This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Could not connect to Internet, but fixed that. What t

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A friend asked me to look into why they were not able to connect to the Internet for the past two weeks. Took me two days to finally get it connected. I could ping other machines on my network. The machine showed I had a connection, but could not connect via IE7 or Firefox. They have NOD32 Antivirus. Have not heard of this antivirus, is it any good. I usually use AVG or Comodo. I ran Norton_Removal_Tool.exe and it fixed my connection. So, I want to find and delete all the other junk on this box (if any). The things I have done so far: Spybot S&D Ad-Aware ATF Cleaner Malwarebytes' Anti-Malware Rebooted machine. Then I ran all the steps in the "Welcome New Members" post and am posting/attaching the requested reports along with the Malwarebytes' report. Thank you in advance for your help! Malwarebytes' Anti-Malware 1.40 Database version: 2684 Windows 5.1.2600 Service Pack 3 8/23/2009 4:12:37 PM mbam-log-2009-08-23 (16-12-37).txt Scan type: Quick Scan Objects scanned: 102499 Time elapsed: 3 minute(s), 37 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 7 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d8c924bf-9feb-4d1f-a400-416aa336de82} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d8c924bf-9feb-4d1f-a400-416aa336de82} (Adware.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\Save (Adware.WhenUSave) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\Mozilla Firefox\Components\SaveComponent.dll (Adware.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\win70.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Program Files\Save\SaveUninst.exe (Adware.WhenUSave) -> Quarantined and deleted successfully. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/23 16:58 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF39A0000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF79BB000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xBA8F1000 Size: 49152 File Visible: No Signed: - Status: - Name: xyjels.sys Image Path: xyjels.sys Address: 0xF7487000 Size: 61440 File Visible: No Signed: - Status: - ==EOF== DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 16:51:39.79 on Sun 08/23/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.391 [GMT -4:00] AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\WINDOWS\system32\agrsmsvc.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe C:\Program Files\Kodak\AiO\center\KodakSvc.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\Acer\Empowering Technology\eRecovery\eRAgent.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\fxssvc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\mom\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank uSearch Page = uDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0509&m=el1200-06w uSearch Bar = mDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0509&m=el1200-06w mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0509&m=el1200-06w mSearch Bar = about:blank mSearchAssistant = BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll TB: Mirar: {d8c924be-9feb-4d1f-a400-416aa336de82} - c:\windows\system32\win7078.dll TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File EB: &Save Branding Window: {2c5a7a51-7e8d-497e-852a-d63ad9014e14} - %SystemRoot%\system32\shdocvw.dll uRun: [Save] c:\documents and settings\mom\application data\save\Save.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [LaunchApp] mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0" mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter" mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe" mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\eRAgent.exe mRun: [Conime] %windir%\system32\conime.exe mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: c:\windows\system32\imon.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\mom\applic~1\mozilla\firefox\profiles\7pfxp4ze.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-20 64160] R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-8-8 15424] R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384] R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\aio\center\KodakSvc.exe [2008-12-1 28672] R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2009-8-8 552064] R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-7 50424] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-4 131072] S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\EKDiscovery.exe [2008-10-10 274432] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456] =============== Created Last 30 ================ 2009-08-23 15:56 –d—– c:\docume~1\mom\applic~1\Malwarebytes 2009-08-23 15:56 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-23 15:56 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-23 15:56 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-23 15:56 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-23 11:03 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-08-21 00:52 116,224 ac—— c:\windows\system32\dllcache\xrxwiadr.dll 2009-08-21 00:50 53,760 ac—— c:\windows\system32\dllcache\wiamsmud.dll 2009-08-21 00:49 249,402 ac—— c:\windows\system32\dllcache\vinwm.sys 2009-08-21 00:48 94,720 ac—— c:\windows\system32\dllcache\umaxud32.dll 2009-08-21 00:47 159,232 ac—— c:\windows\system32\dllcache\tridkbm.sys 2009-08-21 00:46 17,129 ac—— c:\windows\system32\dllcache\tdkcd31.sys 2009-08-21 00:45 155,648 ac—— c:\windows\system32\dllcache\stlnprop.dll 2009-08-21 00:44 9,600 ac—— c:\windows\system32\dllcache\sonymc.sys 2009-08-21 00:43 91,294 ac—— c:\windows\system32\dllcache\skfpwin.sys 2009-08-21 00:42 36,480 ac—— c:\windows\system32\dllcache\sfmanm.sys 2009-08-21 00:41 61,504 ac—— c:\windows\system32\dllcache\s3sav3dm.sys 2009-08-21 00:40 79,104 ac—— c:\windows\system32\dllcache\rocket.sys 2009-08-21 00:39 35,328 ac—— c:\windows\system32\dllcache\psisload.dll 2009-08-21 00:38 29,769 ac—— c:\windows\system32\dllcache\pcntn5m.sys 2009-08-21 00:37 43,689 ac—— c:\windows\system32\dllcache\otceth5.sys 2009-08-21 00:36 132,695 ac—— c:\windows\system32\dllcache\netwlan5.sys 2009-08-21 00:35 19,968 ac—— c:\windows\system32\dllcache\mxicfg.dll 2009-08-21 00:34 12,160 ac—— c:\windows\system32\dllcache\mouhid.sys 2009-08-21 00:33 802,683 ac—— c:\windows\system32\dllcache\ltsm.sys 2009-08-21 00:32 18,688 ac—— c:\windows\system32\dllcache\irsir.sys 2009-08-21 00:31 141,056 ac—— c:\windows\system32\dllcache\icam3.sys 2009-08-21 00:30 115,807 ac—— c:\windows\system32\dllcache\hsf_fsks.sys 2009-08-21 00:29 2,688 ac—— c:\windows\system32\dllcache\hidswvd.sys 2009-08-21 00:28 27,165 ac—— c:\windows\system32\dllcache\fetnd5.sys 2009-08-21 00:27 53,248 ac—— c:\windows\system32\dllcache\eqndiag.exe 2009-08-21 00:26 8,704 ac—— c:\windows\system32\dllcache\dot4scan.sys 2009-08-21 00:25 179,584 ac—— c:\windows\system32\dllcache\dac2w2k.sys 2009-08-21 00:24 7,680 ac—— c:\windows\system32\dllcache\cd20xrnt.sys 2009-08-21 00:23 26,624 ac—— c:\windows\system32\dllcache\ativxbar.sys 2009-08-21 00:22 7,424 ac—— c:\windows\system32\dllcache\adicvls.sys 2009-08-20 23:58 3,948 a——- c:\windows\system32\drivers\nvphy.bin 2009-08-20 23:58 442,368 a——- c:\windows\system32\nvunrm.exe 2009-08-20 23:58 5,836 a——- c:\windows\system32\nvnrm.nvu 2009-08-20 23:53 230,629 a——- c:\windows\system32\Autorun.ini 2009-08-20 23:52 950,272 a——- c:\windows\system32\drivers\nvnrm.sys 2009-08-20 23:52 54,016 a——- c:\windows\system32\drivers\NVENETFD.sys 2009-08-20 23:52 22,016 a——- c:\windows\system32\drivers\nvnetbus.sys 2009-08-20 23:52 35,840 a——- c:\windows\system32\nvconrm.dll 2009-08-20 23:52 199,168 a——- c:\windows\system32\fdco1.dll 2009-08-20 23:52 9,216 a——- c:\windows\system32\bdco1.dll 2009-08-20 23:51 –d—– c:\windows\system32\autorun 2009-08-20 23:26 442,368 a——- c:\windows\system32\NVUSMU.EXE 2009-08-20 22:53 –d—– c:\docume~1\mom\applic~1\AVG8 2009-08-20 20:10 15,688 a——- c:\windows\system32\lsdelete.exe 2009-08-20 19:50 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-08-20 19:50 -cd-h— c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864} 2009-08-20 19:50 –d—– c:\program files\Lavasoft 2009-08-20 18:46 265 a——- c:\windows\wininit.ini 2009-08-20 18:28 –d—– c:\program files\Spybot - Search & Destroy 2009-08-20 18:28 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-08-20 18:17 –d—– c:\windows\pss 2009-08-19 20:17 –d—– c:\program files\common files\Nova Development 2009-08-19 20:12 –d—– c:\program files\Nova Development 2009-08-19 19:54 –d—– c:\windows\system32\XPSViewer 2009-08-19 19:53 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-19 19:53 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-19 19:53 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-19 19:53 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-19 19:53 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-19 19:53 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-08-19 19:53 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-16 14:39 16 a——- c:\windows\popcinfo.dat 2009-08-16 12:38 –d—– c:\docume~1\mom\applic~1\WildTangent 2009-08-13 21:14 –d—– c:\documents and settings\mom\Option 2009-08-13 20:25 –d—– c:\windows\system32\wbem\Repository 2009-08-13 20:24 –d—– c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP 2009-08-09 19:04 –d—– c:\program files\Mozilla Firefox(2) 2009-08-08 11:12 512,096 a——- c:\windows\system32\drivers\amon.sys 2009-08-08 11:12 298,104 a——- c:\windows\system32\imon.dll 2009-08-08 11:12 15,424 a——- c:\windows\system32\drivers\nod32drv.sys 2009-08-08 11:12 –d—– c:\program files\ESET 2009-08-06 16:15 –d—– c:\program files\KingsIsle Entertainment 2009-07-27 18:13 –d—– c:\program files\Unity 2009-07-25 23:38 1,071 a——- c:\windows\AWMODEM.INF ==================== Find3M ==================== 2009-08-13 21:56 143,028 a——- c:\windows\pchealth\helpctr\config\cache\Personal_32_1033.dat 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-12 15:21 233,472 a——- c:\windows\system32\wmpdxm.dll 2009-06-29 12:12 827,392 a——- c:\windows\system32\wininet.dll 2009-06-29 12:12 78,336 a——- c:\windows\system32\ieencode.dll 2009-06-29 12:12 17,408 a——- c:\windows\system32\corpol.dll 2009-06-25 04:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 04:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 04:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 04:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 04:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 04:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe 2009-06-10 12:19 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-05-30 17:51 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2008-10-28 21:14 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat ============= FINISH: 16:52:12.53 ===============

Attachments:

Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Thanks for your help. When I tried to run ComboFix it said NOD32 antivirus was still running after I shut it down. I could not figure out how to stop it from running in the background so I uninstalled it and rebooted the machine. Restarted ComboFix and it still said it was running. Ran ComboFix anyway and here is the log file:

ComboFix 09-08-22.06 - mom 08/24/2009 0:16.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.569 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-1314201555-3785290187-2462946864-1006
c:\windows\APanel.exe
c:\windows\Installer\2a7a44.msi
c:\windows\Installer\2a7a5d.msi
c:\windows\Installer\7e82.msi
c:\windows\system32\autorun.ini

.
((((((((((((((((((((((((( Files Created from 2009-07-24 to 2009-08-24 )))))))))))))))))))))))))))))))
.

2009-08-23 20:47 . 2009-08-23 20:47 ——– d—–w- c:\program files\ERUNT
2009-08-23 19:56 . 2009-08-23 19:56 ——– d—–w- c:\documents and settings\mom\Application Data\Malwarebytes
2009-08-23 19:56 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-23 19:56 . 2009-08-23 19:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-23 19:56 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-23 19:56 . 2009-08-23 19:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-23 15:03 . 2009-08-23 15:03 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-08-21 04:52 . 2008-04-14 09:42 116224 -c–a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2009-08-21 04:50 . 2001-08-18 02:36 53760 -c–a-w- c:\windows\system32\dllcache\wiamsmud.dll
2009-08-21 04:49 . 2001-08-17 16:14 249402 -c–a-w- c:\windows\system32\dllcache\vinwm.sys
2009-08-21 04:48 . 2001-08-18 02:36 94720 -c–a-w- c:\windows\system32\dllcache\umaxud32.dll
2009-08-21 04:47 . 2001-08-17 16:51 159232 -c–a-w- c:\windows\system32\dllcache\tridkbm.sys
2009-08-21 04:46 . 2001-08-17 16:13 17129 -c–a-w- c:\windows\system32\dllcache\tdkcd31.sys
2009-08-21 04:45 . 2001-08-18 02:36 155648 -c–a-w- c:\windows\system32\dllcache\stlnprop.dll
2009-08-21 04:44 . 2008-04-14 04:10 7552 -c–a-w- c:\windows\system32\dllcache\sonyait.sys
2009-08-21 04:43 . 2001-08-17 16:12 91294 -c–a-w- c:\windows\system32\dllcache\skfpwin.sys
2009-08-21 04:42 . 2001-08-17 16:19 36480 -c–a-w- c:\windows\system32\dllcache\sfmanm.sys
2009-08-21 04:41 . 2001-08-17 16:50 61504 -c–a-w- c:\windows\system32\dllcache\s3sav3dm.sys
2009-08-21 04:40 . 2008-04-14 22:00 30592 -c–a-w- c:\windows\system32\dllcache\rndismpx.sys
2009-08-21 04:39 . 2001-08-18 02:36 35328 -c–a-w- c:\windows\system32\dllcache\psisload.dll
2009-08-21 04:38 . 2001-08-17 16:11 29769 -c–a-w- c:\windows\system32\dllcache\pcntn5m.sys
2009-08-21 04:37 . 2001-08-17 16:12 43689 -c–a-w- c:\windows\system32\dllcache\otceth5.sys
2009-08-21 04:36 . 2008-04-14 02:05 132695 -c–a-w- c:\windows\system32\dllcache\netwlan5.sys
2009-08-21 04:35 . 2001-08-18 02:36 19968 -c–a-w- c:\windows\system32\dllcache\mxicfg.dll
2009-08-21 04:34 . 2001-08-17 17:48 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys
2009-08-21 04:33 . 2001-08-17 17:28 802683 -c–a-w- c:\windows\system32\dllcache\ltsm.sys
2009-08-21 04:32 . 2001-08-17 17:51 18688 -c–a-w- c:\windows\system32\dllcache\irsir.sys
2009-08-21 04:31 . 2001-08-17 18:05 141056 -c–a-w- c:\windows\system32\dllcache\icam3.sys
2009-08-21 04:30 . 2001-08-17 17:28 115807 -c–a-w- c:\windows\system32\dllcache\hsf_fsks.sys
2009-08-21 04:29 . 2001-08-17 18:02 2688 -c–a-w- c:\windows\system32\dllcache\hidswvd.sys
2009-08-21 04:28 . 2001-08-17 16:13 27165 -c–a-w- c:\windows\system32\dllcache\fetnd5.sys
2009-08-21 04:27 . 2001-08-18 02:36 53248 -c–a-w- c:\windows\system32\dllcache\eqndiag.exe
2009-08-21 04:26 . 2001-08-17 17:47 8704 -c–a-w- c:\windows\system32\dllcache\dot4scan.sys
2009-08-21 04:25 . 2008-04-14 22:00 179584 -c–a-w- c:\windows\system32\dllcache\dac2w2k.sys
2009-08-21 04:24 . 2008-04-14 22:00 7680 -c–a-w- c:\windows\system32\dllcache\cd20xrnt.sys
2009-08-21 04:23 . 2001-08-17 16:49 26624 -c–a-w- c:\windows\system32\dllcache\ativxbar.sys
2009-08-21 04:22 . 2001-08-17 17:53 7424 -c–a-w- c:\windows\system32\dllcache\adicvls.sys
2009-08-21 03:58 . 2008-01-17 10:17 3948 —-a-w- c:\windows\system32\drivers\nvphy.bin
2009-08-21 03:58 . 2008-03-06 21:23 442368 —-a-w- c:\windows\system32\nvunrm.exe
2009-08-21 03:52 . 2008-01-29 16:37 22016 —-a-w- c:\windows\system32\drivers\nvnetbus.sys
2009-08-21 03:52 . 2008-01-29 16:37 54016 —-a-w- c:\windows\system32\drivers\NVENETFD.sys
2009-08-21 03:52 . 2008-01-29 16:37 950272 —-a-w- c:\windows\system32\drivers\nvnrm.sys
2009-08-21 03:52 . 2008-01-29 16:13 35840 —-a-w- c:\windows\system32\nvconrm.dll
2009-08-21 03:52 . 2008-02-19 22:13 199168 —-a-w- c:\windows\system32\fdco1.dll
2009-08-21 03:52 . 2008-01-29 16:36 9216 —-a-w- c:\windows\system32\bdco1.dll
2009-08-21 03:51 . 2009-08-21 03:53 ——– d—–w- c:\windows\system32\autorun
2009-08-21 03:26 . 2008-04-02 19:32 442368 —-a-w- c:\windows\system32\NVUSMU.EXE
2009-08-21 02:57 . 2009-08-21 02:57 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-08-21 02:53 . 2009-08-21 02:53 ——– d—–w- c:\documents and settings\mom\Application Data\AVG8
2009-08-21 00:10 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-08-20 23:50 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-20 23:50 . 2009-08-21 02:53 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-20 23:50 . 2009-07-08 17:28 2920112 -c–a-w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-08-20 23:50 . 2009-08-21 02:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-20 23:50 . 2009-08-20 23:50 ——– d—–w- c:\program files\Lavasoft
2009-08-20 22:28 . 2009-08-23 19:43 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-20 22:28 . 2009-08-21 02:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-20 00:17 . 2009-08-20 00:17 ——– d—–w- c:\program files\Common Files\Nova Development
2009-08-20 00:12 . 2009-08-20 00:17 ——– d—–w- c:\program files\Nova Development
2009-08-19 23:54 . 2009-08-19 23:54 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-19 23:54 . 2009-08-19 23:54 ——– d—–w- c:\program files\MSBuild
2009-08-19 23:54 . 2009-08-19 23:54 ——– d—–w- c:\program files\Reference Assemblies
2009-08-19 23:53 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-19 23:53 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-19 23:53 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-19 23:53 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-19 23:53 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-19 23:53 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-19 23:53 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-16 18:39 . 2009-08-20 02:58 16 —-a-w- c:\windows\popcinfo.dat
2009-08-16 16:38 . 2009-08-16 16:38 ——– d—–w- c:\documents and settings\mom\Application Data\WildTangent
2009-08-14 01:14 . 2009-08-14 01:14 ——– d—–w- c:\documents and settings\mom\Option
2009-08-14 00:25 . 2009-08-14 00:25 ——– d—–w- c:\windows\system32\wbem\Repository
2009-08-14 00:24 . 2009-08-14 00:24 ——– d—–w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2009-08-13 12:56 . 2009-08-13 12:56 ——– d—–w- c:\documents and settings\isaiah south\Local Settings\Application Data\Mozilla
2009-08-09 23:04 . 2009-08-09 23:04 0 —-a-w- c:\windows\nsreg.dat
2009-08-09 23:04 . 2009-08-09 23:04 ——– d—–w- c:\documents and settings\mom\Local Settings\Application Data\Mozilla
2009-08-09 23:04 . 2009-08-14 00:24 ——– d—–w- c:\program files\Mozilla Firefox(2)
2009-08-08 21:26 . 2009-08-08 21:26 ——– d—–w- c:\documents and settings\isaiah south\Local Settings\Application Data\Identities
2009-08-08 21:00 . 2009-08-08 21:00 ——– d—–w- c:\documents and settings\isaiah south\Application Data\Template
2009-08-08 15:12 . 2009-08-08 15:12 298104 —-a-w- c:\windows\system32\imon.dll
2009-08-08 15:12 . 2009-08-08 15:12 512096 —-a-w- c:\windows\system32\drivers\amon.sys
2009-08-08 15:12 . 2009-08-08 15:12 15424 —-a-w- c:\windows\system32\drivers\nod32drv.sys
2009-08-06 20:15 . 2009-08-06 20:15 ——– d—–w- c:\program files\KingsIsle Entertainment
2009-08-03 22:19 . 2009-08-03 22:19 ——– d—–w- c:\documents and settings\isaiah south\Local Settings\Application Data\Eastman_Kodak_Company
2009-07-27 22:13 . 2009-07-27 22:13 ——– d—–w- c:\documents and settings\isaiah south\Local Settings\Application Data\Unity
2009-07-27 22:13 . 2009-07-27 22:13 ——– d—–w- c:\program files\Unity

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-23 15:04 . 2008-10-29 01:27 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-23 15:04 . 2008-10-29 01:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-23 15:02 . 2009-07-08 23:13 ——– d—–w- c:\documents and settings\mom\Application Data\Save
2009-08-21 02:53 . 2008-10-29 01:37 ——– d—–w- c:\program files\BigFix
2009-08-21 01:05 . 2008-10-29 01:06 ——– d—–w- c:\program files\Google
2009-08-20 21:47 . 2009-07-08 18:20 ——– d—–w- c:\documents and settings\mom\Application Data\LimeWire
2009-08-20 00:26 . 2009-07-08 02:24 80440 —-a-w- c:\documents and settings\mom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-16 17:07 . 2008-10-29 01:09 ——– d—–w- c:\documents and settings\All Users\Application Data\WildTangent
2009-08-14 01:33 . 2009-05-30 01:31 ——– d—–w- c:\program files\Selectsoft
2009-08-08 21:00 . 2009-08-08 21:00 0 —-a-w- c:\documents and settings\isaiah south\Application Data\wklnhst.dat
2009-08-08 16:09 . 2009-07-08 18:19 ——– d—–w- c:\program files\LimeWire
2009-08-06 20:15 . 2008-10-29 01:37 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-05 09:01 . 2008-04-14 22:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2008-04-14 22:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-12 19:21 . 2008-04-14 22:00 233472 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-12 18:23 . 2009-05-29 23:15 ——– d—–w- c:\documents and settings\isaiah south\Application Data\Temp
2009-07-08 23:37 . 2008-10-29 01:04 1024 —h–r- c:\windows\system32\NTIMP3.dll
2009-07-08 23:13 . 2009-07-08 23:13 92504 —-a-w- c:\documents and settings\mom\Application Data\Save\SaveUninst.exe
2009-06-29 16:12 . 2007-08-14 02:54 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-04-14 22:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-14 22:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2008-04-14 22:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2008-04-14 22:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2008-04-14 22:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2008-04-14 22:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2008-04-14 22:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2008-04-14 22:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2008-04-14 22:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2008-04-14 22:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-04-14 22:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2008-04-14 22:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 16:19 . 2008-04-14 22:00 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2008-04-14 22:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2008-04-14 22:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2008-04-14 22:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-30 21:51 . 2008-10-29 00:51 76487 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-29 21:12 . 2009-05-29 21:12 60664 —-a-w- c:\documents and settings\isaiah south\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-25 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-25 81920]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-09-25 210216]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-07-10 421888]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2008-10-22 1310720]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-02-25 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\Client\\Agentsvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\BackupSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\SchedulerSvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9322:TCP"= 9322:TCP:EKDiscovery
"9323:TCP"= 9323:TCP:EKDiscovery

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/20/2009 7:50 PM 64160]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [8/8/2009 11:12 AM 15424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 5:11 PM 16384]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\AiO\Center\KodakSvc.exe [12/1/2008 9:58 PM 28672]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 10:49 AM 1029456]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 2:42 AM 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 7:03 AM 131072]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\EKDiscovery.exe [10/10/2008 12:33 PM 274432]
.
Contents of the 'Scheduled Tasks' folder

2009-08-20 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2021444666-2160809809-2054387210-1006Core.job
- c:\documents and settings\isaiah south\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-12 15:45]

2009-08-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2021444666-2160809809-2054387210-1006UA.job
- c:\documents and settings\isaiah south\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-12 15:45]
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{D8C924BE-9FEB-4D1F-A400-416AA336DE82} - c:\windows\system32\win7078.dll
WebBrowser-{D8C924BE-9FEB-4D1F-A400-416AA336DE82} - c:\windows\system32\win7078.dll
HKCU-Run-Save - c:\documents and settings\mom\Application Data\Save\Save.exe
HKLM-Run-LaunchApp - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0509&m=el1200-06w
mSearch Bar = about:blank
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\documents and settings\mom\Application Data\Mozilla\Firefox\Profiles\7pfxp4ze.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-24 00:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2021444666-2160809809-2054387210-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(732)
c:\windows\system32\imon.dll
.
Completion time: 2009-08-24 0:21
ComboFix-quarantined-files.txt 2009-08-24 04:21

Pre-Run: 56,767,184,896 bytes free
Post-Run: 56,743,956,480 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

301 — E O F — 2009-08-21 07:00
Hi,

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Thanks for the reply. Here are the reports from both scans: Malwarebytes' Anti-Malware 1.40 Database version: 2691 Windows 5.1.2600 Service Pack 3 8/24/2009 6:40:13 PM mbam-log-2009-08-24 (18-40-13).txt Scan type: Quick Scan Objects scanned: 102505 Time elapsed: 3 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, August 24, 2009 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, August 25, 2009 00:49:17 Records in database: 2684991 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ Scan statistics: Objects scanned: 76274 Threats found: 2 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 01:44:45 File name / Threat / Threats count C:\System Volume Information\_restore{04B20ACC-AE7D-4F34-B547-573C2828457F}\RP26\A0132468.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1 C:\System Volume Information\_restore{04B20ACC-AE7D-4F34-B547-573C2828457F}\RP26\A0132478.dll Infected: not-a-virus:WebToolbar.Win32.Zango.ce 1 Selected area has been scanned.
Ran DSS and here are the results: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:14:32.64 on Tue 08/25/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.402 [GMT -4:00] AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\system32\agrsmsvc.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe C:\Program Files\Kodak\AiO\center\KodakSvc.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\fxssvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\Acer\Empowering Technology\eRecovery\eRAgent.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\mom\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0509&m=el1200-06w mSearch Bar = about:blank BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File EB: {2C5A7A51-7E8D-497E-852A-D63AD9014E14} - No File uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0" mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter" mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe" mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [RTHDCPL] RTHDCPL.EXE mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\eRAgent.exe mRun: [Conime] %windir%\system32\conime.exe mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: c:\windows\system32\imon.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\mom\applic~1\mozilla\firefox\profiles\7pfxp4ze.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-20 64160] R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-8-8 15424] R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384] R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\aio\center\KodakSvc.exe [2008-12-1 28672] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456] R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-7 50424] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-4 131072] S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\EKDiscovery.exe [2008-10-10 274432] =============== Created Last 30 ================ 2009-08-24 00:20 -cd—– c:\windows\system32\dllcache\cache 2009-08-24 00:16 a-dshr– C:\cmdcons 2009-08-24 00:15 229,376 a——- c:\windows\PEV.exe 2009-08-24 00:15 161,792 a——- c:\windows\SWREG.exe 2009-08-24 00:15 98,816 a——- c:\windows\sed.exe 2009-08-24 00:15 –ds—- C:\ComboFix 2009-08-23 15:56 –d—– c:\docume~1\mom\applic~1\Malwarebytes 2009-08-23 15:56 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-23 15:56 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-23 15:56 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-23 15:56 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-23 11:03 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-08-21 00:52 116,224 ac—— c:\windows\system32\dllcache\xrxwiadr.dll 2009-08-21 00:50 53,760 ac—— c:\windows\system32\dllcache\wiamsmud.dll 2009-08-21 00:49 249,402 ac—— c:\windows\system32\dllcache\vinwm.sys 2009-08-21 00:48 94,720 ac—— c:\windows\system32\dllcache\umaxud32.dll 2009-08-21 00:47 159,232 ac—— c:\windows\system32\dllcache\tridkbm.sys 2009-08-21 00:46 17,129 ac—— c:\windows\system32\dllcache\tdkcd31.sys 2009-08-21 00:45 155,648 ac—— c:\windows\system32\dllcache\stlnprop.dll 2009-08-21 00:44 9,600 ac—— c:\windows\system32\dllcache\sonymc.sys 2009-08-21 00:43 91,294 ac—— c:\windows\system32\dllcache\skfpwin.sys 2009-08-21 00:42 36,480 ac—— c:\windows\system32\dllcache\sfmanm.sys 2009-08-21 00:41 61,504 ac—— c:\windows\system32\dllcache\s3sav3dm.sys 2009-08-21 00:40 79,104 ac—— c:\windows\system32\dllcache\rocket.sys 2009-08-21 00:39 35,328 ac—— c:\windows\system32\dllcache\psisload.dll 2009-08-21 00:38 29,769 ac—— c:\windows\system32\dllcache\pcntn5m.sys 2009-08-21 00:37 43,689 ac—— c:\windows\system32\dllcache\otceth5.sys 2009-08-21 00:36 132,695 ac—— c:\windows\system32\dllcache\netwlan5.sys 2009-08-21 00:35 19,968 ac—— c:\windows\system32\dllcache\mxicfg.dll 2009-08-21 00:34 12,160 ac—— c:\windows\system32\dllcache\mouhid.sys 2009-08-21 00:33 802,683 ac—— c:\windows\system32\dllcache\ltsm.sys 2009-08-21 00:32 18,688 ac—— c:\windows\system32\dllcache\irsir.sys 2009-08-21 00:31 141,056 ac—— c:\windows\system32\dllcache\icam3.sys 2009-08-21 00:30 115,807 ac—— c:\windows\system32\dllcache\hsf_fsks.sys 2009-08-21 00:29 2,688 ac—— c:\windows\system32\dllcache\hidswvd.sys 2009-08-21 00:28 27,165 ac—— c:\windows\system32\dllcache\fetnd5.sys 2009-08-21 00:27 53,248 ac—— c:\windows\system32\dllcache\eqndiag.exe 2009-08-21 00:26 8,704 ac—— c:\windows\system32\dllcache\dot4scan.sys 2009-08-21 00:25 179,584 ac—— c:\windows\system32\dllcache\dac2w2k.sys 2009-08-21 00:24 7,680 ac—— c:\windows\system32\dllcache\cd20xrnt.sys 2009-08-21 00:23 26,624 ac—— c:\windows\system32\dllcache\ativxbar.sys 2009-08-21 00:22 7,424 ac—— c:\windows\system32\dllcache\adicvls.sys 2009-08-20 23:58 3,948 a——- c:\windows\system32\drivers\nvphy.bin 2009-08-20 23:58 442,368 a——- c:\windows\system32\nvunrm.exe 2009-08-20 23:58 5,836 a——- c:\windows\system32\nvnrm.nvu 2009-08-20 23:52 950,272 a——- c:\windows\system32\drivers\nvnrm.sys 2009-08-20 23:52 54,016 a——- c:\windows\system32\drivers\NVENETFD.sys 2009-08-20 23:52 22,016 a——- c:\windows\system32\drivers\nvnetbus.sys 2009-08-20 23:52 35,840 a——- c:\windows\system32\nvconrm.dll 2009-08-20 23:52 199,168 a——- c:\windows\system32\fdco1.dll 2009-08-20 23:52 9,216 a——- c:\windows\system32\bdco1.dll 2009-08-20 23:51 –d—– c:\windows\system32\autorun 2009-08-20 23:26 442,368 a——- c:\windows\system32\NVUSMU.EXE 2009-08-20 22:53 –d—– c:\docume~1\mom\applic~1\AVG8 2009-08-20 20:10 15,688 a——- c:\windows\system32\lsdelete.exe 2009-08-20 19:50 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-08-20 19:50 -cd-h— c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864} 2009-08-20 19:50 –d—– c:\program files\Lavasoft 2009-08-20 18:46 265 a——- c:\windows\wininit.ini 2009-08-20 18:28 –d—– c:\program files\Spybot - Search & Destroy 2009-08-20 18:28 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-08-20 18:17 –d—– c:\windows\pss 2009-08-19 20:17 –d—– c:\program files\common files\Nova Development 2009-08-19 20:12 –d—– c:\program files\Nova Development 2009-08-19 19:54 –d—– c:\windows\system32\XPSViewer 2009-08-19 19:53 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-19 19:53 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-19 19:53 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-19 19:53 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-19 19:53 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-19 19:53 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-08-19 19:53 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-16 14:39 16 a——- c:\windows\popcinfo.dat 2009-08-16 12:38 –d—– c:\docume~1\mom\applic~1\WildTangent 2009-08-13 21:14 –d—– c:\documents and settings\mom\Option 2009-08-13 20:25 –d—– c:\windows\system32\wbem\Repository 2009-08-13 20:24 –d—– c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP 2009-08-09 19:04 –d—– c:\program files\Mozilla Firefox(2) 2009-08-08 11:12 512,096 a——- c:\windows\system32\drivers\amon.sys 2009-08-08 11:12 298,104 a——- c:\windows\system32\imon.dll 2009-08-08 11:12 15,424 a——- c:\windows\system32\drivers\nod32drv.sys 2009-08-06 16:15 –d—– c:\program files\KingsIsle Entertainment 2009-07-27 18:13 –d—– c:\program files\Unity ==================== Find3M ==================== 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-12 15:21 233,472 a——- c:\windows\system32\wmpdxm.dll 2009-06-29 12:12 827,392 ——– c:\windows\system32\wininet.dll 2009-06-29 12:12 78,336 a——- c:\windows\system32\ieencode.dll 2009-06-29 12:12 17,408 a——- c:\windows\system32\corpol.dll 2009-06-25 04:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 04:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 04:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 04:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 04:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 04:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe 2009-06-10 12:19 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-05-30 17:51 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2008-10-28 21:14 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat ============= FINISH: 17:15:04.90 ===============
Hi,

You are clean,

just some housekeeping to do now,

Please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Scroll down to the Java SE Runtime Environment (JRE) option.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 16)


NEXT


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Hey, CatByte, thanks so much for all your help! Glad to hear that the machine is clean. I will run the clean up and use your recommendations about keeping the box clean.

One last question though, I have uninstalled ESET NOD32 using the NOD32RemovalTool.exe because some dll was missing where it would not uninstall itself either through the NOD32 Uninstall or Windows Add Remove Programs. The removal tool worked fine. I even went through the registry and removed any left over items along with other files that were given in this web site: http://kb.eset.com/esetkb/index?page=content&id=SOLN558. My problem is that when Combofix ran it said that the "Real Time Scanner is active for ESET NOD32 antivirus" after I had already uninstalled it. Where is this scanner running and how do I get rid of it? (I plan on installing AVG antivirus.)

Thanks!
Hi,

Use the eset uninstaller:

ESET Uninstaller:

A removal tool can be downloaded from here, save it to the Desktop.

It is in Dutch but very simple to use as follows:

1. Double-click on nod32removal to start the application.
2. Click on Yes then on OK.
3. ESET is now removed.
4. Now delete nod32removal and empty the Recycle Bin.
5. Now Reboot(restart) your computer.
Already did that prior to running ComboFix (as described in my last post) and still get the message, "Real Time Scanner is active for ESET NOD32 antivirus." Does this "Real Time Scanner" that is STILL running matter if I load AVG? I would like to get rid of it though.
Hi,

Please do the following:

Open Notepad

Click Start >Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.

Copy the text inside of the code box, Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Now paste the copied text into the open notepad, press CTRL+V (or right click and choose 'paste')

Note: There must be NO blank lines in front of the pasted text, but ensure that there is a blank line at the end of the text, otherwise the registry merge will not work.

REGEDIT4

[-HKEY_CLASSES_ROOT\clsid\{E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ]

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in fixme.reg as the file name, then choose All Files as the save as file type.
Then click the save button.
Once you have clicked the save button, close Notepad.

You should now see a file on your desktop that looks like this:

[external image: Posted Image]

Locate the fixme.reg icon on your desktop and double click it, an information box will pop up asking if you want to merge the information in the file into the registry, click YES.

Once the file has run, the information will have merged with your registry so you can delete fixme.reg from your desktop as you won't be needing it any more.


NEXT


Click Start → Control Panel → Folder Options → View tab → select Show hidden files and folders.

delete the folders below: (if they still exist)

C:\Program Files\ESET
C:\Documents and Settings\All Users\Application Data\ESET
C:\Documents and Settings\%USER%\Application Data\ESET

By-the-way, what did the fixme.reg do



hopefully it removed the registry entry for the ESET Real Time Scanner.

Are you still getting the message? or is everything OK now
Only got the message when I ran Combofix and when I ran the Combofix uninstall (and both of the Combofix runs were AFTER I uninstalled NOD32). So, I do not know how to verify that the Real Time Scanner for ESET NOD32 antivirus is not active. Do you know of any way to verify?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI