This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help removing "Protection System" and more..

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey I'm new here and I was looking around to solve this problem. I see what great work you guys do here and I appreciate whatever help you can offer. I'm using my laptop to post but the problem lies on my sister's Dell laptop. She was streaming a video from zshare.net through an ad and became infected. It is running Windows XP Media Center Edition SP2. She has a firewall on but no virus protection software. She became frantic and for some odd reason, turned off System Restore and turned it back on. Then she connected an external hard drive to try and save some documents. Symptoms: - Multiple "Security Center Alerts" Backdoor.Win32.Agent.ich Email-Worm.Win32.NetSky.q Backdoor.Win32.Kbot.al Virus.Win32.Gpcode.ak Net-Worm.Win32.DipNet.d - Fake Windows shield logo in Tray - Constant window pop-up of "Protection System" software - Notification from tray icone saying "Danger - There are some serious security threats detected on your computer. Please, remove them ASAP." - "Windows Security Center" keeps popping up. Looks a lot like Windows. Says Virus Protection not found and has "install" button. - Numerous "clicking" sounds in background - Audio, that she doesn't have, plays by itself - 3 links to porn keep reappearing on the desktop Some concerns: - How to clean the system - Is her saved login/passwords safe? - Are the files she moved to the external HD infected and did it further infect the clean files already in the HD? - If the files are not infected, is it okay to back up more files to the external HD? Things I did before posting: I did a free Housecall scan through TrendMicro. And installed Symantec Endpoint Protection. Seems like they didn't do any good whatsoever. I am moderately knowledgeable with computers but this is totally out of my realm. But, I am confident I am able to follow your instructions correctly. Thanks for your help. I will be follow this thread closely.
Hello Tranquility and welcome to the forums here at WTT.

It's tough to really answer any of your questions with seeing some logs from the PC. She should be pretty safe backing up any personal documents, pictures, music, ect…

Please follow the instructions at this link. Then post the logs from Root Repeal and DDS back to this link. Do not start a new topic. Then we can hopefully start cleaning from there.
Thanks a lot for the response. I followed your instructions and here are the logs. When I opened RootRepeal, I got some PE image error. The log seems to be missing "processes" and "SSDT" sections. Hope that isn't a problem. Will check back for your response and the next steps I should follow.

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 23:35:09.43 on Tue 09/08/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.72 [GMT -4:00]

AV: Protection System *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: Symantec Endpoint Protection *On-access scanning disabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Symantec\LiveUpdate\luall.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscsvc32.exe
C:\Documents and Settings\Jamie\Desktop\dds.scr
c:\program files\logitech\quickcam\lu\lulnchr.exe
c:\program files\logitech\quickcam\lu\LogitechUpdate.exe

============== Pseudo HJT Report ===============

uStart Page = https://home.nyu.edu/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1060908
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Protection System] "c:\program files\protection system\psystem.exe" -noscan
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [CTSVolFE.exe] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppsc1~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpohmr08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: musicmatch.com\online
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jamie\applic~1\mozilla\firefox\profiles\skixw25y.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://home.nyu.edu/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - plugin: c:\documents and settings\jamie\application data\move networks\plugins\npqmp071500000347.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.zencast -
============= SERVICES / DRIVERS ===============

R2 BCMWLNPF;Broadcom Netgroup Packet Filter;c:\windows\system32\drivers\BCMWLNPF.SYS [2006-9-8 33664]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-8-7 108392]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-8-7 108392]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2009-8-7 2440632]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-9-7 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090807.007\NAVENG.SYS [2009-9-7 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090807.007\NAVEX15.SYS [2009-9-7 875728]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\viewpoint\common\viewpointservice.exe" –> c:\program files\viewpoint\common\ViewpointService.exe [?]

=============== Created Last 30 ================

2009-09-07 17:05 123,952 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-09-07 17:05 60,800 a——- c:\windows\system32\S32EVNT1.DLL
2009-09-07 17:05 10,563 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-09-07 17:05 805 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-09-07 16:18 31,232 a——- c:\windows\system32\wingenocx.dll
2009-09-07 11:45 102,664 a——- c:\windows\system32\drivers\tmcomm.sys
2009-09-07 11:29 –d—– c:\documents and settings\jamie\.housecall6.6
2009-09-07 10:21 1,010,176 a——- c:\windows\system32\wscsvc32.exe
2009-08-12 09:42 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx

==================== Find3M ====================

2009-08-24 22:15 0 ac—— c:\windows\system32\drivers\lvuvc.hs
2009-08-24 22:15 0 ac—— c:\windows\system32\drivers\logiflt.iad
2009-08-07 17:05 107,848 a——- c:\windows\system32\SymVPN.dll
2009-08-07 17:05 89,088 a——- c:\windows\system32\atl71.dll
2009-08-07 17:05 49,480 a——- c:\windows\system32\FwsVpn.dll
2009-08-07 17:05 319,920 a——- c:\windows\system32\drivers\srtspl.sys
2009-08-07 17:05 280,112 a——- c:\windows\system32\drivers\srtsp.sys
2009-08-07 17:05 43,824 a——- c:\windows\system32\drivers\srtspx.sys
2009-08-07 17:05 7,372 a——- c:\windows\system32\drivers\srtspl.cat
2009-08-07 17:05 7,368 a——- c:\windows\system32\drivers\srtsp.cat
2009-08-07 17:05 7,359 a——- c:\windows\system32\drivers\srtspx.cat
2009-08-07 17:05 1,431 a——- c:\windows\system32\drivers\srtspl.inf
2009-08-07 17:05 1,422 a——- c:\windows\system32\drivers\srtspx.inf
2009-08-07 17:05 1,416 a——- c:\windows\system32\drivers\srtsp.inf
2009-08-07 17:04 23,888 a——- c:\windows\system32\drivers\COH_Mon.sys
2009-08-07 17:04 10,537 a——- c:\windows\system32\drivers\coh_mon.cat
2009-08-07 17:04 706 a——- c:\windows\system32\drivers\COH_Mon.inf
2009-08-05 05:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-08-05 05:11 204,800 a——- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll
2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll
2009-07-17 14:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 14:55 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 10:08 286,720 ——– c:\windows\system32\dllcache\wmpdxm.dll
2009-07-13 10:08 5,537,792 ——– c:\windows\system32\dllcache\wmp.dll
2009-07-10 09:42 1,315,328 a——- c:\windows\system32\dllcache\msoe.dll
2009-07-02 19:32 3,766 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-29 04:35 634,632 ——– c:\windows\system32\dllcache\iexplore.exe
2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat
2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-06-25 04:17 729,600 a——- c:\windows\system32\lsasrv.dll
2009-06-25 04:17 301,568 a——- c:\windows\system32\kerberos.dll
2009-06-25 04:17 168,448 a——- c:\windows\system32\schannel.dll
2009-06-25 04:17 136,192 a——- c:\windows\system32\msv1_0.dll
2009-06-25 04:17 59,392 a——- c:\windows\system32\wdigest.dll
2009-06-25 04:17 56,320 a——- c:\windows\system32\secur32.dll
2009-06-25 04:17 729,600 ——– c:\windows\system32\dllcache\lsasrv.dll
2009-06-25 04:17 301,568 ——– c:\windows\system32\dllcache\kerberos.dll
2009-06-25 04:17 168,448 ——– c:\windows\system32\dllcache\schannel.dll
2009-06-25 04:17 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll
2009-06-25 04:17 59,392 ——– c:\windows\system32\dllcache\wdigest.dll
2009-06-25 04:17 56,320 ——– c:\windows\system32\dllcache\secur32.dll
2009-06-22 07:49 117,248 a——- c:\windows\system32\mqtgsvc.exe
2009-06-22 07:49 117,248 a——- c:\windows\system32\dllcache\mqtgsvc.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\mqbkup.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\dllcache\mqbkup.exe
2009-06-22 07:49 4,608 a——- c:\windows\system32\mqsvc.exe
2009-06-22 07:49 4,608 ——– c:\windows\system32\dllcache\mqsvc.exe
2009-06-22 07:48 91,776 a——- c:\windows\system32\dllcache\mqac.sys
2009-06-22 07:35 92,544 ——– c:\windows\system32\dllcache\ksecdd.sys
2009-06-16 10:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\dllcache\fontsub.dll
2009-06-16 10:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-12 07:50 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 07:50 80,896 a——- c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\dllcache\telnet.exe
2006-09-15 21:03 0 ac—— c:\docume~1\jamie\applic~1\wklnhst.dat
2008-12-21 23:46 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008122120081222\index.dat

============= FINISH: 23:36:46.37 ===============


ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/08 23:48
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP2
==================================================

Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA9E5C000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF89CE000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA83BE000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden Services
——————-
Service Name: UACd.sys
Image Path: C:\WINDOWS\system32\drivers\UACwvjoewxlya.sys

==EOF==

Attachments:

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.Close all other windows/browser first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do Not run combofix more than once. If you have problems please post back for further instructions.
3.CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.
So far, the "protection system" popups seem to have disappeared. Computer seems to be running smoothly. CPU usage fluctuates less when not in use. Awaiting the next steps I should takes. Seems like there is progress. Thanks a bunch!

ComboFix 09-09-08.07 - Jamie 09/09/2009 10:31.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.139 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jamie\My Documents\ZbThumbnail.info
c:\program files\Protection System
c:\windows\Installer\4681ae.msi
c:\windows\Installer\4681b4.msi
c:\windows\kb913800.exe
c:\windows\system32\drivers\UACwvjoewxlya.sys
c:\windows\system32\UACbdqvxrgilt.dll
c:\windows\system32\UACgvmpfumqsp.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACsdjdwnrvkk.dll
c:\windows\system32\UACwbuoxbqjnk.dll
c:\windows\system32\wscsvc32.exe
c:\windows\TEMP\logishrd\LVPrcInj02.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_UACd.sys
——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-08-09 to 2009-09-09 )))))))))))))))))))))))))))))))
.

2009-09-09 02:50 . 2009-09-09 02:51 ——– d—–w- c:\program files\ERUNT
2009-09-09 02:50 . 2009-06-21 22:04 153088 ——w- c:\windows\system32\dllcache\triedit.dll
2009-09-07 21:18 . 2009-09-07 21:18 ——– d—–w- c:\documents and settings\Jamie\Local Settings\Application Data\Symantec
2009-09-07 21:05 . 2009-09-07 21:05 60800 —-a-w- c:\windows\system32\S32EVNT1.DLL
2009-09-07 21:05 . 2009-09-07 21:05 123952 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-09-07 15:45 . 2009-09-07 15:36 102664 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-09-07 15:29 . 2009-09-07 19:57 ——– d—–w- c:\documents and settings\Jamie\.housecall6.6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-09 02:59 . 2006-09-08 09:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-09-07 21:13 . 2006-09-08 09:59 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-09-07 21:05 . 2006-09-08 09:59 ——– d—–w- c:\program files\Symantec
2009-09-07 21:05 . 2009-09-07 21:05 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-09-07 21:05 . 2009-09-07 21:05 10563 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-09-07 19:53 . 2006-09-08 09:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-08-25 03:03 . 2008-08-26 05:56 ——– d—–w- c:\documents and settings\Jamie\Application Data\Skype
2009-08-25 02:15 . 2008-08-04 23:50 0 -c–a-w- c:\windows\system32\drivers\lvuvc.hs
2009-08-25 02:15 . 2008-09-05 01:57 0 -c–a-w- c:\windows\system32\drivers\logiflt.iad
2009-08-25 01:10 . 2008-08-26 05:57 ——– d—–w- c:\documents and settings\Jamie\Application Data\skypePM
2009-08-07 21:05 . 2009-08-07 21:05 89088 —-a-w- c:\windows\system32\atl71.dll
2009-08-07 21:05 . 2009-08-07 21:05 49480 —-a-w- c:\windows\system32\FwsVpn.dll
2009-08-07 21:05 . 2009-08-07 21:05 107848 —-a-w- c:\windows\system32\SymVPN.dll
2009-08-07 21:05 . 2009-08-07 21:05 7372 —-a-w- c:\windows\system32\drivers\srtspl.cat
2009-08-07 21:05 . 2009-08-07 21:05 7368 —-a-w- c:\windows\system32\drivers\srtsp.cat
2009-08-07 21:05 . 2009-08-07 21:05 7359 —-a-w- c:\windows\system32\drivers\srtspx.cat
2009-08-07 21:05 . 2009-08-07 21:05 43824 —-a-w- c:\windows\system32\drivers\srtspx.sys
2009-08-07 21:05 . 2009-08-07 21:05 319920 —-a-w- c:\windows\system32\drivers\srtspl.sys
2009-08-07 21:05 . 2009-08-07 21:05 280112 —-a-w- c:\windows\system32\drivers\srtsp.sys
2009-08-07 21:05 . 2009-08-07 21:05 1431 —-a-w- c:\windows\system32\drivers\srtspl.inf
2009-08-07 21:05 . 2009-08-07 21:05 1422 —-a-w- c:\windows\system32\drivers\srtspx.inf
2009-08-07 21:05 . 2009-08-07 21:05 1416 —-a-w- c:\windows\system32\drivers\srtsp.inf
2009-08-07 21:04 . 2009-08-07 21:04 706 —-a-w- c:\windows\system32\drivers\COH_Mon.inf
2009-08-07 21:04 . 2009-08-07 21:04 23888 —-a-w- c:\windows\system32\drivers\COH_Mon.sys
2009-08-07 21:04 . 2009-08-07 21:04 10537 —-a-w- c:\windows\system32\drivers\coh_mon.cat
2009-08-05 09:11 . 2005-08-16 09:18 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55 . 2005-08-16 09:18 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-16 22:02 . 2008-12-06 19:08 ——– d—–w- c:\documents and settings\Jamie\Application Data\Move Networks
2009-07-13 14:08 . 2005-08-16 09:19 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-02 23:32 . 2006-09-16 03:19 3766 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-07-02 23:32 . 2006-09-16 03:19 88 –sh–r- c:\windows\system32\13882B5DDD.sys
2009-06-29 16:12 . 2005-08-16 09:18 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2005-08-16 09:18 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2005-08-16 09:18 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 18:36 . 2005-08-16 09:18 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2005-08-16 09:18 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2005-08-16 09:18 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2005-08-16 09:18 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2005-08-16 09:18 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2005-08-16 09:18 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2005-08-16 09:18 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2005-08-16 09:18 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-25 18:36 . 2005-08-16 09:18 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2005-08-16 09:18 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2005-08-16 09:18 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2005-08-16 09:18 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 08:17 . 2005-08-16 09:18 59392 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:17 . 2005-08-16 09:18 56320 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:17 . 2005-08-16 09:18 168448 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:17 . 2005-08-16 09:18 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:17 . 2005-08-16 09:18 729600 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:17 . 2005-08-16 09:18 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-22 11:49 . 2005-08-16 09:18 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2005-08-16 09:18 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2005-08-16 09:18 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2005-08-16 09:18 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-22 11:35 . 2005-08-16 09:18 92544 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:55 . 2005-08-16 09:18 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2005-08-16 09:18 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 11:50 . 2005-08-16 09:18 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 2005-08-16 09:18 76288 —-a-w- c:\windows\system32\telnet.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-20 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"CTSVolFE.exe"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-01-21 185896]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-08-07 115560]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-9-8 24576]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-8-4 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=

R2 BCMWLNPF;Broadcom Netgroup Packet Filter;c:\windows\system32\drivers\BCMWLNPF.SYS [9/8/2006 5:25 AM 33664]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/8/2009 11:44 PM 102448]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" –> c:\program files\Viewpoint\Common\ViewpointService.exe [?]
.
Contents of the 'Scheduled Tasks' folder

2006-12-21 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8158372416.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 05:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://home.nyu.edu/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Jamie\Application Data\Mozilla\Firefox\Profiles\skixw25y.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://home.nyu.edu/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Jamie\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll

—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.zencast - .
- - - - ORPHANS REMOVED - - - -

HKCU-Run-ModemOnHold - c:\program files\NetWaiting\netWaiting.exe
HKCU-Run-Protection System - c:\program files\Protection System\psystem.exe
SafeBoot-Symantec Antvirus
AddRemove-HP PSC 1200 Series - c:\program files\Hewlett-Packard\Digital Imaging\{7C8BB31C-E09E-4c7d-BBF1-45E33B467FE1}\Setup\hpzscr01.exe -datfile hposcr02.dat



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-09 10:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2716)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\browselc.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
c:\windows\System32\DLA\DLASHX_W.DLL
c:\windows\system32\DLAAPI_W.DLL
c:\windows\System32\DLA\DLACResW.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
.
———————— Other Running Processes ————————
.
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
c:\program files\Logitech\QuickCam\LU\LULnchr.exe
c:\program files\Logitech\QuickCam\LU\LogitechUpdate.exe
.
**************************************************************************
.
Completion time: 2009-09-09 10:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-09 14:52

Pre-Run: 3,847,806,976 bytes free
Post-Run: 6,385,848,320 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

259 — E O F — 2009-09-09 04:03
Yes, looking better. Some updating and scans to run.

Your version of Java is outdated.

Please download JavaRa to your desktop and unzip it to its own folder

Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

~~~~~~~~~~~~~~~~~~~~~~~~~~

Next, use Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here
Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.


Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
    * Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    * Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    * Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in
your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

In your next reply post:
Kaspersky log
New DDS log taken after the above scan has run
Malwarebytes' Anti-Malware 1.40
Database version: 2769
Windows 5.1.2600 Service Pack 2

9/9/2009 10:09:08 PM
mbam-log-2009-09-09 (22-09-08).txt

Scan type: Quick Scan
Objects scanned: 105789
Time elapsed: 10 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, September 10, 2009
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, September 10, 2009 03:23:28
Records in database: 2768520
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Objects scanned: 74928
Threats found: 3
Infected objects found: 6
Suspicious objects found: 0
Scan duration: 03:17:03


File name / Threat / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0FB00000.VBN Infected: Trojan.Win32.Tdss.ajeo 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0FB00001.VBN Infected: Trojan.Win32.Tdss.anrc 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACbdqvxrgilt.dll.vir Infected: Packed.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACsdjdwnrvkk.dll.vir Infected: Packed.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACwbuoxbqjnk.dll.vir Infected: Packed.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wscsvc32.exe.vir Infected: Packed.Win32.TDSS.y 1

Selected area has been scanned.




DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 2:10:43.05 on Thu 09/10/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.182 [GMT -4:00]

AV: Symantec Endpoint Protection *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\program files\logitech\quickcam\lu\lulnchr.exe
c:\program files\logitech\quickcam\lu\LogitechUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Jamie\Local Settings\temp\jkos-Jamie\binaries\ScanningProcess.exe
C:\Documents and Settings\Jamie\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = https://home.nyu.edu/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [CTSVolFE.exe] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppsc1~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpohmr08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: musicmatch.com\online
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jamie\applic~1\mozilla\firefox\profiles\skixw25y.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://home.nyu.edu/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - plugin: c:\documents and settings\jamie\application data\move networks\plugins\npqmp071500000347.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.zencast -
============= SERVICES / DRIVERS ===============

R2 BCMWLNPF;Broadcom Netgroup Packet Filter;c:\windows\system32\drivers\BCMWLNPF.SYS [2006-9-8 33664]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-9-8 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090908.032\NAVENG.SYS [2009-9-8 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090908.032\NAVEX15.SYS [2009-9-8 1323568]

=============== Created Last 30 ================

2009-09-09 21:56 –d—– c:\docume~1\jamie\applic~1\Malwarebytes
2009-09-09 21:56 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-09 21:56 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-09-09 21:56 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-09-09 21:56 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-09-09 21:50 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-09 21:50 73,728 a——- c:\windows\system32\javacpl.cpl
2009-09-09 10:29 a-dshr– C:\cmdcons
2009-09-09 10:27 230,912 a——- c:\windows\PEV.exe
2009-09-09 10:27 161,792 a——- c:\windows\SWREG.exe
2009-09-09 10:27 98,816 a——- c:\windows\sed.exe
2009-09-09 00:03 197 a——- c:\windows\system32\MRT.INI
2009-09-08 22:50 153,088 ——– c:\windows\system32\dllcache\triedit.dll
2009-09-07 17:05 123,952 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-09-07 17:05 60,800 a——- c:\windows\system32\S32EVNT1.DLL
2009-09-07 17:05 10,563 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-09-07 17:05 805 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-09-07 11:45 102,664 a——- c:\windows\system32\drivers\tmcomm.sys
2009-09-07 11:29 –d—– c:\documents and settings\jamie\.housecall6.6
2009-08-12 09:42 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx

==================== Find3M ====================

2009-08-24 22:15 0 ac—— c:\windows\system32\drivers\lvuvc.hs
2009-08-24 22:15 0 ac—— c:\windows\system32\drivers\logiflt.iad
2009-08-13 11:16 512,000 a——- c:\windows\system32\dllcache\jscript.dll
2009-08-07 17:05 107,848 a——- c:\windows\system32\SymVPN.dll
2009-08-07 17:05 89,088 a——- c:\windows\system32\atl71.dll
2009-08-07 17:05 49,480 a——- c:\windows\system32\FwsVpn.dll
2009-08-07 17:05 319,920 a——- c:\windows\system32\drivers\srtspl.sys
2009-08-07 17:05 280,112 a——- c:\windows\system32\drivers\srtsp.sys
2009-08-07 17:05 43,824 a——- c:\windows\system32\drivers\srtspx.sys
2009-08-07 17:05 7,372 a——- c:\windows\system32\drivers\srtspl.cat
2009-08-07 17:05 7,368 a——- c:\windows\system32\drivers\srtsp.cat
2009-08-07 17:05 7,359 a——- c:\windows\system32\drivers\srtspx.cat
2009-08-07 17:05 1,431 a——- c:\windows\system32\drivers\srtspl.inf
2009-08-07 17:05 1,422 a——- c:\windows\system32\drivers\srtspx.inf
2009-08-07 17:05 1,416 a——- c:\windows\system32\drivers\srtsp.inf
2009-08-07 17:04 23,888 a——- c:\windows\system32\drivers\COH_Mon.sys
2009-08-07 17:04 10,537 a——- c:\windows\system32\drivers\coh_mon.cat
2009-08-07 17:04 706 a——- c:\windows\system32\drivers\COH_Mon.inf
2009-08-05 05:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-08-05 05:11 204,800 a——- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll
2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll
2009-07-17 14:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 14:55 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 10:08 286,720 ——– c:\windows\system32\dllcache\wmpdxm.dll
2009-07-13 10:08 5,537,792 ——– c:\windows\system32\dllcache\wmp.dll
2009-07-10 09:42 1,315,328 a——- c:\windows\system32\dllcache\msoe.dll
2009-07-02 19:32 3,766 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-29 04:35 634,632 ——– c:\windows\system32\dllcache\iexplore.exe
2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat
2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-06-25 04:17 729,600 a——- c:\windows\system32\lsasrv.dll
2009-06-25 04:17 301,568 a——- c:\windows\system32\kerberos.dll
2009-06-25 04:17 168,448 a——- c:\windows\system32\schannel.dll
2009-06-25 04:17 136,192 a——- c:\windows\system32\msv1_0.dll
2009-06-25 04:17 59,392 a——- c:\windows\system32\wdigest.dll
2009-06-25 04:17 56,320 a——- c:\windows\system32\secur32.dll
2009-06-25 04:17 729,600 ——– c:\windows\system32\dllcache\lsasrv.dll
2009-06-25 04:17 301,568 ——– c:\windows\system32\dllcache\kerberos.dll
2009-06-25 04:17 168,448 ——– c:\windows\system32\dllcache\schannel.dll
2009-06-25 04:17 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll
2009-06-25 04:17 59,392 ——– c:\windows\system32\dllcache\wdigest.dll
2009-06-25 04:17 56,320 ——– c:\windows\system32\dllcache\secur32.dll
2009-06-22 07:49 117,248 a——- c:\windows\system32\mqtgsvc.exe
2009-06-22 07:49 117,248 a——- c:\windows\system32\dllcache\mqtgsvc.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\mqbkup.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\dllcache\mqbkup.exe
2009-06-22 07:49 4,608 a——- c:\windows\system32\mqsvc.exe
2009-06-22 07:49 4,608 ——– c:\windows\system32\dllcache\mqsvc.exe
2009-06-22 07:48 91,776 a——- c:\windows\system32\dllcache\mqac.sys
2009-06-22 07:35 92,544 ——– c:\windows\system32\dllcache\ksecdd.sys
2009-06-16 10:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\dllcache\fontsub.dll
2009-06-16 10:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-12 07:50 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 07:50 80,896 a——- c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\dllcache\telnet.exe
2006-09-15 21:03 0 ac—— c:\docume~1\jamie\applic~1\wklnhst.dat
2008-12-21 23:46 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008122120081222\index.dat

============= FINISH: 2:11:50.85 ===============

Attachments:

Looking pretty clean. You still have an older version of Java on there that should be uninstalled. Use Control Panel/Add/Remove Programs to unistall:

Java™ 6 Update 14

Version 16 should stay.

Also, you should update your Adobe Reader.

http://get.adobe.com/reader/

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    [external image: Posted Image]
The above procedure will:
  • Delete the following: ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

If all is well the just some final advice.

In addition to updating and using what you currently have you may want to consider the following:

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install Winpatrol -
Use Winpatrol to take control of your PC and provide another layer of security.
Help file and tutorial can be found Here

Block unwanted parasites with a custom hosts file -
http://www.mvps.org/winhelp2002/hosts.htm

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

Keep your applications up to date -
Use Secunia Personal Software Inspector to help stay on top of application updates that could leave your PC vulnerable to attack.

I'll leave the thread open a few days in case you have questions or issues.

Regards,
Dave
Java Update 14 uninstalled. Adobe Reader updated. ComboFix uninstalled. Symantec Endpoint Protection re-enabled. Updated to Service Pack 3. Questions: Is it okay to delete/uninstall everything else that was downloaded (ERUNT, MBAM, logs, etc.)? Although I might consider keeping MBAM for periodic scans. Two MSDOS windows popup at startup of Windows running cmd.exe but closes by itself later. Is that an issue? I'm still a little worried about possible infections in the external hard drive. Would it be okay to scan it (if so, which program should I use)? Thanks so much for the help you have provided so far!
I would suggest you keep both ERUNT and MBAM. MBAM is good for occasional scans and I have ERUNT back up my registry daily. Can't hurt to have it but up to you.

Two MSDOS windows popup at startup of Windows running cmd.exe but closes by itself later. Is that an issue?

Interesting? Can you see anything in the Window?

I'm still a little worried about possible infections in the external hard drive. Would it be okay to scan it (if so, which program should I use)?

Definitely okay to scan. What drive designation is it? When you ran Kaspersky it scanned C, D, and E.

Scan area - My Computer:
C:\
D:\
E:\

You can use Symantec also on it.
Okay. Keeping MBAM and ERUNT. The two MSDOS windows stopped showing up. Restarted a few times just to double check. Scanned the external (drive G). I guess it is clear also. I believe you can close this thread now. Sister just started classes and her laptop is especially important at this time. YOU ARE A LIFESAVER! THANK YOU SO MUCH DAVE!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI