\system32\cache329\B_329_4_2_578000.htm
c:\windows\system32\cache329\B_329_4_2_578000.swf
c:\windows\system32\cache329\B_329_4_2_579200.htm
c:\windows\system32\cache329\B_329_4_2_605700.gif
c:\windows\system32\cache329\B_329_4_2_605700.htm
c:\windows\system32\cache329\B_329_4_2_607000.htm
c:\windows\system32\cache329\B_329_4_2_620800.htm
c:\windows\system32\cache329\B_329_4_2_643000.htm
c:\windows\system32\cache329\B_329_4_2_645200.htm
c:\windows\system32\cache329\B_329_4_2_648700.htm
c:\windows\system32\cache329\B_329_4_2_673800.htm
c:\windows\system32\cache329\B_329_4_2_673800.swf
c:\windows\system32\cache329\B_329_4_2_673900.htm
c:\windows\system32\cache329\B_329_4_2_673900.swf
c:\windows\system32\cache329\B_329_4_2_676800.htm
c:\windows\system32\cache329\B_329_4_2_676800.swf
c:\windows\system32\cache329\B_329_4_2_711400.htm
c:\windows\system32\cache329\B_329_4_2_711400.jpg
c:\windows\system32\cache329\B_329_4_2_711500.gif
c:\windows\system32\cache329\B_329_4_2_711500.htm
c:\windows\system32\cache329\B_329_4_3_563600.htm
c:\windows\system32\cache329\B_329_4_3_563600.swf
c:\windows\system32\cache329\B_329_4_3_592500.htm
c:\windows\system32\cache329\B_329_4_3_592500.swf
c:\windows\system32\cache329\B_329_4_3_603400.gif
c:\windows\system32\cache329\B_329_4_3_603400.htm
c:\windows\system32\cache329\B_329_4_3_675700.htm
c:\windows\system32\cache329\B_329_4_4_636700.htm
c:\windows\system32\cache329\B_329_4_4_636800.htm
c:\windows\system32\cache329\B_524800.htm
c:\windows\system32\cache329\B_525100.htm
c:\windows\system32\cache329\B_527100.htm
c:\windows\system32\cache329\B_528500.htm
c:\windows\system32\cache329\B_530800.htm
c:\windows\system32\cache329\B_550500.htm
c:\windows\system32\cache329\B_561000.htm
c:\windows\system32\cache329\B_569300.htm
c:\windows\system32\cache329\B_575200.htm
c:\windows\system32\cache329\B_576800.htm
c:\windows\system32\cache329\B_587800.htm
c:\windows\system32\cache329\B_588700.htm
c:\windows\system32\cache329\B_591300.htm
c:\windows\system32\cache329\B_604700.htm
c:\windows\system32\cache329\B_632900.htm
c:\windows\system32\cache329\B_633600.htm
c:\windows\system32\cache329\B_633900.htm
c:\windows\system32\cache329\B_634500.htm
c:\windows\system32\cache329\B_634700.htm
c:\windows\system32\cache329\B_634800.htm
c:\windows\system32\cache329\B_634900.htm
c:\windows\system32\cache329\B_637600.htm
c:\windows\system32\cache329\B_642100.htm
c:\windows\system32\cache329\B_665300.htm
c:\windows\system32\cache329\B_665500.htm
c:\windows\system32\cache329\B_679800.htm
c:\windows\system32\cache329\B_704700.htm
c:\windows\system32\cache329\B_704800.htm
c:\windows\system32\cache329\B_705100.htm
c:\windows\system32\cache329\B_707700.htm
c:\windows\system32\cache329\t_B_329_0_0_106800.htm
c:\windows\system32\cache329\t_B_329_0_0_107400.htm
c:\windows\system32\cache329\t_B_329_2_0_106800.htm
c:\windows\system32\cache329\t_B_329_2_0_107400.htm
c:\windows\system32\cache329\t_B_329_3_0_106800.htm
c:\windows\system32\cache329\t_B_329_3_0_107400.htm
c:\windows\system32\cache329\t_B_329_4_0_111600.htm
c:\windows\system32\cache329\t_B_329_4_0_152400.htm
c:\windows\system32\cache329\t_B_329_4_0_155300.htm
c:\windows\system32\cache329\t_B_329_4_0_164100.htm
c:\windows\system32\cache329\t_B_329_4_1_646800.htm
c:\windows\system32\cache329\t_B_329_4_1_713900.htm
c:\windows\system32\cache329\t_B_329_4_2_579200.htm
c:\windows\system32\cache329\t_B_329_4_2_607000.htm
c:\windows\system32\cache329\t_B_329_4_2_620800.htm
c:\windows\system32\cache329\t_B_329_4_2_643000.htm
c:\windows\system32\cache329\t_B_329_4_2_645200.htm
c:\windows\system32\cache329\t_B_329_4_2_648700.htm
c:\windows\system32\cache329\t_B_329_4_3_675700.htm
c:\windows\system32\cache329\t_B_329_4_4_636700.htm
c:\windows\system32\cache329\t_B_329_4_4_636800.htm
c:\windows\system32\cache329\t_B_524800.htm
c:\windows\system32\cache329\t_B_525100.htm
c:\windows\system32\cache329\t_B_527100.htm
c:\windows\system32\cache329\t_B_528500.htm
c:\windows\system32\cache329\t_B_530800.htm
c:\windows\system32\cache329\t_B_550500.htm
c:\windows\system32\cache329\t_B_561000.htm
c:\windows\system32\cache329\t_B_569300.htm
c:\windows\system32\cache329\t_B_575200.htm
c:\windows\system32\cache329\t_B_576800.htm
c:\windows\system32\cache329\t_B_587800.htm
c:\windows\system32\cache329\t_B_588700.htm
c:\windows\system32\cache329\t_B_591300.htm
c:\windows\system32\cache329\t_B_604700.htm
c:\windows\system32\cache329\t_B_632900.htm
c:\windows\system32\cache329\t_B_633600.htm
c:\windows\system32\cache329\t_B_633900.htm
c:\windows\system32\cache329\t_B_634500.htm
c:\windows\system32\cache329\t_B_634700.htm
c:\windows\system32\cache329\t_B_634800.htm
c:\windows\system32\cache329\t_B_634900.htm
c:\windows\system32\cache329\t_B_637600.htm
c:\windows\system32\cache329\t_B_642100.htm
c:\windows\system32\cache329\t_B_665300.htm
c:\windows\system32\cache329\t_B_665500.htm
c:\windows\system32\cache329\t_B_679800.htm
c:\windows\system32\cache329\t_B_704700.htm
c:\windows\system32\cache329\t_B_704800.htm
c:\windows\system32\cache329\t_B_705100.htm
c:\windows\system32\cache329\t_B_707700.htm
c:\windows\system32\msblcd32.dll

.
((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.

2009-08-26 16:22 . 2009-08-26 16:22 88 —-a-w- c:\documents and settings\All Users\Application Data\BOINC\slots\1\libfftw3f-3-1-1a_upx.dll
2009-08-26 16:22 . 2009-08-26 16:22 100 —-a-w- c:\documents and settings\All Users\Application Data\BOINC\slots\1\setiathome_6.03_windows_intelx86.exe
2009-08-21 14:24 . 2009-08-21 14:24 ——– d—–w- c:\docume~1\Steve\APPLIC~1\Malwarebytes
2009-08-21 14:24 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-21 14:24 . 2009-08-21 14:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-21 14:24 . 2009-08-21 14:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-21 14:24 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-21 13:36 . 2009-08-21 13:36 ——– d—–w- c:\program files\ERUNT
2009-08-21 04:54 . 2009-08-21 04:54 ——– d—–w- c:\program files\Trend Micro
2009-08-17 16:58 . 2009-08-17 16:58 448600 —-a-w- c:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\libfftw3f-3-1-1a_upx.dll
2009-08-17 16:57 . 2009-08-17 16:58 406016 —-a-w- c:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe
2009-08-17 16:57 . 2009-08-17 16:58 267776 —-a-w- c:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setigraphics_6.03_windows_intelx86.exe
2009-08-09 03:54 . 2009-08-09 03:55 ——– d—–w- c:\program files\PHP
2009-08-09 03:49 . 2009-08-09 03:49 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-27 00:03 . 2009-02-08 04:18 ——– d—–w- c:\documents and settings\All Users\Application Data\BOINC
2009-08-26 23:42 . 2009-03-22 11:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-26 15:01 . 2009-05-27 15:03 ——– d—–w- c:\docume~1\Steve\APPLIC~1\GetRight
2009-08-25 19:43 . 2005-03-03 04:18 ——– d—–w- c:\program files\BOINC
2009-08-22 16:36 . 2009-05-24 00:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Tencent
2009-08-20 03:28 . 2004-12-18 07:44 4212 -c-ha-w- c:\windows\system32\zllictbl.dat
2009-08-19 17:22 . 2009-06-24 13:01 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-19 17:22 . 2009-06-24 13:01 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-19 17:22 . 2009-06-24 13:01 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-23 01:59 . 2009-07-05 09:49 ——– d—–w- c:\program files\MB Free Subliminal Message Software
2009-07-13 18:07 . 2009-06-22 17:37 520024 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-07-13 18:07 . 2009-06-22 17:58 1029456 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-07-12 02:28 . 2009-07-12 02:28 ——– d—–w- c:\documents and settings\All Users\Application Data\iolo
2009-07-12 02:28 . 2009-07-12 02:28 ——– d—–w- c:\docume~1\Steve\APPLIC~1\iolo
2009-07-07 13:42 . 2009-02-25 05:47 ——– d—–w- c:\program files\IObit
2009-07-05 09:41 . 2009-07-05 09:41 ——– d—–w- c:\documents and settings\All Users\Application Data\GoldWave
2009-07-02 14:28 . 2009-07-02 14:28 49992 —-a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-07-02 14:28 . 2004-09-20 03:47 8224 -c–a-w- c:\documents and settings\Steve\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-01 09:49 . 2009-07-01 09:49 ——– d—–w- c:\program files\JRE
2009-07-01 09:48 . 2009-02-08 20:46 ——– d—–w- c:\program files\OpenOffice.org 3
2009-06-30 22:58 . 2009-06-30 22:58 ——– d—–w- c:\program files\PC-Doctor for Windows
2009-06-30 22:48 . 2004-01-27 13:23 ——– d—–w- c:\program files\HP
2009-06-29 22:03 . 2004-09-25 19:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-26 00:26 . 2009-02-09 14:05 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-24 13:01 . 2009-06-24 13:01 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-22 17:48 . 2009-06-22 18:14 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-22 17:48 . 2009-06-22 17:48 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-22 17:42 . 2009-06-22 17:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-22 17:42 . 2009-06-22 17:42 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-16 14:36 . 2004-02-03 19:13 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-02-03 18:50 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-10 15:05 . 2009-06-10 15:05 828160 —-a-w- c:\windows\boinc.scr
2009-06-03 19:09 . 2003-05-31 00:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-03 03:19 . 2009-06-03 04:00 200434 —-a-w- c:\windows\PCHealth\HelpCtr\Config\Cache\Personal_32_1033.dat
2006-01-27 05:14 . 2006-01-27 05:15 774144 -c–a-w- c:\program files\RngInterstitial.dll
2004-11-26 16:54 . 2004-11-26 16:54 307712 -c–a-w- c:\program files\switchsetup.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-01-20 16:47 . 2006-01-20 16:47 0 -csha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-29 21:24 325000 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]
"Google Update"="c:\documents and settings\Steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-01 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-13 520024]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-26 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-19 2007832]
"boinctray"="c:\program files\BOINC\boinctray.exe" [2009-06-10 58112]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-08-20 943888]

c:\documents and settings\Steve\Start Menu\Programs\Startup\
BOINC Manager.lnk - c:\program files\BOINC\boincmgr.exe [2009-6-10 4182784]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
QuickLink Mobile.lnk - c:\program files\Cricket\QuickLink Mobile\QuickLink Mobile.exe [2009-2-4 1525096]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
GetRight.lnk - c:\program files\GetRight\GetRight.exe [2009-5-27 4628752]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
FriendlyName= Amazon.com: Books: How to Remodel a Man : Tips and Techniques on Accomplishing Something You Know Is Impossible but Want to Try Anyway

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-19 17:22 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BOINC Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BOINC Manager.lnk
backup=c:\windows\pss\BOINC Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VETMSGNT"=2 (0x2)
"SymWSC"=2 (0x2)
"iPodService"=3 (0x3)
"CAISafe"=2 (0x2)
"Bonjour Service"=2 (0x2)
"AOL ACS"=2 (0x2)
"StarWindServiceAE"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"EPSON Stylus CX5400"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /M "Stylus CX5400" /EF "HKCU"
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\D4\\D4.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\WINDOWS\\system32\\ntvdm.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"c:\\Program Files\\Compaq Connections\\1940576\\Program\\BackWeb-1940576.exe"=
"c:\\Program Files\\WinMX\\WinMX.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Sweet Home 3D\\jre6\\launch4j-tmp\\SweetHome3D.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"57435:TCP"= 57435:TCP:Pando Media Booster
"57435:UDP"= 57435:UDP:Pando Media Booster
"58553:TCP"= 58553:TCP:Pando P2P TCP Listening Port
"58553:UDP"= 58553:UDP:Pando P2P UDP Listening Port
"443:TCP"= 443:TCP:443

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/22/2009 1:49 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/24/2009 9:01 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/24/2009 9:01 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/24/2009 9:00 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/24/2009 9:00 AM 297752]
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [8/22/2009 6:26 AM 305936]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
R3 uts_bus;UTStarcom USB Composite Device driver (WDM);c:\windows\system32\drivers\uts_bus.sys [2/5/2009 7:35 PM 84352]
R3 uts_mdfl;UTStarcom USB Modem Filter;c:\windows\system32\drivers\uts_mdfl.sys [2/5/2009 7:35 PM 14976]
R3 uts_mdm;UTStarcom USB Modem Drivers;c:\windows\system32\drivers\uts_mdm.sys [2/5/2009 7:35 PM 110848]
R3 uts_serd;UTStarcom USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\uts_serd.sys [2/5/2009 7:35 PM 90880]
S0 IFP300;iriver Internet Audio Player IFP-300;c:\windows\system32\DRIVERS\ifp300.sys –> c:\windows\system32\DRIVERS\ifp300.sys [?]
S2 gupdate1c9ac3fd88d18d4;Google Update Service (gupdate1c9ac3fd88d18d4);c:\program files\Google\Update\GoogleUpdate.exe [3/24/2009 1:17 AM 133104]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\Steve\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\Steve\LOCALS~1\Temp\ALSysIO.sys [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/5/2009 7:14 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/5/2009 7:14 PM 3072]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2/12/2009 1:56 PM 33752]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/21/2009 10:24 AM 38160]
S3 SIWIO;SIWIO;\??\c:\windows\TEMP\SiwIo.sys –> c:\windows\TEMP\SiwIo.sys [?]
S3 zlportio;ZLPORTIO - Allow user access to I/O ports;\??\e:\programs\DriverWizard\zlportio.sys –> e:\programs\DriverWizard\zlportio.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-08-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:08]

2009-08-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-08-26 c:\windows\Tasks\defrag.job
- c:\windows\system32\defrag.exe [2004-02-03 09:42]

2009-08-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-22 11:42]

2009-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 05:16]

2009-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 05:16]

2009-08-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201466077-2511029282-49471186-1009Core.job
- c:\documents and settings\Steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-13 01:21]

2009-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201466077-2511029282-49471186-1009UA.job
- c:\documents and settings\Steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-13 01:21]

2009-08-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-03 22:12]

2009-08-24 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-07-07 13:22]

2009-08-27 c:\windows\Tasks\User_Feed_Synchronization-{04C127C8-F145-45EC-8C84-F31BB42BA089}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
URLSearchHooks-EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
URLSearchHooks-06663B56-0D73-4f9f-BCC5-4AA941470AFD} - (no file)
URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AIM; Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Search; - http://bar.mywebsearch.com/menusearch.html?p=ZU
IE: &Webshots; Photo Search - c:\program files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\v4.windowsupdate
Trusted Zone: microsoft.com\v5.windowsupdate
Trusted Zone: nationalcity.com\signonolb
Trusted Zone: nationalcity.com\www
Trusted Zone: windowsupdate.com
Trusted Zone: windowsupdate.com\download
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
FF - ProfilePath - c:\docume~1\Steve\APPLIC~1\Mozilla\Firefox\Profiles\7v49h34d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr;=ytff-tyc&p;=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type;=yahoo_avg_hs2-tb-web_us&p;=
FF - component: c:\documents and settings\Steve\Application Data\Mozilla\Firefox\Profiles\7v49h34d.default\extensions\[removed]\platform\WINNT_x86-msvc\components\WinKiosk.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Steve\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPPandBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll

—- FIREFOX POLICIES —-


c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-26 19:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(4576)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\windows\wanmpsvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\documents and settings\Steve\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\BOINC\boinc.exe
c:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe
c:\program files\IObit\IObit Security 360\is360.exe
c:\program files\AIM6\aolsoftware.exe
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Completion time: 2009-08-26 20:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-27 00:12

Pre-Run: 7,340,560,384 bytes free
Post-Run: 7,205,687,296 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut

919

Attachments:

Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57435:TCP"=-
"57435:UDP"=-
"58553:TCP"=-
"58553:UDP"=-
"443:TCP"=-

DDS::
IE: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
Kaspersky's keeps timing out and I cannot run it due to the slow connection I'm assuming. Is there a program that will monitor my internet connection and create a log of which files are demanding the bandwidth during a certain time span? I'm running off a cellular broadband but until recently my receive rate has been between 600 and 900 kps. Now I get lucky to get a spike over 100.

Below please find the logs of ComboFix and Malwarebytess Anti-Malware.

ComboFix 09-08-25.05 - Steve 08/26/2009 22:39.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.759.258 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix-001.exe
Command switches used :: c:\documents and settings\Steve\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-07-27 to 2009-08-27 )))))))))))))))))))))))))))))))
.

2009-08-21 14:24 . 2009-08-21 14:24 ——– d—–w- c:\docume~1\Steve\APPLIC~1\Malwarebytes
2009-08-21 14:24 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-21 14:24 . 2009-08-21 14:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-21 14:24 . 2009-08-21 14:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-21 14:24 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-21 13:36 . 2009-08-21 13:36 ——– d—–w- c:\program files\ERUNT
2009-08-21 04:54 . 2009-08-21 04:54 ——– d—–w- c:\program files\Trend Micro
2009-08-17 16:58 . 2009-08-17 16:58 448600 —-a-w- c:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\libfftw3f-3-1-1a_upx.dll
2009-08-17 16:57 . 2009-08-17 16:58 406016 —-a-w- c:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe
2009-08-17 16:57 . 2009-08-17 16:58 267776 —-a-w- c:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setigraphics_6.03_windows_intelx86.exe
2009-08-09 03:54 . 2009-08-09 03:55 ——– d—–w- c:\program files\PHP
2009-08-09 03:49 . 2009-08-09 03:49 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-27 03:02 . 2009-02-08 04:18 ——– d—–w- c:\documents and settings\All Users\Application Data\BOINC
2009-08-26 23:42 . 2009-03-22 11:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-26 15:01 . 2009-05-27 15:03 ——– d—–w- c:\docume~1\Steve\APPLIC~1\GetRight
2009-08-25 19:43 . 2005-03-03 04:18 ——– d—–w- c:\program files\BOINC
2009-08-22 16:36 . 2009-05-24 00:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Tencent
2009-08-20 03:28 . 2004-12-18 07:44 4212 -c-ha-w- c:\windows\system32\zllictbl.dat
2009-08-19 17:22 . 2009-06-24 13:01 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-19 17:22 . 2009-06-24 13:01 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-19 17:22 . 2009-06-24 13:01 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-23 01:59 . 2009-07-05 09:49 ——– d—–w- c:\program files\MB Free Subliminal Message Software
2009-07-13 18:07 . 2009-06-22 17:37 520024 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-07-13 18:07 . 2009-06-22 17:58 1029456 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-07-12 02:28 . 2009-07-12 02:28 ——– d—–w- c:\documents and settings\All Users\Application Data\iolo
2009-07-12 02:28 . 2009-07-12 02:28 ——– d—–w- c:\docume~1\Steve\APPLIC~1\iolo
2009-07-07 13:42 . 2009-02-25 05:47 ——– d—–w- c:\program files\IObit
2009-07-05 09:41 . 2009-07-05 09:41 ——– d—–w- c:\documents and settings\All Users\Application Data\GoldWave
2009-07-02 14:28 . 2009-07-02 14:28 49992 —-a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-07-02 14:28 . 2004-09-20 03:47 8224 -c–a-w- c:\documents and settings\Steve\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-01 09:49 . 2009-07-01 09:49 ——– d—–w- c:\program files\JRE
2009-07-01 09:48 . 2009-02-08 20:46 ——– d—–w- c:\program files\OpenOffice.org 3
2009-06-30 22:58 . 2009-06-30 22:58 ——– d—–w- c:\program files\PC-Doctor for Windows
2009-06-30 22:48 . 2004-01-27 13:23 ——– d—–w- c:\program files\HP
2009-06-29 22:03 . 2004-09-25 19:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-26 00:26 . 2009-02-09 14:05 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-24 13:01 . 2009-06-24 13:01 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-22 17:48 . 2009-06-22 18:14 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-22 17:48 . 2009-06-22 17:48 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-22 17:42 . 2009-06-22 17:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-22 17:42 . 2009-06-22 17:42 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-16 14:36 . 2004-02-03 19:13 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-02-03 18:50 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-10 15:05 . 2009-06-10 15:05 828160 —-a-w- c:\windows\boinc.scr
2009-06-03 19:09 . 2003-05-31 00:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-03 03:19 . 2009-06-03 04:00 200434 —-a-w- c:\windows\PCHealth\HelpCtr\Config\Cache\Personal_32_1033.dat
2006-01-27 05:14 . 2006-01-27 05:15 774144 -c–a-w- c:\program files\RngInterstitial.dll
2004-11-26 16:54 . 2004-11-26 16:54 307712 -c–a-w- c:\program files\switchsetup.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-01-20 16:47 . 2006-01-20 16:47 0 -csha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-08-26_23.49.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-26 23:44 . 2009-08-26 23:44 16384 c:\windows\Temp\Perflib_Perfdata_8c4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-29 21:24 325000 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]
"Google Update"="c:\documents and settings\Steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-01 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-13 520024]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-26 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-19 2007832]
"boinctray"="c:\program files\BOINC\boinctray.exe" [2009-06-10 58112]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-08-20 943888]

c:\documents and settings\Steve\Start Menu\Programs\Startup\
BOINC Manager.lnk - c:\program files\BOINC\boincmgr.exe [2009-6-10 4182784]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
QuickLink Mobile.lnk - c:\program files\Cricket\QuickLink Mobile\QuickLink Mobile.exe [2009-2-4 1525096]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
GetRight.lnk - c:\program files\GetRight\GetRight.exe [2009-5-27 4628752]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
FriendlyName= Amazon.com: Books: How to Remodel a Man : Tips and Techniques on Accomplishing Something You Know Is Impossible but Want to Try Anyway

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-19 17:22 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BOINC Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BOINC Manager.lnk
backup=c:\windows\pss\BOINC Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VETMSGNT"=2 (0x2)
"SymWSC"=2 (0x2)
"iPodService"=3 (0x3)
"CAISafe"=2 (0x2)
"Bonjour Service"=2 (0x2)
"AOL ACS"=2 (0x2)
"StarWindServiceAE"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"EPSON Stylus CX5400"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /M "Stylus CX5400" /EF "HKCU"
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\D4\\D4.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\WINDOWS\\system32\\ntvdm.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"c:\\Program Files\\Compaq Connections\\1940576\\Program\\BackWeb-1940576.exe"=
"c:\\Program Files\\WinMX\\WinMX.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Sweet Home 3D\\jre6\\launch4j-tmp\\SweetHome3D.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/22/2009 1:49 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/24/2009 9:01 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/24/2009 9:01 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/24/2009 9:00 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/24/2009 9:00 AM 297752]
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [8/22/2009 6:26 AM 305936]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/23/2009 8:16 PM 24652]
R3 uts_bus;UTStarcom USB Composite Device driver (WDM);c:\windows\system32\drivers\uts_bus.sys [2/5/2009 7:35 PM 84352]
R3 uts_mdfl;UTStarcom USB Modem Filter;c:\windows\system32\drivers\uts_mdfl.sys [2/5/2009 7:35 PM 14976]
R3 uts_mdm;UTStarcom USB Modem Drivers;c:\windows\system32\drivers\uts_mdm.sys [2/5/2009 7:35 PM 110848]
R3 uts_serd;UTStarcom USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\uts_serd.sys [2/5/2009 7:35 PM 90880]
S0 IFP300;iriver Internet Audio Player IFP-300;c:\windows\system32\DRIVERS\ifp300.sys –> c:\windows\system32\DRIVERS\ifp300.sys [?]
S2 gupdate1c9ac3fd88d18d4;Google Update Service (gupdate1c9ac3fd88d18d4);c:\program files\Google\Update\GoogleUpdate.exe [3/24/2009 1:17 AM 133104]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\Steve\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\Steve\LOCALS~1\Temp\ALSysIO.sys [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/5/2009 7:14 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/5/2009 7:14 PM 3072]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2/12/2009 1:56 PM 33752]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/21/2009 10:24 AM 38160]
S3 SIWIO;SIWIO;\??\c:\windows\TEMP\SiwIo.sys –> c:\windows\TEMP\SiwIo.sys [?]
S3 zlportio;ZLPORTIO - Allow user access to I/O ports;\??\e:\programs\DriverWizard\zlportio.sys –> e:\programs\DriverWizard\zlportio.sys [?]
S4 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [4/3/2006 6:12 PM 14032]
.
Contents of the 'Scheduled Tasks' folder

2009-08-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:08]

2009-08-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-08-26 c:\windows\Tasks\defrag.job
- c:\windows\system32\defrag.exe [2004-02-03 09:42]

2009-08-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-22 11:42]

2009-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 05:16]

2009-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 05:16]

2009-08-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201466077-2511029282-49471186-1009Core.job
- c:\documents and settings\Steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-13 01:21]

2009-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201466077-2511029282-49471186-1009UA.job
- c:\documents and settings\Steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-13 01:21]

2009-08-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-03 22:12]

2009-08-27 c:\windows\Tasks\User_Feed_Synchronization-{04C127C8-F145-45EC-8C84-F31BB42BA089}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Webshots Photo Search - c:\program files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\v4.windowsupdate
Trusted Zone: microsoft.com\v5.windowsupdate
Trusted Zone: nationalcity.com\signonolb
Trusted Zone: nationalcity.com\www
Trusted Zone: windowsupdate.com
Trusted Zone: windowsupdate.com\download
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
FF - ProfilePath - c:\docume~1\Steve\APPLIC~1\Mozilla\Firefox\Profiles\7v49h34d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\documents and settings\Steve\Application Data\Mozilla\Firefox\Profiles\7v49h34d.default\extensions\[removed]\platform\WINNT_x86-msvc\components\WinKiosk.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Steve\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPPandBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll

—- FIREFOX POLICIES —-


c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-26 22:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(9988)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-08-27 23:07
ComboFix-quarantined-files.txt 2009-08-27 03:07
ComboFix2.txt 2009-08-27 00:12

Pre-Run: 7,231,053,824 bytes free
Post-Run: 7,201,931,264 bytes free

336

Malwarebytes' Anti-Malware 1.40
Database version: 2702
Windows 5.1.2600 Service Pack 3

8/27/2009 12:39:12 AM
mbam-log-2009-08-27 (00-39-12).txt

Scan type: Quick Scan
Objects scanned: 110441
Time elapsed: 8 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi,

I know our techs recommend the tests at PC pitstop a lot http://www.pcpitstop.com/

but lets get you clean of malware first, then you can head over to the tech threads to find out what the issue is with the connection.

Try this scanner instead:

]
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
I've been trying and trying to run either the Kaspersky or the ESET online scanners and neither are working. I believe it's due to my slow internet connection. I called my provider yesterday and they talked me through some diagnostics and they believe it's in their service and they submitted a ticket and it may be Wednesday before they even look at it. Some good news though, Microsoft update has started working again. Well, not completely though, my computer has once again started automatic downloading of updates but I'm still not able to access the update site like I should. The diagnostics you've had me do have helped tremendously though, my system is running considerably better than it was so thank you very much. When my speed gets back to where I can actually run the online scanners I will post that.
OK, got my speed back. Ran the ESET Scanner and below are the results: C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined C:\programs\IPScan\ipscan.exe Win32/NetTool.Portscan.C application cleaned by deleting - quarantined C:\System Volume Information\_restore{D1BD6C0F-8411-4455-8163-CEF0F28EC0B2}\RP68\A0033603.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{D1BD6C0F-8411-4455-8163-CEF0F28EC0B2}\RP68\A0033604.exe Win32/NetTool.Portscan.C application cleaned by deleting - quarantined C:\UBCD4Win\UBCD4WinBuilder.iso multiple threats deleted - quarantined C:\UBCD4Win\BartPE\PROGRAMS\IPScan\ipscan.exe Win32/NetTool.Portscan.C application cleaned by deleting - quarantined C:\UBCD4Win\plugin\Network\ipscan\ipscan.exe Win32/NetTool.Portscan.C application cleaned by deleting - quarantined Thanks again for your help!
Please post a fresh DDS and Attach.txt and describe how your computer is running now and if there are any outstanding issues.
Ran Kaspersky and DDS. Below are the results. The computer is running really well now, no real issues that I've noticed. Kaspersky reported about 51 infected files though, that concerns me. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, September 2, 2009 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, September 02, 2009 15:35:17 Records in database: 2740131 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ Scan statistics: Objects scanned: 144016 Threats found: 10 Infected objects found: 41 Suspicious objects found: 0 Scan duration: 07:50:43 File name / Threat / Threats count C:\Dev-Cpp\bin\addr2line.exe Infected: not-a-virus:NetTool.Win32.Scan.k 1 C:\Dev-Cpp\bin\ar.exe Infected: not-a-virus:NetTool.Win32.Scan.j 1 C:\Dev-Cpp\mingw32\bin\ar.exe Infected: not-a-virus:NetTool.Win32.Scan.j 1 C:\minint\SYSTEM32\WM_HOOKS.DLL Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\Program Files\Common Files\Real\Toolbar\RealBar.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.s 1 C:\Program Files\mIRC\backups\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Program Files\Mozilla Firefox\plugins\NPPandBr.dll Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\programs\PassPro\PasswordsPro.exe Infected: not-a-virus:PSWTool.Win32.PasswordsPro.dw 1 C:\programs\ultravnc\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1 C:\programs\ultravnc\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 1 C:\programs\ultravnc\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1 C:\programs\vncserver\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\programs\vncserver\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\Qoobox\Quarantine\C\Program Files\PandoBar\bar\1.bin\NPPANDBR.DLL.vir Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\Qoobox\Quarantine\C\Program Files\PandoBar\bar\1.bin\P4HIGHIN.EXE.vir Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\Qoobox\Quarantine\C\Program Files\PandoBar\bar\1.bin\P4PLUGIN.DLL.vir Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\Qoobox\Quarantine\C\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL.vir Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\Qoobox\Quarantine\C\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL.vir Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\System Volume Information\_restore{D1BD6C0F-8411-4455-8163-CEF0F28EC0B2}\RP63\A0032816.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\System Volume Information\_restore{D1BD6C0F-8411-4455-8163-CEF0F28EC0B2}\RP63\A0032818.EXE Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\System Volume Information\_restore{D1BD6C0F-8411-4455-8163-CEF0F28EC0B2}\RP63\A0032820.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\System Volume Information\_restore{D1BD6C0F-8411-4455-8163-CEF0F28EC0B2}\RP63\A0032821.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\System Volume Information\_restore{D1BD6C0F-8411-4455-8163-CEF0F28EC0B2}\RP63\A0032823.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ek 1 C:\System Volume Information\_restore{D1BD6C0F-8411-4455-8163-CEF0F28EC0B2}\RP68\A0033605.exe Infected: not-a-virus:NetTool.Win32.Portscan.c 1 C:\System Volume Information\_restore{D1BD6C0F-8411-4455-8163-CEF0F28EC0B2}\RP68\A0033606.exe Infected: not-a-virus:NetTool.Win32.Portscan.c 1 C:\UBCD4Win\BartPE\I386\SYSTEM32\WM_HOOKS.DLL Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\UBCD4Win\BartPE\PROGRAMS\PassPro\PasswordsPro.exe Infected: not-a-virus:PSWTool.Win32.PasswordsPro.dw 1 C:\UBCD4Win\BartPE\PROGRAMS\ultravnc\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1 C:\UBCD4Win\BartPE\PROGRAMS\ultravnc\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 1 C:\UBCD4Win\BartPE\PROGRAMS\ultravnc\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1 C:\UBCD4Win\BartPE\PROGRAMS\vncserver\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\UBCD4Win\BartPE\PROGRAMS\vncserver\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\UBCD4Win\plugin\Network\ultravnc\files\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1 C:\UBCD4Win\plugin\Network\ultravnc\files\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 1 C:\UBCD4Win\plugin\Network\ultravnc\files\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1 C:\UBCD4Win\plugin\Network\VNCServer\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\UBCD4Win\plugin\Network\VNCServer\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\UBCD4Win\plugin\Network\VNCServer\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\UBCD4Win\plugin\Network\VNCServer\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\UBCD4Win\plugin\Password\passwordspro\files\PasswordsPro.exe Infected: not-a-virus:PSWTool.Win32.PasswordsPro.dw 1 Selected area has been scanned. DDS: DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 18:16:25.37 on Wed 09/02/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.759.242 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\IObit\IObit Security 360\IS360srv.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\BOINC\boinctray.exe C:\Program Files\IObit\IObit Security 360\IS360tray.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe C:\Program Files\GetRight\GetRight.exe C:\Program Files\BOINC\boincmgr.exe C:\Program Files\Cricket\QuickLink Mobile\QuickLink Mobile.exe C:\Program Files\BOINC\boinc.exe C:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_hpf2_rosetta_6.03_windows_intelx86 C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\AIM6\aolsoftware.exe C:\Downloads\forospyware.com\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7 mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: IE to GetRight Helper: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - c:\program files\getright\xx2gr.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: jZip Webmail plugin: {647fd14a-c4f1-46f4-8fc3-0b40f54226f7} - c:\program files\jzip\WebmailPlugin.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll TB: &Google;: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll TB: Webshots Toolbar: {c17590d2-ecb4-4b15-8820-f58798dcc118} - c:\program files\webshots\WSToolbar4IE.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File EB: &Yahoo;! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup uRun: [Google Update] "c:\documents and settings\steve\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [SmartRAM] "c:\program files\iobit\advanced systemcare 3\Sup_SmartRAM.exe" /m mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [boinctray] "c:\program files\boinc\boinctray.exe" mRun: [IObit Security 360] c:\program files\iobit\iobit security 360\IS360tray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\steve\startm~1\programs\startup\boincm~1.lnk - c:\program files\boinc\boincmgr.exe StartupFolder: c:\docume~1\steve\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\steve\startm~1\programs\startup\quickl~1.lnk - c:\program files\cricket\quicklink mobile\QuickLink Mobile.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\getright.lnk - c:\program files\getright\GetRight.exe IE: &AIM; Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html IE: &Webshots; Photo Search - c:\program files\webshots\WSToolbar4IE.dll/MENUSEARCH.HTM IE: &Yahoo;! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm IE: Download with GetRight - c:\program files\getright\GRdownload.htm IE: Open with GetRight Browser - c:\program files\getright\GRbrowse.htm IE: Yahoo! &Dictionary; - file:///c:\program files\yahoo!\Common/ycdict.htm IE: Yahoo! &Maps; - file:///c:\program files\yahoo!\Common/ycmap.htm IE: Yahoo! &SMS; - file:///c:\program files\yahoo!\Common/ycsms.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: microsoft.com\*.update Trusted Zone: microsoft.com\*.windowsupdate Trusted Zone: microsoft.com\update Trusted Zone: microsoft.com\v4.windowsupdate Trusted Zone: microsoft.com\v5.windowsupdate Trusted Zone: nationalcity.com\signonolb Trusted Zone: nationalcity.com\www Trusted Zone: windowsupdate.com Trusted Zone: windowsupdate.com\download DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - hxxps://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?1&6&04.00.07.02&unknown;&unknown;&http;://aolexpressions.aol.com/testdrive.adp?clientId=2&expTypeId;=1&catId;=43&langCode;=&subcatId;=479&tm;=462&expId;=6211 DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Elf%20Bowling%20Holiday%20Pack/Images/stg_drm.ocx DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233774010406 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233773870562 DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {9732FB42-C321-11D1-836F-00A0C993F125} - hxxp://www.pcpitstop.com/mhLbl.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Elf%20Bowling%20Holiday%20Pack/Images/armhelper.ocx DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: {1CC25AA2-E1AA-4532-BD88-5194DB967928} = 172.28.221.53 172.28.221.54 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program files\mimectl.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\steve\applic~1\mozilla\firefox\profiles\7v49h34d.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr;=ytff-tyc&p;= FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type;=yahoo_avg_hs2-tb-web_us&p;= FF - component: c:\documents and settings\steve\application data\mozilla\firefox\profiles\7v49h34d.default\extensions\[removed]\platform\winnt_x86-msvc\components\WinKiosk.dll FF - plugin: c:\documents and settings\steve\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\progra~1\mozill~1\plugins\np_gp.dll FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPPandBr.dll FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin8.dll FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - plugin: c:\program files\virtools\3d life player\npvirtools.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-22 64160] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-24 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-24 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-24 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-24 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-24 297752] R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2009-8-22 305936] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-5-23 24652] R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] R3 uts_bus;UTStarcom USB Composite Device driver (WDM);c:\windows\system32\drivers\uts_bus.sys [2009-2-5 84352] R3 uts_mdfl;UTStarcom USB Modem Filter;c:\windows\system32\drivers\uts_mdfl.sys [2009-2-5 14976] R3 uts_mdm;UTStarcom USB Modem Drivers;c:\windows\system32\drivers\uts_mdm.sys [2009-2-5 110848] R3 uts_serd;UTStarcom USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\uts_serd.sys [2009-2-5 90880] S0 IFP300;iriver Internet Audio Player IFP-300;c:\windows\system32\drivers\ifp300.sys –> c:\windows\system32\drivers\ifp300.sys [?] S2 gupdate1c9ac3fd88d18d4;Google Update Service (gupdate1c9ac3fd88d18d4);c:\program files\google\update\GoogleUpdate.exe [2009-3-24 133104] S3 ALSysIO;ALSysIO;\??\c:\docume~1\steve\locals~1\temp\alsysio.sys –> c:\docume~1\steve\locals~1\temp\ALSysIO.sys [?] S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2009-3-5 8704] S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2009-3-5 3072] S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-2-12 33752] S3 SIWIO;SIWIO;\??\c:\windows\temp\siwio.sys –> c:\windows\temp\SiwIo.sys [?] S3 zlportio;ZLPORTIO - Allow user access to I/O ports;\??\e:\programs\driverwizard\zlportio.sys –> e:\programs\driverwizard\zlportio.sys [?] S4 WinDefend;Windows Defender Service;c:\program files\windows defender\MsMpEng.exe [2006-4-3 14032] =============== Created Last 30 ================ 2009-08-27 22:52 –d—– c:\program files\ESET 2009-08-26 20:07 -cd—– c:\windows\system32\dllcache\cache 2009-08-26 18:29 a-dshr– C:\cmdcons 2009-08-26 11:15 229,376 a——- c:\windows\PEV.exe 2009-08-26 11:15 161,792 a——- c:\windows\SWREG.exe 2009-08-26 11:15 98,816 a——- c:\windows\sed.exe 2009-08-22 12:34 0 a——- C:\config.ini 2009-08-22 06:59 1,374 a——- c:\windows\imsins.BAK 2009-08-21 10:24 –d—– c:\docume~1\steve\applic~1\Malwarebytes 2009-08-21 10:24 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-21 10:24 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-21 10:24 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-21 10:24 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-21 00:54 –d—– c:\program files\Trend Micro 2009-08-08 23:54 –d—– c:\program files\PHP 2009-08-08 23:49 -cd-h— c:\docume~1\alluse~1\applic~1\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1} ==================== Find3M ==================== 2009-08-19 23:28 4,212 ac–h— c:\windows\system32\zllictbl.dat 2009-08-19 13:22 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-08-19 13:22 335,240 a——- c:\windows\system32\drivers\avgldx86.sys 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll 2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll 2009-07-03 13:09 915,456 a——- c:\windows\system32\wininet.dll 2009-07-02 10:28 49,992 a——- c:\windows\system32\GDIPFONTCACHEV1.DAT 2009-06-25 04:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 04:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 04:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 04:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 04:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 04:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-22 13:48 15,688 a——- c:\windows\system32\lsdelete.exe 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe 2009-06-10 11:05 828,160 a——- c:\windows\boinc.scr 2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll 2006-01-27 01:14 774,144 ac—— c:\program files\RngInterstitial.dll 2004-11-26 12:54 307,712 ac—— c:\program files\switchsetup.exe 2006-01-20 12:47 0 ac-sh— c:\windows\sminst\HPCD.sys ============= FINISH: 18:19:02.70 =============== ATTACH: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 9/19/2004 5:41:10 PM System Uptime: 9/2/2009 6:00:17 PM (0 hours ago) Motherboard: MICRO-STAR INTERNATIONAL CO., LTD | | Gamila/Giovani/Neon series Processor: Intel® Celeron® CPU 2.80GHz | Socket 478 | 2800/100mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 37 GiB total, 5.837 GiB free. D: is CDROM (CDFS) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP40: 6/22/2009 9:13:27 PM - Installed MSN Toolbar RP41: 6/22/2009 9:16:03 PM - Installed Windows Internet Explorer 8. RP42: 6/22/2009 9:25:25 PM - Software Distribution Service 3.0 RP43: 6/24/2009 9:00:49 AM - Installed AVG Free 8.5 RP44: 6/25/2009 8:23:18 PM - Installed Java™ 6 Update 13 RP45: 6/27/2009 10:02:20 AM - Avg8 Update RP46: 7/1/2009 5:39:24 AM - Removed OpenOffice.org 3.0 RP47: 7/1/2009 5:47:58 AM - Installed OpenOffice.org 3.1 RP48: 7/2/2009 9:58:59 AM - System Checkpoint RP49: 7/3/2009 12:55:10 PM - System Checkpoint RP50: 7/6/2009 8:06:49 AM - Avg8 Update RP51: 7/6/2009 9:49:27 AM - Avg8 Update RP52: 7/9/2009 9:04:28 AM - Avg8 Update RP53: 7/18/2009 9:33:28 AM - Avg8 Update RP54: 7/21/2009 8:24:28 PM - System Checkpoint RP55: 8/4/2009 1:31:27 PM - Installed Reset Windows Update RP56: 8/8/2009 11:54:55 PM - Installed PHP 5.3.0 RP57: 8/11/2009 5:46:36 PM - System Checkpoint RP58: 8/19/2009 9:58:33 AM - Avg8 Update RP59: 8/19/2009 1:24:04 PM - Avg8 Update RP60: 8/22/2009 6:59:25 AM - Installed Windows XP KB971633. RP61: 8/22/2009 7:10:52 AM - Installed Windows XP KB961371. RP62: 8/22/2009 7:22:42 AM - Installed Windows XP KB973346. RP63: 8/25/2009 2:38:07 PM - System Checkpoint RP64: 8/28/2009 10:40:41 PM - Software Distribution Service 3.0 RP65: 8/29/2009 5:00:55 AM - Installed Java™ 6 Update 15 RP66: 8/29/2009 5:33:23 AM - Software Distribution Service 3.0 RP67: 8/30/2009 9:51:10 AM - Software Distribution Service 3.0 RP68: 8/30/2009 10:23:26 AM - Software Distribution Service 3.0 ==== Installed Programs ====================== 'Full Speed' Internet Booster + Performance Tests 15 Puzzle 3 castles 3D Pool Shark 3DVIA player 4.1 7-Zip 4.23 Acrobat.com Activision Anthology Remix Edition Ad-Aware Adobe AIR Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Media Player Adobe Reader 6.0 Adobe Reader 9.1.3 Adobe Shockwave Player Advanced SystemCare 3 AIM 6 Aim Plugin for QQ Games AIM Toolbar AIMTunes Alarm 3.5.8 AOL Uninstaller (Choose which Products to Remove) Apple Software Update ArcSoft ShowBiz DVD 2 Ashampoo StartUp Tuner 2.00 Ask Toolbar AusLogics Disk Defrag AVG Free 8.5 Battle for Wesnoth 1.0.1 BitTorrent Blast Thru Blast Thru Special Edition Blobs Block Rox Blue's Room BOINC Boink Bonjour Bowling Mania Special Edition Brain Twister Break Break Gold Buensoft Spanish 2004 CA Yahoo! Anti-Spy (remove only) Caillou's Preschool CameraDrivers CCleaner (remove only) CCScore Championship Chess Charmed Checkers Chinese Checkers Colors of War Special Edition Compaq Connections Compaq Instant Support ConvertHelper 2.2 Craps Special Edition Crazy MiniGolf Creation Station Special Edition Cribbage Dimension 4 v5.0 DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Web Player DNA Documentation of lcc-win32 Dodgem DonateBot Download Updater (AOL LLC) DriverGuide DriverScan DriverGuide Toolkit EASEUS Partition Manager 3.0 Home Edition Easy CD Creator 5 Platinum EasyCleaner EasyZip eGames GameButler eGames Master's Edition 151 Elf Bowling Holiday Pack EmailStripper 2.2 eMazing Mazes EPSON Printer Software ERUNT 1.1j ESET Online Scanner v3 ESSBrwr ESSCDBK ESScore ESSgui ESShelp ESSini ESSPCD ESSPDock ESSSONIC ESSTOOLS essvatgt essvcpt Fishing Special Edition FOX19 Free FLV Converter V 6.4.1 Free Natural Text to Speech Reader 2008 Free Videos To DVD V3.1 Galaxy of Games 201 Galaxy Video Poker Special Edition getPlus® for Adobe GetRight GoldWave v5.52 Gonzo Heads Google Chrome Google Earth Google SketchUp 7 Google Update Helper Google Updater GTK+ 2.6.9 runtime environment HijackThis 2.0.2 HLPPDOCK Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB970653-v3) HP DVD Writer HP Photo & Imaging 3.5 - HP Devices HP Product Detection HP Software Update hpg2436 hpg3970 hpg4600 hpg5530 hpg8200 HpSdpAppCoreApp ICatch (VI) PC Camera ICS Viewer 6.0 Intel® Extreme Graphics Driver InterActual Player IObit Security 360 RC J2SE Runtime Environment 5.0 Update 2 J2SE Runtime Environment 5.0 Update 6 Java 2 Runtime Environment, SE v1.4.2_03 Java 2 Runtime Environment, SE v1.4.2_05 Java 2 Runtime Environment, SE v1.4.2_06 Java™ 6 Update 15 Java™ 6 Update 7 jZip KC Softwares SUMo Keno Craze Special Edition kgcbaby kgcbase kgchday kgchlwn kgcinvt kgckids kgcmove kgcvday Kodak EasyShare software Kombat Kars Special Edition Kronen-Design 1.39b Shareware KSU lcc-win32 version 3.2 (base system) LeadTool Learn2 Player (Uninstall Only) Lernout & Hauspie TruVoice American English TTS Engine LS_HSI Max Mix Foto Mechanic Meijer Photo Software by HP Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Outlook Web Access S/MIME Microsoft Plus! Digital Media Edition Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft Text-to-Speech Engine 4.0 (English) Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Works 7.0 Microsoft WSE 3.0 Runtime Morpheus 5.1 (remove only) Motherboard Monitor 5 Mozilla Firefox (3.5.2) MSN Toolbar MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) Musicmatch® Jukebox MVP Word Search Node Jumper Special Edition Notifier NVIDIA Ethernet Driver NVIDIA GART Driver OfotoXMI Old West Poker Special Edition Online help of lcc-win32 OpenOffice.org 3.1 Opera 9.64 OTtBP OTtBPSDK Pando Pando Toolbar PC-Doctor for Windows PC Alert 4 PC Inspector File Recovery PCDADDIN PCDHELP PCDrdsho PE Builder 3.1.10a PHP 5.3.0 Plaxo Toolbar for Outlook and Outlook Express PowerDVD Professor Wilde Puzzle Master 5 QuickLink Mobile QuickTime Radio@Netscape RealArcade Really Slick Screensavers 1.0 RealPlayer Realtek AC'97 Audio Rhapsody Road Runner Medic 5.2 Roulette Fever Special Edition Scan Secret Circuit Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB973540) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) SETI@home-MapView v6.54 SFR SFR2 SHASTA SKIN0001 SKINXSDK Smart Defrag 1.20 Snake Arena Special Edition Sokoban YASC Sonic RecordNow! Sonic the Hedgehog Adventure 3 Sonic Update Manager SpeedFan (remove only) Spelling Dictionaries Support For Adobe Reader 9 Spybot - Search & Destroy staticcr SureThing CD Labeler 4 SE Sweet Home 3D Sweet Home 3D version 1.7 Switch Uninstall System47 Screen Saver The GIMP 2.2.9 The Grudge Wallpaper Tri Peaks Trillian TTSReader 1.20 TurnOff TV Guide Crosswords TweakNow RegCleaner Standard U.S. Video Poker Special Edition UBCD4Win 3.06 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows XP (KB968389) Update for Windows XP (KB973815) USB MassStorage CardReader UTStarcom USB Modem Software VC 9.0 Runtime VC80CRTRedist - 8.0.50727.762 Viewpoint Manager (Remove Only) Viewpoint Media Player Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 VPRINTOL WebFldrs XP Webshots Desktop Webshots Toolbar Western Video Poker WhatPulse Wild Wheels Special Edition Winamp (remove only) Windows Defender Windows Defender Signatures Windows Genuine Advantage v1.3.0254.0 Windows Imaging Component Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows Search 4.0 Windows XP Service Pack 3 WinISO 5.3 WinRAR archiver WIRELESS Word Wiz Yahoo! Address AutoComplete Yahoo! extras Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Search Protection Yahoo! Software Update Yahoo! Toolbar Yahoo! Widgets Zone Deluxe Games ==== Event Viewer Messages From Past Week ======== 9/1/2009 11:24:19 PM, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:. 8/26/2009 11:11:15 AM, error: Service Control Manager [7031] - The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 8/26/2009 11:11:10 AM, error: Service Control Manager [7034] - The IS360service service terminated unexpectedly. It has done this 1 time(s). 8/26/2009 11:10:51 AM, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 1 time(s). 8/26/2009 10:58:34 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 8/26/2009 10:37:48 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). ==== End Of File ===========================
Hi,

Just a couple of files there to delete, the rest are not actual infections, just risk tools, if you are aware of them and downloaded them yourself, they are fine.


Please do the following:

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/q "C:\Program Files\Common Files\Real\Toolbar\RealBar.dll" "C:\Program Files\Mozilla Firefox\plugins\NPPandBr.dll"


NEXT

P2P - I see you have P2P software BitTorrent and DNA installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT


The rest of your log is clean, just some housekeeping to do now:

Please do the following:

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Scroll down to the Java SE Runtime Environment (JRE) option.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 16)


NEXT


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If there are any other logs/tools remaining > right click and delete them

NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI