This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Please help laptop unbearable

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello thank you very much for viewing my logs. My computer is constantly crashing and wont let me open some things like task manager ect.. I works ok in safemode but wont run some installers :S The pc is also really slow and i have nothing running (Disabled all startup and all services except microsoft ones through msconfig).vThank you for all help.

HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:03:10, on 07/09/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Media Access Startup - {25B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Media Access Startup\1.0.0.610\HPIEAddOn.dll
O2 - BHO: NP Helper Class - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Internet Saving Optimizer\3.1.0.3900\NPIEAddOn.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKUS\S-1-5-18\..\Run: [fsc-reg] c:\fsc-reg\fscreg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [fsc-reg] c:\fsc-reg\fscreg.exe (User 'Default user')

–
End of file - 3581 bytes

HJT Startup log:
StartupList report, 07/09/2009, 21:05:30
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows Vista SP1 (WinNT 6.00.1905)
Detected: Internet Explorer v7.00 (7.00.6001.18294)
* Using default options
==================================================

Running processes:

C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\WerCon.exe
C:\Windows\system32\wuauclt.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\Windows\system32\userinit.exe,

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

————————————————–

Shell & screensaver key from C:\Windows\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=explorer.exe
SCRNSAVE.EXE=C:\Windows\system32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Lexmark Toolbar\toolband.dll - {1017A80C-6F09-4548-A84D-EDD6AC9525F0}
AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
Media Access Startup - C:\Program Files\Media Access Startup\1.0.0.610\HPIEAddOn.dll - {25B8D58C-B0CB-46b0-BA64-05B3804E4E86}
NP Helper Class - C:\Program Files\Internet Saving Optimizer\3.1.0.3900\NPIEAddOn.dll - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86}
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B}
(no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll - {A3BC75A2-1F87-4686-AA43-5347D756017C}
(no name) - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E}
(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
(no name) - C:\Program Files\Windows Live\Toolbar\wltcore.dll - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}

————————————————–

Enumerating Task Scheduler jobs:

Ad-Aware Update (Weekly).job
GoogleUpdateTaskUserS-1-5-21-183728956-105466596-3194839557-1000Core.job
GoogleUpdateTaskUserS-1-5-21-183728956-105466596-3194839557-1000UA.job
PersonalAV.job
User_Feed_Synchronization-{E71E007F-7532-4391-A840-9E3D08613A68}.job

————————————————–

Enumerating Winsock LSP files:

NameSpace #1: C:\Windows\system32\NLAapi.dll
NameSpace #2: C:\Windows\system32\napinsp.dll
NameSpace #3: C:\Windows\system32\pnrpnsp.dll
NameSpace #4: C:\Windows\system32\pnrpnsp.dll
NameSpace #7: C:\Program Files\Bonjour\mdnsNSP.dll

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\Windows\system32\webcheck.dll

————————————————–
End of report, 4,545 bytes
Report generated in 0.032 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

Thank you in advanced,
Hannah
:welcome:

Go to your Add Remove Programs in the Control Panel and see if you can uninstall both these programs. If you can't then dont worry about it

C:\Program Files\Media Access Startup
C:\Program Files\Internet Saving Optimizer




Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean





Please download Malwarebytes' Anti-Malware from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report and also a new HJT log please

I need to see the Hijackthis log in normal windows, not safemode as safemode will not show everything
Hello thank you very much for your fast response. I have run both the programs with a huge struggle (I had to rename the files as they wouldnt open, then they kept crashing so i had to run combofix first then run malware byte). Anyway now i have ran the pgrams im unable to connect to the internet through wifi or Ethernet. On wifi it says connected with limited access and on ethernet it seems to connect fine but my internet doesnt work. I cant post logs as i cant get pc on the internet. what should i do next? Thank you in advanced, Hannah
Hannah,

All systems and infections are different on each computer, what Combofix can fix on one can sometimes damage another. I never posted any instructions to run Combofix. I have no idea of what you have done :blush:


Your going to have to access this forum on a known clean computer , save the logs from the infected computer, burn them to a CD ( not a USB Flash drive ) and transfer them to the clean computer and access this forum and post them please.

C:\ComboFix.txt <–You can find the Combofix log here

Open up Malwarebytes and go to the logs tab, open it and copy and paste it as well
ooops sorry about that i googles. Malwarebyte removal wont open and thats what was suggested sorry!:

Heres what the logs contain:

COMBOFIX:
ComboFix 09-09-09.09 - Flossy 10/09/2009 17:44.1.2 - NTFSx86
MicrosoftÆ Windows Vistaô Home Premium 6.0.6001.1.1252.44.1033.18.1912.1187 [GMT 1:00]
Running from: c:\users\[removed]\Documents\Downloads\llll.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-957877722-2994610554-2224942004-500
c:\windows\Installer\129d1f.msi
c:\windows\system32\drivers\ndisrd.sys
c:\windows\system32\drivers\snetcfg.exe
c:\windows\system32\drivers\UACxqxqrinbdr.sys
c:\windows\system32\ndisapi.dll
c:\windows\system32\UACbreemojpws.dat
c:\windows\system32\UACfmebeuvcnv.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACqrxsjplskv.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Service_Ndisrd
——-\Service_NdisrdMP


((((((((((((((((((((((((( Files Created from 2009-08-10 to 2009-09-10 )))))))))))))))))))))))))))))))
.

2009-09-10 15:51 . 2009-09-10 15:51 ——– d—–w- c:\users\Flossy\AppData\Roaming\Malwarebytes
2009-09-10 15:13 . 2009-08-03 12:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 15:13 . 2009-09-10 15:51 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-10 15:13 . 2009-09-10 15:13 ——– d—–w- c:\programdata\Malwarebytes
2009-09-10 15:13 . 2009-08-03 12:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-01 19:38 . 2009-09-01 19:38 ——– d—–w- c:\program files\Trend Micro
2009-08-31 14:37 . 2009-08-31 14:37 ——– d—–w- c:\program files\TomTom HOME 2
2009-08-31 14:35 . 2009-08-31 14:35 ——– d—–w- c:\program files\TomTom DesktopSuite
2009-08-26 11:12 . 2009-06-22 10:22 2048 —-a-w- c:\windows\system32\tzres.dll
2009-08-26 09:02 . 2009-06-05 12:34 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2009-08-26 09:02 . 2009-06-05 10:08 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-19 12:54 . 2009-06-15 15:24 175104 —-a-w- c:\windows\system32\wdigest.dll
2009-08-19 12:54 . 2009-06-15 15:21 499712 —-a-w- c:\windows\system32\kerberos.dll
2009-08-19 12:54 . 2009-06-15 18:20 439896 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-19 12:54 . 2009-06-15 15:24 270848 —-a-w- c:\windows\system32\schannel.dll
2009-08-19 12:54 . 2009-06-15 15:23 1256448 —-a-w- c:\windows\system32\lsasrv.dll
2009-08-19 12:54 . 2009-06-15 15:22 213504 —-a-w- c:\windows\system32\msv1_0.dll
2009-08-19 12:54 . 2009-06-15 15:24 72704 —-a-w- c:\windows\system32\secur32.dll
2009-08-19 12:54 . 2009-06-15 12:57 9728 —-a-w- c:\windows\system32\lsass.exe
2009-08-19 12:12 . 2009-08-31 11:34 ——– d—–w- C:\$AVG8.VAULT$
2009-08-19 12:07 . 2009-08-19 12:52 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-08-19 12:07 . 2009-08-19 12:07 ——– d—–w- c:\users\Flossy\AppData\Roaming\SUPERAntiSpyware.com
2009-08-19 12:05 . 2009-08-19 12:05 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-19 12:05 . 2009-08-19 12:05 12552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-08-19 12:05 . 2009-08-19 12:05 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-19 12:05 . 2009-08-19 12:05 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-19 12:05 . 2009-08-19 12:05 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-19 12:04 . 2009-09-01 08:54 ——– d—–w- c:\windows\system32\drivers\Avg
2009-08-19 12:04 . 2009-08-19 12:04 ——– d—–w- c:\programdata\AVG Security Toolbar
2009-08-19 12:04 . 2009-08-19 12:04 ——– d—–w- c:\program files\AVG
2009-08-13 21:14 . 2009-08-13 21:14 ——– d—–w- c:\program files\Common Files\Uninstall
2009-08-13 11:58 . 2009-07-17 14:35 71680 —-a-w- c:\windows\system32\atl.dll
2009-08-13 11:58 . 2009-06-10 12:12 160256 —-a-w- c:\windows\system32\wkssvc.dll
2009-08-13 11:58 . 2009-06-04 12:34 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-08-13 11:58 . 2009-06-10 12:07 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-08-13 11:58 . 2009-07-14 13:00 313344 —-a-w- c:\windows\system32\wmpdxm.dll
2009-08-13 11:58 . 2009-07-14 12:59 4096 —-a-w- c:\windows\system32\dxmasf.dll
2009-08-13 11:58 . 2009-07-14 12:58 7680 —-a-w- c:\windows\system32\spwmp.dll
2009-08-13 11:58 . 2009-07-14 10:59 8147456 —-a-w- c:\windows\system32\wmploc.DLL

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-25 22:27 . 2009-05-13 18:52 ——– d—–w- c:\users\Flossy\AppData\Roaming\Spotify
2009-08-19 12:45 . 2009-07-09 20:30 ——– d—–w- c:\programdata\avg8
2009-08-14 12:02 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-07-31 15:20 . 2009-05-13 18:50 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-30 19:42 . 2009-06-21 17:54 ——– d—–w- c:\program files\Java
2009-07-30 19:41 . 2009-07-30 19:41 ——– d—–w- c:\programdata\McAfee
2009-07-18 16:06 . 2009-07-29 08:10 827904 —-a-w- c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-07-29 08:10 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-07-29 08:10 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-07-10 08:55 . 2009-07-09 17:18 34 —-a-w- c:\users\Flossy\jagex_runescape_preferences.dat
2009-07-06 21:10 . 2009-07-09 20:22 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-07-06 21:01 . 2009-07-09 19:53 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-15 15:24 . 2009-07-28 12:12 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-28 12:12 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-28 12:12 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-28 12:12 289792 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 08:56 1062144 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Google Update"="c:\users\Flossy\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-07-30 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"LXCRCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\LXCRtime.dll" [2006-11-21 106496]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-05-28 20480]
"FSCRecovery"="c:\program files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe" [2008-06-18 268096]

c:\users\Flossy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4C8FB82F-58CD-42AA-8267-486A91F178C1}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ACF1CCCE-0134-4996-9F22-BD9F0167F95B}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7449FDFB-DFE1-4EC6-9DB8-4F6901F2942D}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{E4514DA3-1CC0-49D6-8C49-641993A365A3}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
"UDP Query User{B5B17813-7789-4A23-A5E9-B178B4DAF9EB}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify
"{EE26AFA2-3812-4736-9CD7-332EFC1FBC9F}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A8512137-65E6-4652-8433-832C05836F7A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{13EDF3CE-3833-412D-9EB5-7A4B5BA106E4}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{5D9E3170-E0A9-411A-9ACB-EB2CF8D7F316}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{8D560507-F4CF-4601-BE8B-9346F61DFB75}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{125BCEE2-D699-4F65-97B3-246DB08298CB}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{29B7576C-4100-4960-9621-0D2A9E83121E}"= UDP:c:\windows\System32\lxcrcoms.exe:Lexmark Communications System
"{C78E094B-CB61-40D8-BD6D-9DFDFA34E9EF}"= TCP:c:\windows\System32\lxcrcoms.exe:Lexmark Communications System
"{CDC8A753-6127-4304-ABA8-0006BABEDE1E}"= UDP:c:\program files\Lexmark 2400 Series\lxcrmon.exe:Device Monitor
"{80A0B81A-ACB6-4111-8A8A-A2138BE10DDA}"= TCP:c:\program files\Lexmark 2400 Series\lxcrmon.exe:Device Monitor
"{05609BDB-3F4E-4828-8D94-B80796B2BE69}"= UDP:c:\program files\Lexmark 2400 Series\LXCRaiox.exe:All In One Center
"{9787EC89-21AB-440A-92AF-B6F3272C92CF}"= TCP:c:\program files\Lexmark 2400 Series\LXCRaiox.exe:All In One Center
"{B6A9520A-E410-4E7F-A1FA-EF6EC8D0117F}"= c:\program files\AVG\AVG8\avgam.exe:avgam.exe
"{9202141E-9AA4-41D2-8547-163376C2C9A3}"= c:\program files\AVG\AVG8\avgdiag.exe:avgdiag.exe
"{2FBEC5F2-0722-4898-8E31-41DA4135F1F3}"= c:\program files\AVG\AVG8\avgdiagex.exe:avgdiagex.exe
"{858E8D06-5C97-4B16-80C0-C1CA71594F81}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{422C6D66-84C2-4FE1-9763-AA947E239DC8}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{1D51D636-2CEE-4EC5-86EB-ED6B60E703D1}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe

R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [19/08/2009 13:05 12552]
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [09/07/2009 20:53 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [19/08/2009 13:05 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [19/08/2009 13:05 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [19/08/2009 13:04 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [19/08/2009 13:04 297752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 20:06 1029456]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\RTL8187B.sys [10/10/2008 23:57 337920]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [13/05/2009 19:50 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/05/2009 18:35 29744]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [10/09/2009 16:13 38160]
.
Contents of the 'Scheduled Tasks' folder

2009-09-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 21:00]

2009-08-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-183728956-105466596-3194839557-1000Core.job
- c:\users\Flossy\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-30 19:06]

2009-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-183728956-105466596-3194839557-1000UA.job
- c:\users\Flossy\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-30 19:06]

2009-09-10 c:\windows\Tasks\User_Feed_Synchronization-{E71E007F-7532-4391-A840-9E3D08613A68}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod;=FUJD
uInternet Settings,ProxyOverride = *.local
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-NPCTray - c:\program files\Norman\npc\bin\npc_tray.exe
HKU-Default-Run-fsc-reg - c:\fsc-reg\fscreg.exe



**************************************************************************
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\lxcrcoms.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\IoctlSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\System32\rundll32.exe
c:\program files\FSC OSD Utility\OSDUtility.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2009-09-10 18:02 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-10 17:02

Pre-Run: 67,580,739,584 bytes free
Post-Run: 67,350,097,920 bytes free

214 — E O F — 2009-08-28 10:41


MALWARE:
Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 6.0.6001 Service Pack 1 (Safe Mode)

10/09/2009 19:50:39
mbam-log-2009-09-10 (19-50-39).txt

Scan type: Quick Scan
Objects scanned: 78822
Time elapsed: 3 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\explorerbar.funredirector (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\explorerbar.funredirector.1 (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{480098c6-f6ad-4c61-9b5c-2bae228a34d1} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{883dfc00-8a21-411d-956c-73a4e4b7d16f} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Media Access Startup (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{c5096216-7703-409e-b85a-8a6ee7395128}}_is1 (Adware.DoubleD) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\DoubleD\GamingHarbor Toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\System Search Dispatcher (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\System Search Dispatcher\1.2.0.750 (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\System Search Dispatcher\1.2.0.750\Data (Adware.DoubleD) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\System Search Dispatcher\1.2.0.750\unins000.dat (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\System Search Dispatcher\1.2.0.750\unins000.exe (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\System Search Dispatcher\1.2.0.750\Data\eacore.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\System Search Dispatcher\1.2.0.750\Data\URLDynamic.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\System Search Dispatcher\1.2.0.750\Data\URLStatic.mx (Adware.DoubleD) -> Quarantined and deleted successfully.


HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:57:12, on 10/09/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\FSC OSD Utility\OSDUtility.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\Flossy\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Flossy\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Flossy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Flossy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows; Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA
O4 - HKLM\..\Run: [FSCRecovery] c:\Program Files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe
O4 - HKLM\..\Run: [FSC OSD Utility] c:\PROGRA~1\FSCOSD~1\OSDUTI~1.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Flossy\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: lxcr_device - - C:\Windows\system32\lxcrcoms.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe

–
End of file - 5974 bytes


Thank you in advanced,
Hannah x
Hello Hannah,

Limewire <– Just want to give you a heads up on P2P programs, your downloading a file from an unknown source, you never know whats attached to that file, its like playing Russian roulette malwarewise.

We have noticed that many people seeking help from us are coming with infections contracted from the use of P2P programs.

Because of this, we changed our malware forum's policy on the use of P2P file sharing programs.

  • If your helper detects the presence of such programs on your computer he/she will ask you to remove them. Help will be withdrawn should you not agree to their removal.
  • If we clean your computer of infection, and you return to us a short time later with an infection contracted by the use of P2P programs, volunteer analysts will refuse their help.

We do not ask you to do this without reason.


P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.





Final check

Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

How are thing running now ??
Hello thanks for the reply. I dont have limewire installed and how am i meant to use an online scan if my internet doesnt run? Thank you, Hannah
Limewire was installed at one time, your firewall is giving it access to the internet. This was just a heads up on File Sharing.

From your Combofix log.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4C8FB82F-58CD-42AA-8267-486A91F178C1}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ACF1CCCE-0134-4996-9F22-BD9F0167F95B}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7449FDFB-DFE1-4EC6-9DB8-4F6901F2942D}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{E4514DA3-1CC0-49D6-8C49-641993A365A3}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
"UDP Query User{B5B17813-7789-4A23-A5E9-B178B4DAF9EB}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify
"{EE26AFA2-3812-4736-9CD7-332EFC1FBC9F}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A8512137-65E6-4652-8433-832C05836F7A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{13EDF3CE-3833-412D-9EB5-7A4B5BA106E4}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{5D9E3170-E0A9-411A-9ACB-EB2CF8D7F316}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{8D560507-F4CF-4601-BE8B-9346F61DFB75}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{125BCEE2-D699-4F65-97B3-246DB08298CB}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire

"{29B7576C-4100-4960-9621-0D2A9E83121E}"= UDP:c:\windows\System32\lxcrcoms.exe:Lexmark Communications System
"{C78E094B-CB61-40D8-BD6D-9DFDFA34E9EF}"= TCP:c:\windows\System32\lxcrcoms.exe:Lexmark Communications System
"{CDC8A753-6127-4304-ABA8-0006BABEDE1E}"= UDP:c:\program files\Lexmark 2400 Series\lxcrmon.exe:Device Monitor
"{80A0B81A-ACB6-4111-8A8A-A2138BE10DDA}"= TCP:c:\program files\Lexmark 2400 Series\lxcrmon.exe:Device Monitor
"{05609BDB-3F4E-4828-8D94-B80796B2BE69}"= UDP:c:\program files\Lexmark 2400 Series\LXCRaiox.exe:All In One Center
"{9787EC89-21AB-440A-92AF-B6F3272C92CF}"= TCP:c:\program files\Lexmark 2400 Series\LXCRaiox.exe:All In One Center
"{B6A9520A-E410-4E7F-A1FA-EF6EC8D0117F}"= c:\program files\AVG\AVG8\avgam.exe:avgam.exe
"{9202141E-9AA4-41D2-8547-163376C2C9A3}"= c:\program files\AVG\AVG8\avgdiag.exe:avgdiag.exe
"{2FBEC5F2-0722-4898-8E31-41DA4135F1F3}"= c:\program files\AVG\AVG8\avgdiagex.exe:avgdiagex.exe
"{858E8D06-5C97-4B16-80C0-C1CA71594F81}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{422C6D66-84C2-4FE1-9763-AA947E239DC8}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{1D51D636-2CEE-4EC5-86EB-ED6B60E703D1}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe


From me
Give me a bit of time to digest your logs. Are you back online now ?

From your last post

Yeh im online now :D Im watching this Darren Brown predicts the lottery want to see what all the fuss is about.
Thank you.

Oh lol when you said are you back online. I thought you meant like am i online as in on another pc. I havent managed to get the laptop to connect yet :(. Thank you in advanced.
By the way the laptop is still not fixed. It keeps crashing every second and wont let me open the Networks page. Plus when i go to shutdown its gets stuck on the shutting down page. Thanks
Hannah,

Not sure if you damaged your system running combofix on your own or not, I don't know at this point if your problems are malware or windows related. You stated that you disabled a bunch of programs through msconfig, I would go back there and re enable all the ones you have disabled. I also don't know what you have done here, hopefully not more damage.

Post here in our other forum to see if they can get you back up and running. When they do , go ahead and run ESET and post the log.
http://forums.whatthetech.com/Browsers_Int…email_f123.html

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI