This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]  Need Help with Complete Removal of AntiVirus Pro 2010

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi modena2904,

Ok, we will clean up now.

From your desktop, please delete
  • any notepads/logs that we created
  • GooredFix.exe
  • GooredFix.txt

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep MBAM updated and use it regularly.


Updates and upgrades

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update


You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 6.0.1 first. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have a antivrus program and an on demand antispyware program (MBAM).

I recommend you use an antispyware program with resident (real time) scanning. I suggest

Winpatrol
OR
Windows Defender


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879


We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".


Take care :adios:
Thank you for your help. I completed the clean-up steps without issue, and have completed your recommended prevention steps. The computer is working very well, so I think this topic is resolved. I submitted a donation to whatthetech via PayPal to help keep your site running. Thanks. - Eric
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
Thanks for re-opening my topic.

Over the last 6 weeks or so since my malware cleansing, I have noticed some odd symptoms with this computer, things that used to work but now don't. None that are showstoppers, but annoying. I don't know if these are related to the original malware infection, but it's as good a place as any to start. Here are the symptoms:

1. Windows Media player is not working fully. When trying to rip a CD in WMP, it fails if you try to rip to the WMV format. Ripping to MP3 format works fine. Also, some video files (WMV) that used to play now don't. WMP says codec not available, but is unsuccessful in downloading the codec.

2. Applications are generally very slow to open. For example, ~15 seconds to open Firefox or Word. Speed within applications seems fine once they are open. Sometimes, they open at "normal" speed if they are closed and then reopened.

3. On the My Computer display, with view by type and in groups, I have a group called “Other” with single entry under it: a generic icon, with no name, and the description “System Folder”. If you right-click on this entry, the only options are "Cut", "Create Shortcut" and "Delete". I attached a screenshot to this reply. I found what appears to be the same problem described here: http://forums.techguy.org/windows-nt-2000-…-folder-my.html, but no solution. This phantom entry doesn't appear to do any harm, but it sure seems like a symptom of some deeper problem.


I have tried to do some troubleshooting on my own regarding the WMP problem. After doing some internet searching, it seems like it might be related to a corrupted DirectShow installation. I tried a few fixes. I installed the K-Lite codec package, which also attempts to repair DirectShow – the installer cited many broken DirectShow registry entries, and was unable to reregister quartz.dll (citing inadequate permission). I also attempted to repair DirectShow using Dial-A-Fix. I used that to restore my registry permissions to default, but it was still unable to reregister quartz.dll (same error).

I also thought about using system restore to return to a restore point prior to the malware infection. However, I found that for some reason, I don't have any restore points available except for one on 10/16/09 (which is the day that I looked). System restore is enabled, so I'm not sure why there are no restore points.

Thanks.

- Eric
Hi

I don't have any restore points available except for one on 10/16/09 (which is the day that I looked). System restore is enabled, so I'm not sure why there are no restore points.

Not sure where the Restore points went, you should have had some from early September when we cleaned this machine.

I have a group called “Other” with single entry under it: a generic icon, with no name, and the description

Probably a leatover from something uninstalled. we will have a look.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :reg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace /s
    
    :filefind
    quartz.dll
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Please post back with
  • SystemLook log
  • DDS log

Thanks
I have completed the diagnostics as requested. The log files and attachment are below. I would like to point out that I may have accidentally fixed the slow-opening application problem. As I mentioned in my prior post, I had used the Dial-a-Fix tool to reset registry permissions. I found out this morning that this also apparently turned off file/print sharing on this PC, so I could not access any shares on this PC from other PCs on my home network. I used the network sharing wizard to reactivate file/print sharing. After completing that, the slow-application problem no longer appears to be present. Thanks. - Eric System Look Log File: SystemLook v1.0 by jpshortstuff (29.08.09) Log created at 17:28 on 17/10/2009 by Eric (Administrator - Elevation successful) ========== reg ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace] (No values found) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\Controls] @="{21EC2020-3AEA-1069-A2DD-08002B30309D}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders] (No values found) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}] @="Portable Devices" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{59031a47-3f72-44a7-89c5-5595fe6b30ee}] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{640167b4-59b0-47a6-b335-a6b3c0695aea}] @="Portable Media Devices" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{E211B736-43FD-11D1-9EFB-0000F8757FCD}] @="Scanners & Cameras" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{4AFB2C12-9D16-4478-AEF4-C3FC539961E4}] @="Zen MicroPhoto Media Explorer" ========== filefind ========== Searching for "quartz.dll" C:\WINDOWS\$hf_mig$\KB904706\SP2QFE\quartz.dll –a— 1287680 bytes [04:13 30/08/2005] [04:13 30/08/2005] E2C4A06F5EE1CE5E13F4A4DBF47807B5 C:\WINDOWS\$hf_mig$\KB941568\SP2QFE\quartz.dll –a— 1287680 bytes [22:35 29/10/2007] [22:35 29/10/2007] F1091214867010B4EC86A606FC16D30D C:\WINDOWS\$hf_mig$\KB951698\SP2QFE\quartz.dll –a— 1288192 bytes [04:55 07/05/2008] [04:55 07/05/2008] 4B1ECE9D3F4EDA2952722158DD11DE91 C:\WINDOWS\$hf_mig$\KB951698\SP3GDR\quartz.dll –a— 1288192 bytes [05:12 07/05/2008] [05:12 07/05/2008] 67AE7B2D4B51CD0CFB03CFB4A6402003 C:\WINDOWS\$hf_mig$\KB951698\SP3QFE\quartz.dll –a— 1288192 bytes [05:04 07/05/2008] [05:04 07/05/2008] 76D5F8B56A21E3EA1D8FA2C4EC7C2BEA C:\WINDOWS\$hf_mig$\KB961373\SP3QFE\quartz.dll –a— 1288192 bytes [23:14 20/12/2008] [23:14 20/12/2008] 116445A0D1C07D3121553C78108ACC9D C:\WINDOWS\$hf_mig$\KB971633\SP3QFE\quartz.dll –a— 1291264 bytes [19:12 03/06/2009] [19:12 03/06/2009] A80E6DC3F39CB08B05558EF096FBF69D C:\WINDOWS\$NtServicePackUninstall$\quartz.dll –a–c 1287680 bytes [22:39 17/08/2008] [05:18 07/05/2008] 9C7CC7FA0638177E07B9C194F308B2B9 C:\WINDOWS\$NtUninstallKB904706$\quartz.dll –a–c 1287680 bytes [11:47 06/01/2006] [04:56 04/08/2004] CDBC0E967CB1312E1266CB3ADCB844DD C:\WINDOWS\$NtUninstallKB941568$\quartz.dll –a–c 1287168 bytes [16:00 12/12/2007] [03:54 30/08/2005] 293F5498EE4AF7B31AB2FB3A78C4D7A7 C:\WINDOWS\$NtUninstallKB951698$\quartz.dll –a–c 1288192 bytes [22:51 17/08/2008] [00:12 14/04/2008] B4822C5241762BC96AE8D8B10CD65BC7 C:\WINDOWS\$NtUninstallKB951698_0$\quartz.dll –a–c 1287680 bytes [01:32 11/06/2008] [22:43 29/10/2007] DC15D841E7ABF2DB5DC8815EDBD4A854 C:\WINDOWS\$NtUninstallKB961373$\quartz.dll –a–c 1288192 bytes [15:04 15/04/2009] [05:12 07/05/2008] 67AE7B2D4B51CD0CFB03CFB4A6402003 C:\WINDOWS\$NtUninstallKB971633$\quartz.dll –a–c 1288192 bytes [15:03 15/07/2009] [22:14 20/12/2008] 957B59AC917F1316871450C70FEAB42A C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\quartz.dll –a— 1246208 bytes [00:30 27/03/2004] [14:00 30/05/2003] 4E61D3ADB6C74B37A2E838658AA27200 C:\WINDOWS\RegisteredPackages\{FB8B5424-4B01-433E-AB3B-4B296655D43A}\quartz.dll –a— 1246208 bytes [00:26 27/03/2004] [14:00 30/05/2003] 4E61D3ADB6C74B37A2E838658AA27200 C:\WINDOWS\ServicePackFiles\i386\quartz.dll —— 1288192 bytes [20:28 24/10/2004] [00:12 14/04/2008] B4822C5241762BC96AE8D8B10CD65BC7 C:\WINDOWS\system32\dllcache\quartz.dll –a–c 1291264 bytes [14:00 30/05/2003] [19:09 03/06/2009] 9432675B8174F398BC1B5075F0317D2D C:\WINDOWS\system32\quartz.dll –a— 1291264 bytes [14:00 30/05/2003] [19:09 03/06/2009] 9432675B8174F398BC1B5075F0317D2D -=End Of File=- DDS Log File: DDS (Ver_09-10-13.01) - NTFSx86 Run by [removed] at 17:31:30.59 on Sat 10/17/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.885 [GMT -4:00] AV: avast! antivirus 4.8.1351 [VPS 091017-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\CTsvcCDA.exe c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE C:\Program Files\DriveCrypt\DcrServ.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\System32\dllhost.exe C:\Program Files\UPHClean\uphclean.exe C:\WINDOWS\System32\vssvc.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\system32\ZuneBusEnum.exe c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\dllhost.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Creative\Prodikeys\Prodload.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Roland\VSC32\vsc32cnf.exe C:\Program Files\Roland\VSC32\vscvol.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Logitech\Profiler\lwemon.exe C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files\Brother\Brmfcmon\BrMfimon.exe C:\Program Files\Firefox\firefox.exe D:\Users\Eric\Desktop\Oct 2009 PC Problems\What the Tech\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms} mStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {4064EA35-578D-4073-A834-C96D82CBCF40} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [Start WingMan Profiler] "c:\program files\logitech\profiler\lwemon.exe" /noui uRun: [RemoteCenter] c:\program files\creative\mediasource\remotecontrol\RcMan.exe uRun: [Creative MediaSource Go] c:\program files\creative\mediasource\go\CTCMSGo.exe /SCB uRun: [Google Update] "c:\documents and settings\eric\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [CTSysVol] c:\program files\creative\sbaudigy2zs\surround mixer\CTSysVol.exe /r mRun: [CTDVDDET] c:\program files\creative\sbaudigy2zs\dvdaudio\CTDVDDET.EXE mRun: [CTHelper] CTHELPER.EXE mRun: [SBDrvDet] c:\program files\creative\sb drive det\SBDrvDet.exe /r mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [RoxioEngineUtility] "c:\program files\common files\roxio shared\system\EngUtil.exe" mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe -CheckReg mRun: [ProdikeysAutorun] "c:\program files\creative\prodikeys\Prodload.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [vsc32cnf.exe] c:\program files\roland\vsc32\vsc32cnf.exe mRun: [vscvol.exe] c:\program files\roland\vsc32\vscvol.exe mRun: [SsAAD.exe] c:\progra~1\sony\sonics~1\SsAAD.exe mRun: [DLPSP] "c:\program files\dell printers\additional color laser software\status monitor\DLPSP.EXE" mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\status~1.lnk - c:\program files\brother\brmfcmon\BrMfcWnd.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cab DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15026/CTSUEng.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.snapfish.com/SnapfishActivia.cab DPF: {4CCA4E6B-9259-11D9-AC6E-444553544200} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136547307687 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1252336575984 DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} - hxxp://download.microsoft.com/download/B/3/A/B3A2EA73-793D-4ABE-992D-C81140384044/igdtoolx.cab DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15026/CTPID.cab Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\eric\applic~1\mozilla\firefox\profiles\s7rib94w.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - plugin: c:\documents and settings\eric\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\firefox\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\opera7\program\plugins\np32dsw.dll FF - plugin: c:\program files\opera7\program\plugins\npdrmv2.dll FF - plugin: c:\program files\opera7\program\plugins\npdsplay.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava11.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava12.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava13.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava14.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava32.dll FF - plugin: c:\program files\opera7\program\plugins\NPJPI142_03.dll FF - plugin: c:\program files\opera7\program\plugins\npjpi160_14.dll FF - plugin: c:\program files\opera7\program\plugins\NPOJI610.dll FF - plugin: c:\program files\opera7\program\plugins\npoji610.dll FF - plugin: c:\program files\opera7\program\plugins\nppdf32.dll FF - plugin: c:\program files\opera7\program\plugins\nppl3260.dll FF - plugin: c:\program files\opera7\program\plugins\nprjplug.dll FF - plugin: c:\program files\opera7\program\plugins\nprpjplug.dll FF - plugin: c:\program files\opera7\program\plugins\NPSWF32.dll FF - plugin: c:\program files\opera7\program\plugins\npwmsdrm.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: XUL Cache: {60305F03-96C0-4B12-82EC-F43265C7B7F5} - c:\documents and settings\amy\local settings\application data\{60305F03-96C0-4B12-82EC-F43265C7B7F5} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 DCR;DCR;c:\windows\system32\drivers\DCR.sys [2004-4-3 224800] R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2004-3-13 77312] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-5 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-5 20560] R2 DLSDB;Dell Printer Status Database;c:\program files\dell printers\additional color laser software\status monitor\dlsdbnt.exe [2006-3-4 135168] R2 DriveCryptService;DriveCrypt Service;c:\program files\drivecrypt\DcrServ.exe [2004-4-3 208012] R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\PFModNT.sys [2004-3-26 15840] R2 RVIEGVST;VSC VST Engine;c:\program files\roland\virtual sound canvas vst\RVIEg01VST.sys [2005-6-21 188276] R3 Prodikeys;Creative Prodikeys Driver;c:\windows\system32\drivers\ProdDrvr.sys [2004-6-6 14392] R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [2005-6-21 951284] S2 BridDfu;LINKSYS WAP11 USB Device Driver;c:\windows\system32\drivers\BridDFU.sys [2004-5-1 16302] S3 ATIXPGAA;ATIXPGAA;\??\c:\program files\asus\smartdoctor\atixpgaa.sys –> c:\program files\asus\smartdoctor\ATIXPGAA.SYS [?] =============== Created Last 30 ================ 2009-10-16 15:52 116,224 ac—— c:\windows\system32\dllcache\xrxwiadr.dll 2009-10-16 15:52 23,040 ac—— c:\windows\system32\dllcache\xrxwbtmp.dll 2009-10-16 15:52 18,944 ac—— c:\windows\system32\dllcache\xrxscnui.dll 2009-10-16 15:52 27,648 ac—— c:\windows\system32\dllcache\xrxftplt.exe 2009-10-16 15:52 4,608 ac—— c:\windows\system32\dllcache\xrxflnch.exe 2009-10-16 15:50 35,871 ac—— c:\windows\system32\dllcache\wbfirdma.sys 2009-10-16 15:49 440,576 ac—— c:\windows\system32\dllcache\tridkb.dll 2009-10-16 15:48 7,552 ac—— c:\windows\system32\dllcache\sonyait.sys 2009-10-16 15:47 17,280 ac—— c:\windows\system32\dllcache\scr111.sys 2009-10-16 15:46 130,942 ac—— c:\windows\system32\dllcache\ptserlv.sys 2009-10-16 15:45 54,528 ac—— c:\windows\system32\dllcache\opl3sax.sys 2009-10-16 15:44 35,200 ac—— c:\windows\system32\dllcache\msgame.sys 2009-10-16 15:43 253,952 ac—— c:\windows\system32\dllcache\kdsusd.dll 2009-10-16 15:42 372,824 ac—— c:\windows\system32\dllcache\iconf32.dll 2009-10-16 15:41 165,888 ac—— c:\windows\system32\dllcache\hpgt53.dll 2009-10-16 15:40 34,816 ac—— c:\windows\system32\dllcache\esuimg.dll 2009-10-16 15:39 102,484 ac—— c:\windows\system32\dllcache\digiinf.dll 2009-10-16 15:38 272,640 ac—— c:\windows\system32\dllcache\cinemclc.sys 2009-10-16 15:37 66,082 ac—— c:\windows\system32\dllcache\c_1149.nls 2009-10-16 15:36 268,160 ac—— c:\windows\system32\dllcache\atidvai.dll 2009-10-16 15:35 66,048 ac—— c:\windows\system32\dllcache\s3legacy.dll 2009-10-16 15:18 8,396,800 a——- c:\windows\sectest.db 2009-10-16 12:53 178,176 a——- c:\windows\system32\unrar.dll 2009-10-16 12:53 –d—– c:\program files\K-Lite Codec Pack 2009-10-10 20:27 –d—– c:\program files\mpg123dsf 2009-10-02 20:26 195,440 ——– c:\windows\system32\MpSigStub.exe 2009-09-20 17:34 0 a—h— c:\windows\system32\drivers\Msft_User_ZuneDriver_01_09_00.Wdf 2009-09-20 17:34 0 a—h— c:\windows\system32\drivers\Msft_Kernel_WinUSB_01009.Wdf 2009-09-19 08:52 –d—– c:\program files\Foxit Software 2009-09-18 20:09 16,832 a——- c:\windows\system32\amcompat.tlb 2009-09-18 20:09 23,392 a——- c:\windows\system32\nscompat.tlb ==================== Find3M ==================== 2009-09-20 17:33 0 a—h— c:\windows\system32\drivers\MsftWdf_user_01_09_00.Wdf 2009-09-15 16:26 0 a—h— c:\windows\system32\drivers\Msft_Kernel_zumbus_01009.Wdf 2009-09-15 16:26 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf 2009-09-11 10:18 136,192 a——- c:\windows\system32\msv1_0.dll 2009-09-10 14:54 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 14:53 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-09-04 17:03 58,880 a——- c:\windows\system32\msasn1.dll 2009-09-04 13:17 447,216 a——- c:\windows\system32\ZuneWlanCfgSvc.exe 2009-09-04 13:16 58,592 a——- c:\windows\system32\ZuneBusEnum.exe 2009-09-02 00:29 74,240 a——- c:\windows\system32\ZuneUsbTransport.dll 2009-09-02 00:29 57,344 a——- c:\windows\system32\ZuneRegUtil.dll 2009-09-02 00:29 18,944 a——- c:\windows\system32\ZuneTcp2Udp.dll 2009-09-02 00:29 12,800 a——- c:\windows\system32\ZunePTDNS.dll 2009-09-02 00:29 310,784 a——- c:\windows\system32\ZuneNetProxy.dll 2009-09-02 00:29 147,456 a——- c:\windows\system32\ZuneMTPZ.dll 2009-09-02 00:28 40,832 a——- c:\windows\system32\drivers\zumbus.sys 2009-08-29 04:08 916,480 a——- c:\windows\system32\wininet.dll 2009-08-26 04:00 247,326 a——- c:\windows\system32\strmdll.dll 2009-08-17 12:37 1,837,296 a——- c:\windows\system32\WUDFUpdate_01009.dll 2009-08-17 12:37 1,461,992 a——- c:\windows\system32\WdfCoInstaller01009.dll 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-08-04 20:44 2,189,184 ——– c:\windows\system32\ntoskrnl.exe 2009-08-04 10:20 2,066,048 ——– c:\windows\system32\ntkrnlpa.exe 2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll 2007-10-27 20:28 47,360 a——- c:\docume~1\eric\applic~1\pcouffin.sys 2006-05-17 21:28 330 a—h— c:\documents and settings\all users\hpothb07.dat 2005-01-15 15:10 309 a—h— c:\documents and settings\eric\hpothb07.dat 2003-07-31 05:53 147,456 a——- c:\windows\inf\EL2K_XP.sys 2003-07-31 05:50 448,768 a——- c:\windows\inf\EL2K_N64.sys 2003-07-31 05:43 147,456 a——- c:\windows\inf\EL2K_2K.sys 2008-08-17 19:36 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081720080818\index.dat ============= FINISH: 17:31:58.65 =============== 📎Attach.txt
Hi

Well hopefully that's one down and 2 to go. Good news is, I don't see any malware.

By chance did you look in My Computer to see if fixing the shares removed the Other entry?

Doesn't seem to be anything unusal in the SystemLook log. The keys point at what is listed underneath them.

{59031a47-3f72-44a7-89c5-5595fe6b30ee}]

is the SharedDocs folder

Do you have any mobile devices or some that you removed? What about this Zen MicroPhoto Media Explorer?

For the WMP problem, did you try the solution HERE?

Scroll down to this part, WMA or WMV - Troubleshooting Playback

Reinstalling DirectX should register quartz.dll

You do have the correct version of quartz.dll and in the right folder. Are you trying to register it from an Adminstrator account?

By chance did you look in My Computer to see if fixing the shares removed the Other entry?


I checked. The phantom entry is still there.

Do you have any mobile devices or some that you removed? What about this Zen MicroPhoto Media Explorer?


My daughter uses a Creative Zen MP3 player with this PC, but she sync's it using Windows Media Player. I don't think I need the Zen MicroPhoto software anymore. So I just tried to uninstall the Zen software using Add/Remove Programs, but got the following, "An error has occurred while running setup." The details from the error window are as follows:

Error Code: -5004 : 0x80070005
Error Information:
>SetupDLL\SetupDLL.cpp (1968)
PAPP:Creative Zen MicroPhoto
PVENDOR:Creative Technology Ltd (http://www.creative.com)
PGUID:1AEC8F41-4701-415D-9782-F69CFB535463
$9.1.0.429
@Windows XP Service Pack 3 (2600) IE 8.0.6001.18702

The other mobile devices that I connect to this PC are two different iPods (which sync through iTunes), a Zune player (which syncs through both WMP and the Zune application), and also an LG cell phone that I sync using BitPim.

For the WMP problem, did you try the solution HERE[/u rl]?

Scroll down to this part, WMA or WMV - Troubleshooting Playback

Reinstalling DirectX should register quartz.dll


I had not seen the troubleshooting page that you referenced. It suggests first reinstalling the MicroSoft codec installation packages from this page: http://www.microsoft.com/windows/windowsme...ecdownload.aspx

I had tried that previously -- there is no version available for download on that page that works with Windows XP. I tried the Windows 2000 version, but the installer aborts, stating that it is not compatible.

I had thought about trying to reinstall DirectX, but was hesitant to do that. However, I think that may be required. As an experiment, I tried to run DXDIAG on my machine and got an error message, "Error: Could not load DXDIAGN.DLL". Which version of DirectX should I use for a reinstall?

You do have the correct version of quartz.dll and in the right folder. Are you trying to register it from an Adminstrator account?


Yes, I am trying to register from an administrator account.

Thanks.

- Eric
Hi modena2904,

I've pretty much given you all the easy common fixes that I know. I think it would be best if you posted in the Tech section of the forum. I could take more guesses, but that's all they would be. Googling your problem gives a variety of solutions. I wouldn't know which one to advise you to try. The Techs would be able to assist you to resolve this much faster.

Microsoft Windows Forum would probably be your best bet.

Please include a link to this thread when you post there.

Sorry I couldn't be of much help. :(
Thank you for helping. At least I know that it is not a malware recurrence. I'll post a new topic in the other forum, as suggested. Thanks. - Eric
Hi modena2904,

Good, I'll follow that thread and hopefully pick up some tips.

It would seem I missed a bit of malware, (thanks noahdfear). Don't know if it will help, as this is a redirecter.

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Please post back with the GooredFix log and a new DSS.txt

Thanks
I ran GooredFix and also re-ran DDS. Log files below. Thanks. - Eric GooredFix by jpshortstuff (24.09.09.1) Log created at 21:07 on 20/10/2009 (Eric) Firefox version 3.0 (en-US) ========== GooredScan ========== Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{60305F03-96C0-4B12-82EC-F43265C7B7F5} -> Success! Deleting C:\Documents and Settings\Amy\Local Settings\Application Data\{60305F03-96C0-4B12-82EC-F43265C7B7F5} -> Success! ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ (none) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [21:56 03/12/2008] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [23:33 24/10/2008] -=E.O.F=- DDS (Ver_09-10-13.01) - NTFSx86 Run by [removed] at 21:09:23.64 on Tue 10/20/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.835 [GMT -4:00] AV: avast! antivirus 4.8.1351 [VPS 091020-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\CTsvcCDA.exe c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE C:\Program Files\DriveCrypt\DcrServ.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\System32\dllhost.exe C:\Program Files\UPHClean\uphclean.exe C:\WINDOWS\System32\vssvc.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\system32\ZuneBusEnum.exe c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\dllhost.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Creative\Prodikeys\Prodload.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Roland\VSC32\vsc32cnf.exe C:\Program Files\Roland\VSC32\vscvol.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Logitech\Profiler\lwemon.exe C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\Brother\Brmfcmon\BrMfimon.exe C:\Documents and Settings\Eric\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Eric\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Eric\Local Settings\Application Data\Google\Chrome\Application\chrome.exe D:\Users\Eric\Desktop\Oct 2009 PC Problems\What the Tech\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms} mStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {4064EA35-578D-4073-A834-C96D82CBCF40} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [Start WingMan Profiler] "c:\program files\logitech\profiler\lwemon.exe" /noui uRun: [RemoteCenter] c:\program files\creative\mediasource\remotecontrol\RcMan.exe uRun: [Creative MediaSource Go] c:\program files\creative\mediasource\go\CTCMSGo.exe /SCB uRun: [Google Update] "c:\documents and settings\eric\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [CTSysVol] c:\program files\creative\sbaudigy2zs\surround mixer\CTSysVol.exe /r mRun: [CTDVDDET] c:\program files\creative\sbaudigy2zs\dvdaudio\CTDVDDET.EXE mRun: [CTHelper] CTHELPER.EXE mRun: [SBDrvDet] c:\program files\creative\sb drive det\SBDrvDet.exe /r mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [RoxioEngineUtility] "c:\program files\common files\roxio shared\system\EngUtil.exe" mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe -CheckReg mRun: [ProdikeysAutorun] "c:\program files\creative\prodikeys\Prodload.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [vsc32cnf.exe] c:\program files\roland\vsc32\vsc32cnf.exe mRun: [vscvol.exe] c:\program files\roland\vsc32\vscvol.exe mRun: [SsAAD.exe] c:\progra~1\sony\sonics~1\SsAAD.exe mRun: [DLPSP] "c:\program files\dell printers\additional color laser software\status monitor\DLPSP.EXE" mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\status~1.lnk - c:\program files\brother\brmfcmon\BrMfcWnd.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cab DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15026/CTSUEng.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.snapfish.com/SnapfishActivia.cab DPF: {4CCA4E6B-9259-11D9-AC6E-444553544200} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136547307687 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1252336575984 DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} - hxxp://download.microsoft.com/download/B/3/A/B3A2EA73-793D-4ABE-992D-C81140384044/igdtoolx.cab DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15026/CTPID.cab Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\eric\applic~1\mozilla\firefox\profiles\s7rib94w.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - plugin: c:\documents and settings\eric\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\firefox\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\opera7\program\plugins\np32dsw.dll FF - plugin: c:\program files\opera7\program\plugins\npdrmv2.dll FF - plugin: c:\program files\opera7\program\plugins\npdsplay.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava11.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava12.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava13.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava14.dll FF - plugin: c:\program files\opera7\program\plugins\NPJava32.dll FF - plugin: c:\program files\opera7\program\plugins\NPJPI142_03.dll FF - plugin: c:\program files\opera7\program\plugins\npjpi160_14.dll FF - plugin: c:\program files\opera7\program\plugins\npoji610.dll FF - plugin: c:\program files\opera7\program\plugins\NPOJI610.dll FF - plugin: c:\program files\opera7\program\plugins\nppdf32.dll FF - plugin: c:\program files\opera7\program\plugins\nppl3260.dll FF - plugin: c:\program files\opera7\program\plugins\nprjplug.dll FF - plugin: c:\program files\opera7\program\plugins\nprpjplug.dll FF - plugin: c:\program files\opera7\program\plugins\NPSWF32.dll FF - plugin: c:\program files\opera7\program\plugins\npwmsdrm.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 DCR;DCR;c:\windows\system32\drivers\DCR.sys [2004-4-3 224800] R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2004-3-13 77312] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-5 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-5 20560] R2 DLSDB;Dell Printer Status Database;c:\program files\dell printers\additional color laser software\status monitor\dlsdbnt.exe [2006-3-4 135168] R2 DriveCryptService;DriveCrypt Service;c:\program files\drivecrypt\DcrServ.exe [2004-4-3 208012] R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\PFModNT.sys [2004-3-26 15840] R2 RVIEGVST;VSC VST Engine;c:\program files\roland\virtual sound canvas vst\RVIEg01VST.sys [2005-6-21 188276] R3 Prodikeys;Creative Prodikeys Driver;c:\windows\system32\drivers\ProdDrvr.sys [2004-6-6 14392] R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [2005-6-21 951284] S2 BridDfu;LINKSYS WAP11 USB Device Driver;c:\windows\system32\drivers\BridDFU.sys [2004-5-1 16302] S3 ATIXPGAA;ATIXPGAA;\??\c:\program files\asus\smartdoctor\atixpgaa.sys –> c:\program files\asus\smartdoctor\ATIXPGAA.SYS [?] =============== Created Last 30 ================ 2009-10-18 16:32 –d—– C:\DECCHECK 2009-10-16 15:52 116,224 ac—— c:\windows\system32\dllcache\xrxwiadr.dll 2009-10-16 15:52 23,040 ac—— c:\windows\system32\dllcache\xrxwbtmp.dll 2009-10-16 15:52 18,944 ac—— c:\windows\system32\dllcache\xrxscnui.dll 2009-10-16 15:52 27,648 ac—— c:\windows\system32\dllcache\xrxftplt.exe 2009-10-16 15:52 4,608 ac—— c:\windows\system32\dllcache\xrxflnch.exe 2009-10-16 15:50 35,871 ac—— c:\windows\system32\dllcache\wbfirdma.sys 2009-10-16 15:49 440,576 ac—— c:\windows\system32\dllcache\tridkb.dll 2009-10-16 15:48 7,552 ac—— c:\windows\system32\dllcache\sonyait.sys 2009-10-16 15:47 17,280 ac—— c:\windows\system32\dllcache\scr111.sys 2009-10-16 15:46 130,942 ac—— c:\windows\system32\dllcache\ptserlv.sys 2009-10-16 15:45 54,528 ac—— c:\windows\system32\dllcache\opl3sax.sys 2009-10-16 15:44 35,200 ac—— c:\windows\system32\dllcache\msgame.sys 2009-10-16 15:43 253,952 ac—— c:\windows\system32\dllcache\kdsusd.dll 2009-10-16 15:42 372,824 ac—— c:\windows\system32\dllcache\iconf32.dll 2009-10-16 15:41 165,888 ac—— c:\windows\system32\dllcache\hpgt53.dll 2009-10-16 15:40 34,816 ac—— c:\windows\system32\dllcache\esuimg.dll 2009-10-16 15:39 102,484 ac—— c:\windows\system32\dllcache\digiinf.dll 2009-10-16 15:38 272,640 ac—— c:\windows\system32\dllcache\cinemclc.sys 2009-10-16 15:37 66,082 ac—— c:\windows\system32\dllcache\c_1149.nls 2009-10-16 15:36 268,160 ac—— c:\windows\system32\dllcache\atidvai.dll 2009-10-16 15:35 66,048 ac—— c:\windows\system32\dllcache\s3legacy.dll 2009-10-16 15:18 8,396,800 a——- c:\windows\sectest.db 2009-10-16 12:53 178,176 a——- c:\windows\system32\unrar.dll 2009-10-16 12:53 –d—– c:\program files\K-Lite Codec Pack 2009-10-10 20:27 –d—– c:\program files\mpg123dsf 2009-10-02 20:26 195,440 ——– c:\windows\system32\MpSigStub.exe ==================== Find3M ==================== 2009-09-20 17:34 0 a—h— c:\windows\system32\drivers\Msft_User_ZuneDriver_01_09_00.Wdf 2009-09-20 17:34 0 a—h— c:\windows\system32\drivers\Msft_Kernel_WinUSB_01009.Wdf 2009-09-20 17:33 0 a—h— c:\windows\system32\drivers\MsftWdf_user_01_09_00.Wdf 2009-09-15 16:26 0 a—h— c:\windows\system32\drivers\Msft_Kernel_zumbus_01009.Wdf 2009-09-15 16:26 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf 2009-09-11 10:18 136,192 a——- c:\windows\system32\msv1_0.dll 2009-09-10 14:54 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 14:53 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-09-04 17:03 58,880 a——- c:\windows\system32\msasn1.dll 2009-09-04 13:17 447,216 a——- c:\windows\system32\ZuneWlanCfgSvc.exe 2009-09-04 13:16 58,592 a——- c:\windows\system32\ZuneBusEnum.exe 2009-09-02 00:29 74,240 a——- c:\windows\system32\ZuneUsbTransport.dll 2009-09-02 00:29 57,344 a——- c:\windows\system32\ZuneRegUtil.dll 2009-09-02 00:29 18,944 a——- c:\windows\system32\ZuneTcp2Udp.dll 2009-09-02 00:29 12,800 a——- c:\windows\system32\ZunePTDNS.dll 2009-09-02 00:29 310,784 a——- c:\windows\system32\ZuneNetProxy.dll 2009-09-02 00:29 147,456 a——- c:\windows\system32\ZuneMTPZ.dll 2009-09-02 00:28 40,832 a——- c:\windows\system32\drivers\zumbus.sys 2009-08-29 04:08 916,480 a——- c:\windows\system32\wininet.dll 2009-08-26 04:00 247,326 a——- c:\windows\system32\strmdll.dll 2009-08-17 12:37 1,837,296 a——- c:\windows\system32\WUDFUpdate_01009.dll 2009-08-17 12:37 1,461,992 a——- c:\windows\system32\WdfCoInstaller01009.dll 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-08-04 20:44 2,189,184 ——– c:\windows\system32\ntoskrnl.exe 2009-08-04 10:20 2,066,048 ——– c:\windows\system32\ntkrnlpa.exe 2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll 2007-10-27 20:28 47,360 a——- c:\docume~1\eric\applic~1\pcouffin.sys 2006-05-17 21:28 330 a—h— c:\documents and settings\all users\hpothb07.dat 2005-01-15 15:10 309 a—h— c:\documents and settings\eric\hpothb07.dat 2003-07-31 05:53 147,456 a——- c:\windows\inf\EL2K_XP.sys 2003-07-31 05:50 448,768 a——- c:\windows\inf\EL2K_N64.sys 2003-07-31 05:43 147,456 a——- c:\windows\inf\EL2K_2K.sys 2008-08-17 19:36 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081720080818\index.dat ============= FINISH: 21:10:07.65 =============== 📎Attach.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI