This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can only browse one site in IE6

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Friends: I can browse with Firefox, no problem. When I try to browse with IE6, I find I can only pull up one site and get the following message when I try to browse any other sites: " The requested lookup key was not found in any activation context". Windows XP Pro. Please help. Thank you. Here is my HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:19:05, on 10/31/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis\HijackThis.exe

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: 94.247.2.216 search.yahoo.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Search - ?p=ZS
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?69e5dcbc3c174f3bb218825acd4bfce6
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?69e5dcbc3c174f3bb218825acd4bfce6
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://fadeelak9984.spaces.live.com//Photo…ad/MsnPUpld.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

–
End of file - 7040 bytes
Hi Wakenaam,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Also please describe how your computer behaves at the moment.
Hello Tomk: Thanks for your response. The computer which was giving problems with IE6, I formatted and reinstalled XP Pro. Works fine now. My other computer (this one) is painting all my VLC icons black. The icons start our initially for a split second in original colour then they get repainted in black. Would appreciate your help on this. Did the TFC and the Malwarebytes scans. Results of the Malware scan is posted. Windows XP Pro. I did not do a HJT scan now as you did not request one. Thanks for any help. Malwarebytes' Anti-Malware 1.41 Database version: 3115 Windows 5.1.2600 Service Pack 2 11/7/2009 8:41:10 AM mbam-log-2009-11-07 (08-41-10).txt Scan type: Full Scan (C:\|) Objects scanned: 202922 Time elapsed: 25 minute(s), 25 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Wakenaam,

So we've switched computers now?

Then we need to start at the beginning.

  • Download DDS and save it to your desktop from
  • Here
  • here or
  • here.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click DDS icon to run the tool (may take up to 3 minutes to run)
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
  • We Need to check for Rootkits with RootRepeal
    • Download RootRepeal from one of the following locations and save it to your desktop.
    • Open [external image: Posted Image] on your desktop.
    • Click the [external image: Posted Image] tab.
    • Click the [external image: Posted Image] button.
    • In the Select Scan dialog, check
      [external image: Posted Image]
    • Push Ok
    • Check the box for your main system drive (Usually C:), and press Ok.
    • Allow RootRepeal to run a scan of your system. This may take some time.
    • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
  • Copy/paste the log (that you've previously saved to your desktop) from RootRepeal onto your post.

  • Copy/paste the DDS.txt log (that you've previously saved to your desktop) onto your post.

  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
TomK: Thanks for your responses. Here is the RootRepeal log: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/11/08 08:37 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP2 ================================================== Drivers ——————- Name: Image Path: Address: 0xF74D6000 Size: 95360 File Visible: No Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xA994E000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7C19000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA852C000 Size: 49152 File Visible: No Signed: - Status: - SSDT ——————- #: 041 Function Name: NtCreateKey Status: Hooked by "TfSysMon.sys" at address 0xf7483a1c #: 063 Function Name: NtDeleteKey Status: Hooked by "TfSysMon.sys" at address 0xf7483c10 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "TfSysMon.sys" at address 0xf7483cb6 #: 119 Function Name: NtOpenKey Status: Hooked by "TfSysMon.sys" at address 0xf748390c #: 247 Function Name: NtSetValueKey Status: Hooked by "TfSysMon.sys" at address 0xf7483e52 #: 257 Function Name: NtTerminateProcess Status: Hooked by "TfSysMon.sys" at address 0xf7485b30 ==EOF== Here is the DDS.txt log: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 8:12:08.53 on Sun 11/08/2009 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.520 [GMT -5:00] AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB} AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Hotspot Shield\bin\openvpnas.exe C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\Norton Ghost\Agent\VProSvc.exe C:\Documents and Settings\Fazela\Application Data\mjusbsp\magicJack.exe C:\Nexon\MapleStory\npkcmsvc.exe C:\Macrium Reflect Free\ReflectService.exe C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\dllhost.exe C:\Program Files\ThreatFire\TFService.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\msdtc.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Windows Live\Toolbar\wltuser.exe C:\Documents and Settings\Fazela\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.netscape.com/ mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\7z.exe, BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [cdloader] "c:\documents and settings\fazela\application data\mjusbsp\cdloader2.exe" MAGICJACK mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background dRun: [services] c:\windows\services.exe dRun: [reader_s] c:\documents and settings\fazela\reader_s.exe dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe uPolicies-explorer: HideSCANetwork = 0 (0x0) uPolicies-explorer: HideSCAVolume = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Open in new background tab - c:\program files\windows live toolbar\components\en-ca\msntabres.dll.mui/229?e4b23bd0b5ec4cd1a429ca8bc7552c68 IE: Open in new foreground tab - c:\program files\windows live toolbar\components\en-ca\msntabres.dll.mui/230?e4b23bd0b5ec4cd1a429ca8bc7552c68 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Trusted Zone: antimalwareguard.com Trusted Zone: antimalwareguard.com DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: igfxcui - igfxdev.dll Notify: xxbwzn - xxbwzn.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\fazela\applic~1\mozilla\firefox\profiles\75umymae.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157 FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2008-5-20 15328] R0 tdrpman228;Acronis Try&Decide and Restore Points filter (build 228);c:\windows\system32\drivers\tdrpm228.sys [2009-10-4 902592] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-9-23 51984] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-9-23 59664] R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [2008-9-14 140800] R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [2008-9-14 5248] R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [2006-12-14 12964] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-9-4 9968] R2 HssSrv;Hotspot Shield Routing Service;c:\program files\hotspot shield\hsswpr\hsssrv.exe [2009-6-1 331312] R2 ReflectService;Macrium Reflect Image Mounting Service;c:\macrium reflect free\ReflectService.exe [2008-8-6 216032] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512] R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2004-8-3 5120] R2 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service –> c:\program files\threatfire\TFService.exe service [?] R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2007-12-20 1562096] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-9-23 33552] S0 ati0jpxx;ati0jpxx;c:\windows\system32\drivers\ati0jpxx.sys –> c:\windows\system32\drivers\ati0jpxx.sys [?] S0 ati0qwxx;ati0qwxx;c:\windows\system32\drivers\ati0qwxx.sys –> c:\windows\system32\drivers\ati0qwxx.sys [?] S1 SASKUTIL;SASKUTIL;\??\c:\superantispyware\saskutil.sys –> c:\superantispyware\SASKUTIL.sys [?] S2 0060701201636616mcinstcleanup;0060701201636616mcinstcleanup; [x] S2 0210201202775077mcinstcleanup;0210201202775077mcinstcleanup; [x] S2 IcRecUsb;IC Recorder Driver;c:\windows\system32\drivers\IcRecUsb.sys [2009-9-23 17432] S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\hotspot shield\bin\HssTrayService.exe [2009-6-1 34352] S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [2008-7-8 31712] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-9-4 7408] =============== Created Last 30 ================ 2009-11-04 18:15 –d—– c:\windows\system32\wbem\Repository 2009-11-03 06:29 –d—– C:\Kaaba 2009-10-23 11:42 –d—– C:\All In The Family S06 Episodes 13 - 24 (of 24) 2009-10-23 11:39 –d—– C:\All In The Family S06 Episodes 1 - 12 (of 24) 2009-10-22 08:35 –d—– c:\program files\common files\Sony Shared 2009-10-21 17:29 –d—– C:\All In The Family S05 Episodes 13 - 24 (of 24) 2009-10-21 17:27 –d—– C:\All In The Family S05 Episodes 1 - 12 (of 24) 2009-10-21 01:27 –d—– C:\All.In.The.Family.S3.E22-24 2009-10-20 05:51 –d—– c:\docume~1\fazela\applic~1\CursorArts 2009-10-20 05:51 0 a——- C:\Default.Bmp 2009-10-20 05:51 –d—– c:\program files\ActivIcons 2009-10-20 05:48 –d—– C:\ActivIcons 2009-10-17 22:52 –d—– C:\All In The Family #2 2009-10-17 19:21 –d—– C:\All In The Family S04 Episodes 17-24 (of 24) 2009-10-17 19:19 –d—– C:\All In The Family S04 Episodes 9-16 (of 24) 2009-10-17 19:18 –d—– C:\All In The Family S04 Episodes 1-8 (of 24) 2009-10-17 16:33 –d—– C:\All.In.The.Family.S01.DVDrip.Ac3.XviD-Jana 2009-10-17 16:21 –d—– C:\All in the family 2009-10-13 14:33 –d—– C:\My Music 2009-10-13 11:38 32,768 ac—— c:\windows\system32\dllcache\sisnic.sys 2009-10-13 11:38 32,768 a——- c:\windows\system32\drivers\sisnic.sys 2009-10-13 11:26 44,544 a—-r– c:\windows\system32\drivers\bcm4sbxp.sys 2009-10-13 09:09 156,160 ac—— c:\windows\system32\dllcache\b57xp32.sys 2009-10-13 09:09 156,160 a——- c:\windows\system32\drivers\b57xp32.sys 2009-10-12 19:31 –d—– C:\swtools 2009-10-12 14:12 135,168 a——- c:\windows\system32\igfxres.dll 2009-10-12 13:27 –d—– c:\windows\Downloaded Installations 2009-10-12 13:07 –d—– c:\program files\Broadcom 2009-10-12 13:05 220,992 a——- c:\windows\system32\drivers\smwdm.sys 2009-10-12 13:05 49,152 a——- c:\windows\system32\DSndUp.exe 2009-10-12 13:05 –d—– c:\program files\Analog Devices 2009-10-12 13:05 45,056 ——– c:\windows\system32\CleanUp.exe 2009-10-12 12:47 –d—– C:\Ibmtools 2009-10-12 10:42 92,416 ac—— c:\windows\system32\dllcache\mga.sys 2009-10-12 10:41 5,632 ac—— c:\windows\system32\dllcache\EXCH_adsiisex.dll 2009-10-12 10:40 488 a—hr– c:\windows\system32\logonui.exe.manifest 2009-10-12 10:40 749 a—hr– c:\windows\WindowsShell.Manifest 2009-10-12 10:40 749 a—hr– c:\windows\system32\wuaucpl.cpl.manifest 2009-10-12 10:40 749 a—hr– c:\windows\system32\sapi.cpl.manifest 2009-10-12 10:40 749 a—hr– c:\windows\system32\nwc.cpl.manifest 2009-10-12 10:40 749 a—hr– c:\windows\system32\ncpa.cpl.manifest 2009-10-12 10:38 16,384 ac—— c:\windows\system32\dllcache\isignup.exe 2009-10-12 10:24 –dsh— c:\windows\Installer 2009-10-12 10:24 13,312 ac—— c:\windows\system32\dllcache\irclass.dll 2009-10-12 10:24 13,312 a——- c:\windows\system32\irclass.dll 2009-10-12 10:24 24,661 ac—— c:\windows\system32\dllcache\spxcoins.dll 2009-10-12 10:24 24,661 a——- c:\windows\system32\spxcoins.dll 2009-10-10 17:11 –d—– C:\BootMaster 2009-10-10 10:01 –d—– C:\FixMBR ==================== Find3M ==================== 2009-10-12 10:36 24,724 ac—— c:\windows\system32\emptyregdb.dat 2009-10-09 07:28 2,081,048 a——- c:\windows\system32\AutoPartNt.exe 2009-10-04 02:33 902,592 a——- c:\windows\system32\drivers\tdrpm228.sys 2009-10-04 02:32 540,000 a——- c:\windows\system32\drivers\timntr.sys 2009-10-04 02:32 44,704 a——- c:\windows\system32\drivers\tifsfilt.sys 2009-10-04 02:32 138,208 ac—— c:\windows\system32\drivers\snapman.sys 2009-09-23 09:07 59,664 a——- c:\windows\system32\drivers\TfSysMon.sys 2009-09-23 09:07 33,552 a——- c:\windows\system32\drivers\TfNetMon.sys 2009-09-23 09:07 51,984 a——- c:\windows\system32\drivers\TfFsMon.sys 2009-09-10 14:54 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 14:53 19,160 ac—— c:\windows\system32\drivers\mbam.sys 2009-03-11 15:50 40,960 ac—— c:\documents and settings\fazela\hpmonZ.exe 2009-03-11 15:50 24,576 ac—— c:\documents and settings\fazela\shortcut.exe 2009-03-11 15:50 585,728 ac—— c:\documents and settings\fazela\HPAsset.exe 2009-03-02 08:50 47,360 ac—— c:\docume~1\fazela\applic~1\pcouffin.sys 2008-10-11 13:29 73,728 ac—— c:\documents and settings\fazela\zlib.dll 2008-10-11 13:29 36,208 ac—— c:\documents and settings\fazela\Dscan16.dll 2008-10-11 13:29 17,477 ac—— c:\documents and settings\fazela\Smstub16.exe 2008-10-11 13:29 2,855 ac—— c:\documents and settings\fazela\Smstub16.pif 2008-10-08 18:40 50,689,960 ac—— c:\program files\avg_free_stf_en_8_173a1373.exe 2007-11-08 16:45 32,592 ac—— c:\docume~1\fazela\applic~1\GDIPFONTCACHEV1.DAT 2007-10-04 14:55 61,480 ac—— c:\documents and settings\fazela\GoToAssistDownloadHelper.exe ============= FINISH: 8:13:56.40 =============== The attach.txt file was attached as requested. Thanks for your help again.

Attachments:

Wakenaam,

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
TomK: Thanks again for your help. Here is the report from ComboFix:

ComboFix 09-11-08.03 - Fazela 11/08/2009 22:34.4.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.589 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
ADS - WINDOWS: deleted 48 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Fazela\Application Data\inst.exe
c:\windows\kb913800.exe
c:\windows\system32\inf
c:\windows\system32\tmp.reg

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_PROTECT


((((((((((((((((((((((((( Files Created from 2009-10-09 to 2009-11-09 )))))))))))))))))))))))))))))))
.

2009-11-09 00:11 . 2009-08-01 16:16 6256600 —ha-w- c:\documents and settings\Fazela\Application Data\mjusbsp\in00000\setup.exe
2009-11-09 00:11 . 2009-08-01 16:12 728600 —ha-w- c:\documents and settings\Fazela\Application Data\mjusbsp\ar00000\install.exe
2009-11-09 00:11 . 2008-02-29 12:42 386496 —-a-w- c:\documents and settings\Fazela\Application Data\mjusbsp\ar00000\magicJackSplash.exe
2009-11-08 19:06 . 2009-11-08 19:44 ——– d—–w- c:\program files\DVDFab 5
2009-11-08 18:58 . 2009-11-08 19:04 ——– d—–w- C:\DVDFab.Platinum.v5.2.5.0
2009-11-08 18:54 . 2009-11-08 18:56 ——– d—–w- C:\dvdfab
2009-11-08 17:53 . 2009-11-08 17:55 ——– d—–w- C:\Slysoft CloneDVD2 V2.9.1.9(KNIGHTY1973)
2009-11-04 23:15 . 2009-11-04 23:15 ——– d—–w- c:\windows\system32\wbem\Repository
2009-11-03 11:29 . 2009-11-03 11:50 ——– d—–w- C:\Kaaba
2009-10-23 16:42 . 2009-10-30 20:44 ——– d—–w- C:\All In The Family S06 Episodes 13 - 24 (of 24)
2009-10-23 16:39 . 2009-11-08 14:20 ——– d—–w- C:\All In The Family S06 Episodes 1 - 12 (of 24)
2009-10-22 13:46 . 2009-10-22 13:46 ——– d—–w- c:\documents and settings\Fazela\Application Data\Sony Corporation
2009-10-22 13:35 . 2009-10-22 13:35 ——– d—–w- c:\program files\Common Files\Sony Shared
2009-10-22 13:34 . 2009-10-22 13:43 ——– d—–w- c:\documents and settings\Fazela\Local Settings\Application Data\Downloaded Installations
2009-10-22 13:31 . 2009-10-22 13:31 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-10-21 22:29 . 2009-10-23 12:14 ——– d—–w- C:\All In The Family S05 Episodes 13 - 24 (of 24)
2009-10-21 22:27 . 2009-11-03 02:30 ——– d—–w- C:\All In The Family S05 Episodes 1 - 12 (of 24)
2009-10-21 06:27 . 2009-10-21 20:35 ——– d—–w- C:\All.In.The.Family.S3.E22-24
2009-10-20 10:51 . 2009-10-20 10:51 ——– d—–w- c:\documents and settings\Fazela\Application Data\CursorArts
2009-10-20 10:51 . 2009-10-20 15:33 ——– d—–w- c:\program files\ActivIcons
2009-10-20 10:48 . 2009-10-20 10:49 ——– d—–w- C:\ActivIcons
2009-10-18 03:52 . 2009-11-06 20:31 ——– d—–w- C:\All In The Family #2
2009-10-18 00:21 . 2009-10-23 17:13 ——– d—–w- C:\All In The Family S04 Episodes 17-24 (of 24)
2009-10-18 00:19 . 2009-10-22 11:58 ——– d—–w- C:\All In The Family S04 Episodes 9-16 (of 24)
2009-10-18 00:18 . 2009-10-19 09:36 ——– d—–w- C:\All In The Family S04 Episodes 1-8 (of 24)
2009-10-17 21:33 . 2009-11-05 23:06 ——– d—–w- C:\All.In.The.Family.S01.DVDrip.Ac3.XviD-Jana
2009-10-17 21:21 . 2009-10-23 16:39 ——– d—–w- C:\All in the family
2009-10-17 00:18 . 2009-11-08 17:02 ——– d—–w- c:\documents and settings\Fazela\Application Data\vlc
2009-10-13 19:33 . 2009-10-13 19:33 ——– d—–w- C:\My Music
2009-10-13 16:38 . 2004-08-04 02:31 32768 -c–a-w- c:\windows\system32\dllcache\sisnic.sys
2009-10-13 16:38 . 2004-08-04 02:31 32768 —-a-w- c:\windows\system32\drivers\sisnic.sys
2009-10-13 16:26 . 2006-05-17 15:03 44544 —-a-r- c:\windows\system32\drivers\bcm4sbxp.sys
2009-10-13 14:09 . 2006-05-10 19:00 156160 -c–a-w- c:\windows\system32\dllcache\b57xp32.sys
2009-10-13 14:09 . 2006-05-10 19:00 156160 —-a-w- c:\windows\system32\drivers\b57xp32.sys
2009-10-13 00:31 . 2009-10-13 13:59 ——– d—–w- C:\swtools
2009-10-12 19:12 . 2006-02-07 12:35 135168 —-a-w- c:\windows\system32\igfxres.dll
2009-10-12 18:27 . 2009-10-12 18:43 ——– d—–w- c:\windows\Downloaded Installations
2009-10-12 18:07 . 2009-10-13 14:09 ——– d—–w- c:\program files\Broadcom
2009-10-12 18:05 . 2005-03-28 14:19 220992 —-a-w- c:\windows\system32\drivers\smwdm.sys
2009-10-12 18:05 . 2009-10-12 18:05 ——– d—–w- c:\program files\Analog Devices
2009-10-12 18:05 . 2004-12-08 21:16 49152 —-a-w- c:\windows\system32\DSndUp.exe
2009-10-12 18:05 . 2002-04-17 19:05 45056 ——w- c:\windows\system32\CleanUp.exe
2009-10-12 17:47 . 2009-10-12 17:48 ——– d—–w- C:\Ibmtools
2009-10-12 15:42 . 2006-07-19 20:16 7680 -c–a-w- c:\windows\system32\dllcache\migregdb.exe
2009-10-12 15:41 . 2001-08-18 02:36 5632 -c–a-w- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-10-12 15:38 . 2001-08-23 12:00 16384 -c–a-w- c:\windows\system32\dllcache\isignup.exe
2009-10-12 15:24 . 2009-10-22 13:45 ——– d-sh–w- c:\windows\Installer
2009-10-12 15:24 . 2001-08-23 12:00 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2009-10-12 15:24 . 2001-08-23 12:00 13312 —-a-w- c:\windows\system32\irclass.dll
2009-10-12 15:24 . 2001-08-23 12:00 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-10-12 15:24 . 2001-08-23 12:00 24661 —-a-w- c:\windows\system32\spxcoins.dll
2009-10-10 22:11 . 2009-10-10 22:43 ——– d—–w- C:\BootMaster
2009-10-10 15:01 . 2009-10-10 15:04 ——– d—–w- C:\FixMBR

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-09 00:11 . 2009-01-16 21:39 ——– d—–w- c:\documents and settings\Fazela\Application Data\mjusbsp
2009-11-08 19:41 . 2009-02-28 15:42 ——– d—–w- c:\documents and settings\All Users\Application Data\vsosdk
2009-11-08 19:08 . 2007-07-24 17:11 ——– d—–w- c:\documents and settings\Fazela\Application Data\uTorrent
2009-11-08 19:06 . 2009-02-27 23:47 ——– d—–w- c:\documents and settings\Fazela\Application Data\Vso
2009-11-08 19:06 . 2009-02-27 23:47 47360 -c–a-w- c:\documents and settings\Fazela\Application Data\pcouffin.sys
2009-11-08 19:06 . 2009-02-27 23:47 47360 -c–a-w- c:\documents and settings\Fazela\Application Data\pcouffin.sys
2009-11-08 19:06 . 2009-02-27 23:47 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-07 12:56 . 2007-10-11 20:44 ——– d—–w- c:\program files\Softwin
2009-11-07 12:56 . 2007-10-09 15:49 ——– d—–w- c:\program files\Common Files\Softwin
2009-10-25 23:14 . 2009-09-13 14:52 117760 —-a-w- c:\documents and settings\Fazela\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-25 12:57 . 2009-08-11 02:38 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-10-20 00:49 . 2008-10-21 04:01 ——– d—–w- c:\documents and settings\Fazela\Application Data\Skype
2009-10-20 00:24 . 2008-10-21 02:51 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-10-20 00:24 . 2008-10-21 04:13 ——– d—–w- c:\documents and settings\Fazela\Application Data\skypePM
2009-10-13 01:17 . 2006-12-14 13:40 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-10-12 15:36 . 2006-12-14 00:26 24724 -c–a-w- c:\windows\system32\emptyregdb.dat
2009-10-12 15:36 . 2006-12-14 00:25 ——– d—–w- c:\program files\Windows Media Connect 2
2009-10-09 12:28 . 2009-10-05 16:28 2081048 —-a-w- c:\windows\system32\AutoPartNt.exe
2009-10-06 18:38 . 2009-09-13 14:51 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-10-05 18:30 . 2008-09-06 21:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-05 18:27 . 2008-10-21 05:11 ——– d—–w- c:\program files\Norton Ghost
2009-10-04 07:34 . 2008-10-22 18:51 ——– d—–w- c:\program files\Common Files\Acronis
2009-10-04 07:33 . 2009-10-04 07:33 902592 —-a-w- c:\windows\system32\drivers\tdrpm228.sys
2009-10-04 07:32 . 2008-10-22 18:52 540000 —-a-w- c:\windows\system32\drivers\timntr.sys
2009-10-04 07:32 . 2008-10-22 18:52 44704 —-a-w- c:\windows\system32\drivers\tifsfilt.sys
2009-10-04 07:32 . 2008-10-22 18:52 138208 -c–a-w- c:\windows\system32\drivers\snapman.sys
2009-09-30 12:28 . 2009-03-13 21:12 ——– d—–w- c:\program files\ThreatFire
2009-09-29 10:27 . 2007-01-03 21:06 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-23 14:07 . 2009-09-23 13:44 59664 —-a-w- c:\windows\system32\drivers\TfSysMon.sys
2009-09-23 14:07 . 2009-09-23 13:44 33552 —-a-w- c:\windows\system32\drivers\TfNetMon.sys
2009-09-23 14:07 . 2009-09-23 13:44 51984 —-a-w- c:\windows\system32\drivers\TfFsMon.sys
2009-09-23 12:22 . 2009-09-23 12:20 ——– d—–w- c:\program files\Panasonic
2009-09-22 10:38 . 2009-05-30 22:46 ——– d—–w- c:\documents and settings\Fazela\Application Data\dvdcss
2009-09-16 14:21 . 2006-12-17 14:22 33176 -c–a-w- c:\documents and settings\Fazela\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-16 14:14 . 2009-09-16 14:06 ——– d—–w- c:\program files\Windows Live
2009-09-16 14:14 . 2006-12-14 02:55 ——– d—–w- c:\program files\Windows Live Toolbar
2009-09-16 14:13 . 2009-09-16 14:13 ——– d—–w- c:\program files\Microsoft Sync Framework
2009-09-16 14:11 . 2009-09-16 14:11 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-16 14:08 . 2006-12-14 02:54 ——– d—–w- c:\program files\MSN Messenger
2009-09-16 14:07 . 2009-09-16 14:07 ——– d—–w- c:\program files\Microsoft
2009-09-16 14:07 . 2009-09-16 14:07 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-09-16 13:27 . 2009-09-16 13:27 ——– d—–w- c:\program files\Common Files\Windows Live
2009-09-14 11:00 . 2007-01-03 19:27 ——– d—–w- c:\program files\Common Files\Real
2009-09-14 10:59 . 2009-09-14 10:59 ——– d—–w- c:\program files\Common Files\xing shared
2009-09-14 03:34 . 2008-10-07 16:39 4045528 -c–a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-09-13 14:51 . 2009-08-11 02:38 ——– d—–w- c:\documents and settings\Fazela\Application Data\SUPERAntiSpyware.com
2009-09-10 19:54 . 2008-10-07 16:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2008-10-07 16:38 19160 -c–a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 14:36 . 2009-09-04 14:36 0 —-a-w- c:\windows\system32\cd.dat
2008-10-08 23:40 . 2008-10-08 23:38 50689960 -c–a-w- c:\program files\avg_free_stf_en_8_173a1373.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-06-20 19:08 218160 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"cdloader"="c:\documents and settings\Fazela\Application Data\mjusbsp\cdloader2.exe" [2009-08-01 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-14 198160]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-03-11 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HideSCANetwork"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0jpxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0qwxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Enable Labtec Wireless Desktop.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Enable Labtec Wireless Desktop.lnk
backup=c:\windows\pss\Enable Labtec Wireless Desktop.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Fazela\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"57124:TCP"= 57124:TCP:Pando Media Booster
"57124:UDP"= 57124:UDP:Pando Media Booster
"57479:TCP"= 57479:TCP:Pando Media Booster
"57479:UDP"= 57479:UDP:Pando Media Booster

R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [5/20/2008 9:32 AM 15328]
R0 tdrpman228;Acronis Try&Decide; and Restore Points filter (build 228);c:\windows\system32\drivers\tdrpm228.sys [10/4/2009 2:33 AM 902592]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [9/23/2009 8:44 AM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [9/23/2009 8:44 AM 59664]
R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [9/14/2008 3:44 PM 140800]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [9/14/2008 3:44 PM 5248]
R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [12/14/2006 8:40 AM 12964]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/4/2009 1:50 PM 9968]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\macrium reflect free\ReflectService.exe [8/6/2008 12:34 PM 216032]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/3/2004 5:56 PM 5120]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [12/20/2007 4:13 PM 1562096]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [9/23/2009 8:44 AM 33552]
S0 ati0jpxx;ati0jpxx;c:\windows\system32\Drivers\ati0jpxx.sys –> c:\windows\system32\Drivers\ati0jpxx.sys [?]
S0 ati0qwxx;ati0qwxx;c:\windows\system32\Drivers\ati0qwxx.sys –> c:\windows\system32\Drivers\ati0qwxx.sys [?]
S1 SASKUTIL;SASKUTIL;\??\c:\superantispyware\SASKUTIL.sys –> c:\superantispyware\SASKUTIL.sys [?]
S2 0060701201636616mcinstcleanup;0060701201636616mcinstcleanup; [x]
S2 0210201202775077mcinstcleanup;0210201202775077mcinstcleanup; [x]
S2 IcRecUsb;IC Recorder Driver;c:\windows\system32\drivers\IcRecUsb.sys [9/23/2009 7:20 AM 17432]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [7/8/2008 1:39 PM 31712]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/4/2009 1:50 PM 7408]

— Other Services/Drivers In Memory —

*NewlyCreated* - MBR
*Deregistered* - mbr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{21DB17A7-9EB9-0768-D9C5-22A71AD280F1}]
c:\windows\system32:svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{23559A9F-34FC-7AEC-0103-010100020305}]
c:\windows\system32\Update.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{286C63DF-E3B9-797E-0E4F-E10C0AD1C6D7}]
c:\documents and settings\Fazela\Application Data\svchost.exe s

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{FD009504-E099-E131-A5F2-B040C000E300}]
c:\windows\svchost.exe
.
Contents of the 'Scheduled Tasks' folder

2009-11-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 19:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.netscape.com/
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?e4b23bd0b5ec4cd1a429ca8bc7552c68
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?e4b23bd0b5ec4cd1a429ca8bc7552c68
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
FF - ProfilePath - c:\documents and settings\Fazela\Application Data\Mozilla\Firefox\Profiles\75umymae.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
HKU-Default-Run-services - c:\windows\services.exe
HKU-Default-Run-reader_s - c:\documents and settings\Fazela\reader_s.exe
Notify-xxbwzn - xxbwzn.dll
AddRemove-Magic ISO Maker v5.4 (build 0239) - c:\progra~1\MagicISO\UNWISE.EXE
AddRemove-PE Builder_is1 - c:\bart pe builder\pebuilder3110a\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-08 22:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86D3E950]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86d3e950
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(984)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'lsass.exe'(1040)
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'explorer.exe'(3628)
c:\program files\ThreatFire\TfWah.dll
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 8\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\nexon\MapleStory\npkcmsvc.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\ThreatFire\TFService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\msdtc.exe
.
**************************************************************************
.
Completion time: 2009-11-09 22:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-09 03:56
ComboFix2.txt 2009-03-10 00:22
ComboFix3.txt 2009-03-09 23:49
ComboFix4.txt 2008-11-02 15:32

Pre-Run: 359,109,771,264 bytes free
Post-Run: 359,080,292,352 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin

Current=4 Default=4 Failed=0 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
- - End Of File - - B10D5F1B0A01575C61B3507E08984E92
Wakenaam,

You have two AV's running. That's not good. Your McAfee is also your firewall so I suggest that you uninstall Bitdefender.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
TomK: Appreciate the help. Neither Bitdefender nor McAfee is active. I uninstalled them so many times yet they keep showing up. The only active AV scanners I have are AVAST and THREATFIRE. I see the VLC Media icons are still showing up as black solid rectangles. Here is the log from rooter:

Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully …
.
Windows XP . (5.1.2600) Service Pack 2
[32_bits] - x86 Family 15 Model 4 Stepping 1, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Enabled
.
Internet Explorer 6.0.2900.2180
.
A:\ [Removable]
C:\ [Fixed-NTFS] .. ( Total:465 Go - Free:334 Go )
D:\ [CD_Rom]
E:\ [CD_Rom]
F:\ [Removable]
.
Scan : 06:25.31
Path : C:\Documents and Settings\Fazela\Desktop\Rooter.exe
User : Fazela ( Administrator -> YES )
.
———————-\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (916)
______ \??\C:\WINDOWS\system32\csrss.exe (972)
______ \??\C:\WINDOWS\system32\winlogon.exe (996)
______ C:\WINDOWS\system32\services.exe (1040)
______ C:\WINDOWS\system32\lsass.exe (1052)
______ C:\WINDOWS\system32\svchost.exe (1232)
______ C:\WINDOWS\system32\svchost.exe (1300)
______ C:\WINDOWS\System32\svchost.exe (1444)
______ C:\WINDOWS\system32\svchost.exe (1572)
______ C:\WINDOWS\system32\svchost.exe (1676)
______ C:\WINDOWS\system32\spoolsv.exe (1916)
______ C:\WINDOWS\Explorer.EXE (324)
______ C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (444)
______ C:\Program Files\Common Files\Real\Update_OB\realsched.exe (452)
______ C:\Program Files\QuickTime\qttask.exe (468)
______ C:\Program Files\Windows Live\Messenger\msnmsgr.exe (520)
______ C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (880)
______ C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (352)
______ C:\Program Files\Hotspot Shield\bin\openvpnas.exe (1204)
______ C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (1344)
______ C:\Program Files\Java\jre6\bin\jqs.exe (1364)
______ C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (1392)
______ C:\Program Files\Norton Ghost\Agent\VProSvc.exe (1468)
______ C:\Documents and Settings\Fazela\Application Data\mjusbsp\magicJack.exe (1556)
______ C:\Nexon\MapleStory\npkcmsvc.exe (1600)
______ C:\Macrium Reflect Free\ReflectService.exe (1668)
______ C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe (1880)
______ C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe (2000)
______ C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (400)
______ C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (612)
______ C:\WINDOWS\system32\svchost.exe (544)
______ C:\WINDOWS\system32\dllhost.exe (684)
______ C:\Program Files\ThreatFire\TFService.exe (1420)
______ C:\WINDOWS\system32\dllhost.exe (2500)
______ C:\WINDOWS\System32\alg.exe (3012)
______ C:\WINDOWS\system32\wscntfy.exe (3108)
______ C:\WINDOWS\system32\msdtc.exe (3200)
______ C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe (4024)
______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (3776)
______ C:\Program Files\Windows Live\Toolbar\wltuser.exe (3788)
______ C:\Documents and Settings\Fazela\Desktop\Rooter.exe (1928)
.
———————-\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:32256 | Length:500104733184)
.
———————-\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
.
———————-\\ Registry
.
Rootkit! … [HKLM\SYSTEM\ControlSet005\Services\tdssserv]
.
———————-\\ Files & Folders
.
C:\DOCUME~1\Fazela\Application Data\uTorrent\TMPGEnc_Suite+crack+serial.rar.torrent
==> Cracks & Keygens <==
.
———————-\\ Scan completed at 06:25.37
.
C:\Rooter$\Rooter_1.txt - (09/11/2009 | 06:25.37).c
Wakenaam,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\windows\system32\Drivers\ati0jpxx.sys
    c:\windows\system32\Drivers\ati0qwxx.sys
    C:\DOCUME~1\Fazela\Application Data\uTorrent\TMPGEnc_Suite+crack+serial.rar.torrent
    
    Folder::
    C:\Program Files\Symantec\LiveUpdate
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0jpxx.sys]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0qwxx.sys]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{21DB17A7-9EB9-0768-D9C5-22A71AD280F1}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{23559A9F-34FC-7AEC-0103-010100020305}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{286C63DF-E3B9-797E-0E4F-E10C0AD1C6D7}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{FD009504-E099-E131-A5F2-B040C000E300}]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\tdssserv]
    
    Driver::
    Symantec SymSnap VSS Provider
    SymSnapService
    ati0jpxx
    ati0qwxx
    0060701201636616mcinstcleanup
    0210201202775077mcinstcleanup
    
    RegNull::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
    
    SecCenter::
    {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
    {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
TomK: Thanks for your persistence. The VLC media icons still show up as black rectangles after the new ComboFix scan. Here is the log:

ComboFix 09-11-08.03 - Fazela 11/09/2009 21:41.5.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.687 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Fazela\Desktop\cfscript.txt

FILE ::
"c:\docume~1\Fazela\Application Data\uTorrent\TMPGEnc_Suite+crack+serial.rar.torrent"
"c:\windows\system32\Drivers\ati0jpxx.sys"
"c:\windows\system32\Drivers\ati0qwxx.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Fazela\Application Data\uTorrent\TMPGEnc_Suite+crack+serial.rar.torrent
c:\program files\Symantec\LiveUpdate
c:\program files\Symantec\LiveUpdate\1.Settings.Hosts.LiveUpdate
c:\program files\Symantec\LiveUpdate\ALUNOTIFY.EXE
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Symantec\LiveUpdate\AUPDATE.EXE
c:\program files\Symantec\LiveUpdate\EULA.txt
c:\program files\Symantec\LiveUpdate\Lang\09\01\ALUNOTIFYRES.loc
c:\program files\Symantec\LiveUpdate\Lang\09\01\AluSchedulerSvcRes.loc
c:\program files\Symantec\LiveUpdate\Lang\09\01\AUPDATERES.loc
c:\program files\Symantec\LiveUpdate\Lang\09\01\EULA.txt
c:\program files\Symantec\LiveUpdate\Lang\09\01\LUALLRES.loc
c:\program files\Symantec\LiveUpdate\Lang\09\01\LuCfgRes.loc
c:\program files\Symantec\LiveUpdate\Lang\09\01\README.TXT
c:\program files\Symantec\LiveUpdate\Lang\09\01\ResLuComServer_3_4.loc
c:\program files\Symantec\LiveUpdate\Lang\09\01\S32LUCP1RES.loc
c:\program files\Symantec\LiveUpdate\Lang\09\01\SymantecRootInstallerRes.loc
c:\program files\Symantec\LiveUpdate\Lang\fallback.dat
c:\program files\Symantec\LiveUpdate\LSETUP.EXE
c:\program files\Symantec\LiveUpdate\LUALL.EXE
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuccMUI.dll
c:\program files\Symantec\LiveUpdate\LUCheck.exe
c:\program files\Symantec\LiveUpdate\LuComServer_3_4.EXE
c:\program files\Symantec\LiveUpdate\LuConfig.EXE
c:\program files\Symantec\LiveUpdate\ludirloc.dat
c:\program files\Symantec\LiveUpdate\LUINFO.INF
c:\program files\Symantec\LiveUpdate\LUinsDll.dll
c:\program files\Symantec\LiveUpdate\LuPreCon.DLL
c:\program files\Symantec\LiveUpdate\LuResult.txt
c:\program files\Symantec\LiveUpdate\NetDetectController_3_4.DLL
c:\program files\Symantec\LiveUpdate\NotifyHA.exe
c:\program files\Symantec\LiveUpdate\ProductRegCom_3_4.DLL
c:\program files\Symantec\LiveUpdate\PSProductRegCom_3_4.DLL
c:\program files\Symantec\LiveUpdate\README.TXT
c:\program files\Symantec\LiveUpdate\S32LIVE1.DLL
c:\program files\Symantec\LiveUpdate\S32LUCP1.CPL
c:\program files\Symantec\LiveUpdate\S32LUIS1.DLL
c:\program files\Symantec\LiveUpdate\S32LUWI1.DLL
c:\program files\Symantec\LiveUpdate\Settings.Default.LiveUpdate
c:\program files\Symantec\LiveUpdate\UNRAR.DLL

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_0060701201636616MCINSTCLEANUP
——-\Legacy_0210201202775077MCINSTCLEANUP
——-\Legacy_PROTECT
——-\Legacy_SYMANTEC_SYMSNAP_VSS_PROVIDER
——-\Legacy_SYMSNAPSERVICE
——-\Service_0060701201636616mcinstcleanup
——-\Service_0210201202775077mcinstcleanup
——-\Service_ati0jpxx
——-\Service_ati0qwxx
——-\Service_Symantec SymSnap VSS Provider
——-\Service_SymSnapService


((((((((((((((((((((((((( Files Created from 2009-10-10 to 2009-11-10 )))))))))))))))))))))))))))))))
.

2009-11-10 02:59 . 2009-08-01 16:16 6256600 —ha-w- c:\documents and settings\Fazela\Application Data\mjusbsp\in00000\setup.exe
2009-11-10 02:59 . 2009-08-01 16:12 728600 —ha-w- c:\documents and settings\Fazela\Application Data\mjusbsp\ar00000\install.exe
2009-11-10 02:59 . 2008-02-29 12:42 386496 —-a-w- c:\documents and settings\Fazela\Application Data\mjusbsp\ar00000\magicJackSplash.exe
2009-11-09 11:25 . 2009-11-09 11:25 ——– d—–w- C:\Rooter$
2009-11-08 19:06 . 2009-11-08 19:44 ——– d—–w- c:\program files\DVDFab 5
2009-11-08 18:58 . 2009-11-08 19:04 ——– d—–w- C:\DVDFab.Platinum.v5.2.5.0
2009-11-08 18:54 . 2009-11-08 18:56 ——– d—–w- C:\dvdfab
2009-11-08 17:53 . 2009-11-08 17:55 ——– d—–w- C:\Slysoft CloneDVD2 V2.9.1.9(KNIGHTY1973)
2009-11-04 23:15 . 2009-11-04 23:15 ——– d—–w- c:\windows\system32\wbem\Repository
2009-11-03 11:29 . 2009-11-03 11:50 ——– d—–w- C:\Kaaba
2009-10-23 16:42 . 2009-10-30 20:44 ——– d—–w- C:\All In The Family S06 Episodes 13 - 24 (of 24)
2009-10-23 16:39 . 2009-11-08 14:20 ——– d—–w- C:\All In The Family S06 Episodes 1 - 12 (of 24)
2009-10-22 13:46 . 2009-10-22 13:46 ——– d—–w- c:\documents and settings\Fazela\Application Data\Sony Corporation
2009-10-22 13:35 . 2009-10-22 13:35 ——– d—–w- c:\program files\Common Files\Sony Shared
2009-10-22 13:34 . 2009-10-22 13:43 ——– d—–w- c:\documents and settings\Fazela\Local Settings\Application Data\Downloaded Installations
2009-10-22 13:31 . 2009-10-22 13:31 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-10-21 22:29 . 2009-10-23 12:14 ——– d—–w- C:\All In The Family S05 Episodes 13 - 24 (of 24)
2009-10-21 22:27 . 2009-11-03 02:30 ——– d—–w- C:\All In The Family S05 Episodes 1 - 12 (of 24)
2009-10-21 06:27 . 2009-10-21 20:35 ——– d—–w- C:\All.In.The.Family.S3.E22-24
2009-10-20 10:51 . 2009-10-20 10:51 ——– d—–w- c:\documents and settings\Fazela\Application Data\CursorArts
2009-10-20 10:51 . 2009-10-20 15:33 ——– d—–w- c:\program files\ActivIcons
2009-10-20 10:48 . 2009-10-20 10:49 ——– d—–w- C:\ActivIcons
2009-10-18 03:52 . 2009-11-06 20:31 ——– d—–w- C:\All In The Family #2
2009-10-18 00:21 . 2009-10-23 17:13 ——– d—–w- C:\All In The Family S04 Episodes 17-24 (of 24)
2009-10-18 00:19 . 2009-10-22 11:58 ——– d—–w- C:\All In The Family S04 Episodes 9-16 (of 24)
2009-10-18 00:18 . 2009-10-19 09:36 ——– d—–w- C:\All In The Family S04 Episodes 1-8 (of 24)
2009-10-17 21:33 . 2009-11-05 23:06 ——– d—–w- C:\All.In.The.Family.S01.DVDrip.Ac3.XviD-Jana
2009-10-17 21:21 . 2009-10-23 16:39 ——– d—–w- C:\All in the family
2009-10-17 00:18 . 2009-11-09 21:09 ——– d—–w- c:\documents and settings\Fazela\Application Data\vlc
2009-10-13 19:33 . 2009-10-13 19:33 ——– d—–w- C:\My Music
2009-10-13 16:38 . 2004-08-04 02:31 32768 -c–a-w- c:\windows\system32\dllcache\sisnic.sys
2009-10-13 16:38 . 2004-08-04 02:31 32768 —-a-w- c:\windows\system32\drivers\sisnic.sys
2009-10-13 16:26 . 2006-05-17 15:03 44544 —-a-r- c:\windows\system32\drivers\bcm4sbxp.sys
2009-10-13 14:09 . 2006-05-10 19:00 156160 -c–a-w- c:\windows\system32\dllcache\b57xp32.sys
2009-10-13 14:09 . 2006-05-10 19:00 156160 —-a-w- c:\windows\system32\drivers\b57xp32.sys
2009-10-13 00:31 . 2009-10-13 13:59 ——– d—–w- C:\swtools
2009-10-12 19:12 . 2006-02-07 12:35 135168 —-a-w- c:\windows\system32\igfxres.dll
2009-10-12 18:27 . 2009-10-12 18:43 ——– d—–w- c:\windows\Downloaded Installations
2009-10-12 18:07 . 2009-10-13 14:09 ——– d—–w- c:\program files\Broadcom
2009-10-12 18:05 . 2005-03-28 14:19 220992 —-a-w- c:\windows\system32\drivers\smwdm.sys
2009-10-12 18:05 . 2009-10-12 18:05 ——– d—–w- c:\program files\Analog Devices
2009-10-12 18:05 . 2004-12-08 21:16 49152 —-a-w- c:\windows\system32\DSndUp.exe
2009-10-12 18:05 . 2002-04-17 19:05 45056 ——w- c:\windows\system32\CleanUp.exe
2009-10-12 17:47 . 2009-10-12 17:48 ——– d—–w- C:\Ibmtools
2009-10-12 15:42 . 2006-07-19 20:16 7680 -c–a-w- c:\windows\system32\dllcache\migregdb.exe
2009-10-12 15:41 . 2001-08-18 02:36 5632 -c–a-w- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-10-12 15:38 . 2001-08-23 12:00 16384 -c–a-w- c:\windows\system32\dllcache\isignup.exe
2009-10-12 15:24 . 2009-10-22 13:45 ——– d-sh–w- c:\windows\Installer
2009-10-12 15:24 . 2001-08-23 12:00 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2009-10-12 15:24 . 2001-08-23 12:00 13312 —-a-w- c:\windows\system32\irclass.dll
2009-10-12 15:24 . 2001-08-23 12:00 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-10-12 15:24 . 2001-08-23 12:00 24661 —-a-w- c:\windows\system32\spxcoins.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-10 02:59 . 2009-01-16 21:39 ——– d—–w- c:\documents and settings\Fazela\Application Data\mjusbsp
2009-11-10 02:55 . 2008-09-06 22:41 ——– d—–w- c:\program files\Symantec
2009-11-10 02:53 . 2007-07-24 17:11 ——– d—–w- c:\documents and settings\Fazela\Application Data\uTorrent
2009-11-10 01:35 . 2008-10-21 04:01 ——– d—–w- c:\documents and settings\Fazela\Application Data\Skype
2009-11-10 01:01 . 2008-10-21 04:13 ——– d—–w- c:\documents and settings\Fazela\Application Data\skypePM
2009-11-08 19:41 . 2009-02-28 15:42 ——– d—–w- c:\documents and settings\All Users\Application Data\vsosdk
2009-11-08 19:06 . 2009-02-27 23:47 ——– d—–w- c:\documents and settings\Fazela\Application Data\Vso
2009-11-08 19:06 . 2009-02-27 23:47 47360 -c–a-w- c:\documents and settings\Fazela\Application Data\pcouffin.sys
2009-11-08 19:06 . 2009-02-27 23:47 47360 -c–a-w- c:\documents and settings\Fazela\Application Data\pcouffin.sys
2009-11-08 19:06 . 2009-02-27 23:47 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-07 12:56 . 2007-10-11 20:44 ——– d—–w- c:\program files\Softwin
2009-11-07 12:56 . 2007-10-09 15:49 ——– d—–w- c:\program files\Common Files\Softwin
2009-10-25 23:14 . 2009-09-13 14:52 117760 —-a-w- c:\documents and settings\Fazela\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-25 12:57 . 2009-08-11 02:38 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-10-20 00:24 . 2008-10-21 02:51 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-10-13 01:17 . 2006-12-14 13:40 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-10-12 15:36 . 2006-12-14 00:26 24724 -c–a-w- c:\windows\system32\emptyregdb.dat
2009-10-12 15:36 . 2006-12-14 00:25 ——– d—–w- c:\program files\Windows Media Connect 2
2009-10-09 12:28 . 2009-10-05 16:28 2081048 —-a-w- c:\windows\system32\AutoPartNt.exe
2009-10-06 18:38 . 2009-09-13 14:51 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-10-05 18:30 . 2008-09-06 21:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-05 18:27 . 2008-10-21 05:11 ——– d—–w- c:\program files\Norton Ghost
2009-10-04 07:34 . 2008-10-22 18:51 ——– d—–w- c:\program files\Common Files\Acronis
2009-10-04 07:33 . 2009-10-04 07:33 902592 —-a-w- c:\windows\system32\drivers\tdrpm228.sys
2009-10-04 07:32 . 2008-10-22 18:52 540000 —-a-w- c:\windows\system32\drivers\timntr.sys
2009-10-04 07:32 . 2008-10-22 18:52 44704 —-a-w- c:\windows\system32\drivers\tifsfilt.sys
2009-10-04 07:32 . 2008-10-22 18:52 138208 -c–a-w- c:\windows\system32\drivers\snapman.sys
2009-09-30 12:28 . 2009-03-13 21:12 ——– d—–w- c:\program files\ThreatFire
2009-09-29 10:27 . 2007-01-03 21:06 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-23 14:07 . 2009-09-23 13:44 59664 —-a-w- c:\windows\system32\drivers\TfSysMon.sys
2009-09-23 14:07 . 2009-09-23 13:44 33552 —-a-w- c:\windows\system32\drivers\TfNetMon.sys
2009-09-23 14:07 . 2009-09-23 13:44 51984 —-a-w- c:\windows\system32\drivers\TfFsMon.sys
2009-09-23 12:22 . 2009-09-23 12:20 ——– d—–w- c:\program files\Panasonic
2009-09-22 10:38 . 2009-05-30 22:46 ——– d—–w- c:\documents and settings\Fazela\Application Data\dvdcss
2009-09-16 14:21 . 2006-12-17 14:22 33176 -c–a-w- c:\documents and settings\Fazela\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-16 14:14 . 2009-09-16 14:06 ——– d—–w- c:\program files\Windows Live
2009-09-16 14:14 . 2006-12-14 02:55 ——– d—–w- c:\program files\Windows Live Toolbar
2009-09-16 14:13 . 2009-09-16 14:13 ——– d—–w- c:\program files\Microsoft Sync Framework
2009-09-16 14:11 . 2009-09-16 14:11 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-16 14:08 . 2006-12-14 02:54 ——– d—–w- c:\program files\MSN Messenger
2009-09-16 14:07 . 2009-09-16 14:07 ——– d—–w- c:\program files\Microsoft
2009-09-16 14:07 . 2009-09-16 14:07 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-09-16 13:27 . 2009-09-16 13:27 ——– d—–w- c:\program files\Common Files\Windows Live
2009-09-14 11:00 . 2007-01-03 19:27 ——– d—–w- c:\program files\Common Files\Real
2009-09-14 10:59 . 2009-09-14 10:59 ——– d—–w- c:\program files\Common Files\xing shared
2009-09-14 03:34 . 2008-10-07 16:39 4045528 -c–a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-09-13 14:51 . 2009-08-11 02:38 ——– d—–w- c:\documents and settings\Fazela\Application Data\SUPERAntiSpyware.com
2009-09-10 19:54 . 2008-10-07 16:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2008-10-07 16:38 19160 -c–a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 14:36 . 2009-09-04 14:36 0 —-a-w- c:\windows\system32\cd.dat
2008-10-08 23:40 . 2008-10-08 23:38 50689960 -c–a-w- c:\program files\avg_free_stf_en_8_173a1373.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-11-09_03.49.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-09 11:15 . 2009-11-09 11:15 16384 c:\windows\temp\Perflib_Perfdata_fb8.dat
+ 2009-11-10 02:58 . 2009-11-10 02:58 16384 c:\windows\temp\Perflib_Perfdata_cc.dat
+ 2009-11-10 02:59 . 2009-11-10 02:59 16384 c:\windows\temp\Perflib_Perfdata_650.dat
+ 2009-11-09 11:14 . 2009-11-09 11:14 16384 c:\windows\temp\Perflib_Perfdata_5bc.dat
+ 2009-11-10 02:58 . 2009-11-10 02:58 16384 c:\windows\temp\Perflib_Perfdata_450.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-06-20 19:08 218160 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"cdloader"="c:\documents and settings\Fazela\Application Data\mjusbsp\cdloader2.exe" [2009-08-01 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-14 198160]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-03-11 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HideSCANetwork"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Enable Labtec Wireless Desktop.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Enable Labtec Wireless Desktop.lnk
backup=c:\windows\pss\Enable Labtec Wireless Desktop.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=
"c:\\Documents and Settings\\Fazela\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"57124:TCP"= 57124:TCP:Pando Media Booster
"57124:UDP"= 57124:UDP:Pando Media Booster
"57479:TCP"= 57479:TCP:Pando Media Booster
"57479:UDP"= 57479:UDP:Pando Media Booster

R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [5/20/2008 9:32 AM 15328]
R0 tdrpman228;Acronis Try&Decide; and Restore Points filter (build 228);c:\windows\system32\drivers\tdrpm228.sys [10/4/2009 2:33 AM 902592]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [9/23/2009 8:44 AM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [9/23/2009 8:44 AM 59664]
R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [9/14/2008 3:44 PM 140800]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [9/14/2008 3:44 PM 5248]
R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [12/14/2006 8:40 AM 12964]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/4/2009 1:50 PM 9968]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\macrium reflect free\ReflectService.exe [8/6/2008 12:34 PM 216032]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [9/23/2009 8:44 AM 33552]
S1 SASKUTIL;SASKUTIL;\??\c:\superantispyware\SASKUTIL.sys –> c:\superantispyware\SASKUTIL.sys [?]
S2 IcRecUsb;IC Recorder Driver;c:\windows\system32\drivers\IcRecUsb.sys [9/23/2009 7:20 AM 17432]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [7/8/2008 1:39 PM 31712]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/4/2009 1:50 PM 7408]

— Other Services/Drivers In Memory —

*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder

2009-11-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 19:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.netscape.com/
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?e4b23bd0b5ec4cd1a429ca8bc7552c68
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?e4b23bd0b5ec4cd1a429ca8bc7552c68
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
FF - ProfilePath - c:\documents and settings\Fazela\Application Data\Mozilla\Firefox\Profiles\75umymae.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-09 21:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86D21008]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86d21008
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1000)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'lsass.exe'(1056)
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'explorer.exe'(660)
c:\program files\ThreatFire\TfWah.dll
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 8\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\nexon\MapleStory\npkcmsvc.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\ThreatFire\TFService.exe
c:\windows\system32\wscntfy.exe
c:\documents and settings\Fazela\Application Data\mjusbsp\magicJack.exe
.
**************************************************************************
.
Completion time: 2009-11-10 22:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-10 03:06
ComboFix2.txt 2009-11-09 03:56
ComboFix3.txt 2009-03-10 00:22
ComboFix4.txt 2009-03-09 23:49
ComboFix5.txt 2009-11-10 02:38

Pre-Run: 358,985,662,464 bytes free
Post-Run: 358,970,286,080 bytes free

Current=4 Default=4 Failed=0 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
- - End Of File - - 0559EAD8273FB75F3EFEDE82C82998CE
Wakenaam,

Earlier on ComboFix installed the Recovery Console. We're going to use that now.

Reboot your machine and when the Boot Menu flashes up - select "Microsoft Windows Recovery Console"
(you need to be very fast with the arrow key as you only have a couple of seconds before it defaults to the windows XP bootup)

[external image: Posted Image]

[external image: Posted Image]

When you get to the above screen, take note of the number that references your operating system.
If it's '1' like the picture above, type 1 and press Enter

[external image: Posted Image]

Next type FIXMBR

[external image: Posted Image]

If it ask if you're sure you want to write a new MBR, answer 'Y'

Then type EXIT to reboot the machine.

Then please run ComboFix again and post the log.
TomK: Thanks again for your help. The icons are the same as before, no change. I will just have to live with it. I thought it was an easy fix. Again, thanks for your patience and perseverence with me. Anyways, here is the new log from ComboFix:

ComboFix 09-11-11.02 - Fazela 11/11/2009 17:47.6.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.598 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_PROTECT


((((((((((((((((((((((((( Files Created from 2009-10-11 to 2009-11-11 )))))))))))))))))))))))))))))))
.

2009-11-11 22:37 . 2009-08-01 16:16 6256600 —ha-w- c:\documents and settings\Fazela\Application Data\mjusbsp\in00000\setup.exe
2009-11-11 22:37 . 2009-08-01 16:12 728600 —ha-w- c:\documents and settings\Fazela\Application Data\mjusbsp\ar00000\install.exe
2009-11-11 22:37 . 2008-02-29 12:42 386496 —-a-w- c:\documents and settings\Fazela\Application Data\mjusbsp\ar00000\magicJackSplash.exe
2009-11-09 11:25 . 2009-11-09 11:25 ——– d—–w- C:\Rooter$
2009-11-08 19:06 . 2009-11-08 19:44 ——– d—–w- c:\program files\DVDFab 5
2009-11-08 18:58 . 2009-11-08 19:04 ——– d—–w- C:\DVDFab.Platinum.v5.2.5.0
2009-11-08 18:54 . 2009-11-08 18:56 ——– d—–w- C:\dvdfab
2009-11-08 17:53 . 2009-11-08 17:55 ——– d—–w- C:\Slysoft CloneDVD2 V2.9.1.9(KNIGHTY1973)
2009-11-04 23:15 . 2009-11-04 23:15 ——– d—–w- c:\windows\system32\wbem\Repository
2009-11-03 11:29 . 2009-11-03 11:50 ——– d—–w- C:\Kaaba
2009-10-23 16:42 . 2009-10-30 20:44 ——– d—–w- C:\All In The Family S06 Episodes 13 - 24 (of 24)
2009-10-23 16:39 . 2009-11-08 14:20 ——– d—–w- C:\All In The Family S06 Episodes 1 - 12 (of 24)
2009-10-22 13:46 . 2009-10-22 13:46 ——– d—–w- c:\documents and settings\Fazela\Application Data\Sony Corporation
2009-10-22 13:35 . 2009-10-22 13:35 ——– d—–w- c:\program files\Common Files\Sony Shared
2009-10-22 13:34 . 2009-10-22 13:43 ——– d—–w- c:\documents and settings\Fazela\Local Settings\Application Data\Downloaded Installations
2009-10-22 13:31 . 2009-10-22 13:31 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-10-21 22:29 . 2009-10-23 12:14 ——– d—–w- C:\All In The Family S05 Episodes 13 - 24 (of 24)
2009-10-21 22:27 . 2009-11-03 02:30 ——– d—–w- C:\All In The Family S05 Episodes 1 - 12 (of 24)
2009-10-21 06:27 . 2009-10-21 20:35 ——– d—–w- C:\All.In.The.Family.S3.E22-24
2009-10-20 10:51 . 2009-10-20 10:51 ——– d—–w- c:\documents and settings\Fazela\Application Data\CursorArts
2009-10-20 10:51 . 2009-10-20 15:33 ——– d—–w- c:\program files\ActivIcons
2009-10-20 10:48 . 2009-10-20 10:49 ——– d—–w- C:\ActivIcons
2009-10-18 03:52 . 2009-11-06 20:31 ——– d—–w- C:\All In The Family #2
2009-10-18 00:21 . 2009-10-23 17:13 ——– d—–w- C:\All In The Family S04 Episodes 17-24 (of 24)
2009-10-18 00:19 . 2009-10-22 11:58 ——– d—–w- C:\All In The Family S04 Episodes 9-16 (of 24)
2009-10-18 00:18 . 2009-10-19 09:36 ——– d—–w- C:\All In The Family S04 Episodes 1-8 (of 24)
2009-10-17 21:33 . 2009-11-05 23:06 ——– d—–w- C:\All.In.The.Family.S01.DVDrip.Ac3.XviD-Jana
2009-10-17 21:21 . 2009-10-23 16:39 ——– d—–w- C:\All in the family
2009-10-17 00:18 . 2009-11-11 21:36 ——– d—–w- c:\documents and settings\Fazela\Application Data\vlc
2009-10-13 19:33 . 2009-10-13 19:33 ——– d—–w- C:\My Music
2009-10-13 16:38 . 2004-08-04 02:31 32768 -c–a-w- c:\windows\system32\dllcache\sisnic.sys
2009-10-13 16:38 . 2004-08-04 02:31 32768 —-a-w- c:\windows\system32\drivers\sisnic.sys
2009-10-13 16:26 . 2006-05-17 15:03 44544 —-a-r- c:\windows\system32\drivers\bcm4sbxp.sys
2009-10-13 14:09 . 2006-05-10 19:00 156160 -c–a-w- c:\windows\system32\dllcache\b57xp32.sys
2009-10-13 14:09 . 2006-05-10 19:00 156160 —-a-w- c:\windows\system32\drivers\b57xp32.sys
2009-10-13 00:31 . 2009-10-13 13:59 ——– d—–w- C:\swtools

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-11 22:37 . 2009-01-16 21:39 ——– d—–w- c:\documents and settings\Fazela\Application Data\mjusbsp
2009-11-10 02:55 . 2008-09-06 22:41 ——– d—–w- c:\program files\Symantec
2009-11-10 02:53 . 2007-07-24 17:11 ——– d—–w- c:\documents and settings\Fazela\Application Data\uTorrent
2009-11-10 01:35 . 2008-10-21 04:01 ——– d—–w- c:\documents and settings\Fazela\Application Data\Skype
2009-11-10 01:01 . 2008-10-21 04:13 ——– d—–w- c:\documents and settings\Fazela\Application Data\skypePM
2009-11-08 19:41 . 2009-02-28 15:42 ——– d—–w- c:\documents and settings\All Users\Application Data\vsosdk
2009-11-08 19:06 . 2009-02-27 23:47 ——– d—–w- c:\documents and settings\Fazela\Application Data\Vso
2009-11-08 19:06 . 2009-02-27 23:47 47360 -c–a-w- c:\documents and settings\Fazela\Application Data\pcouffin.sys
2009-11-08 19:06 . 2009-02-27 23:47 47360 -c–a-w- c:\documents and settings\Fazela\Application Data\pcouffin.sys
2009-11-08 19:06 . 2009-02-27 23:47 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-07 12:56 . 2007-10-11 20:44 ——– d—–w- c:\program files\Softwin
2009-11-07 12:56 . 2007-10-09 15:49 ——– d—–w- c:\program files\Common Files\Softwin
2009-10-25 23:14 . 2009-09-13 14:52 117760 —-a-w- c:\documents and settings\Fazela\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-25 12:57 . 2009-08-11 02:38 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-10-20 00:24 . 2008-10-21 02:51 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-10-13 14:09 . 2009-10-12 18:07 ——– d—–w- c:\program files\Broadcom
2009-10-13 01:17 . 2006-12-14 13:40 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-10-12 18:05 . 2009-10-12 18:05 ——– d—–w- c:\program files\Analog Devices
2009-10-12 15:36 . 2006-12-14 00:26 24724 -c–a-w- c:\windows\system32\emptyregdb.dat
2009-10-12 15:36 . 2006-12-14 00:25 ——– d—–w- c:\program files\Windows Media Connect 2
2009-10-09 12:28 . 2009-10-05 16:28 2081048 —-a-w- c:\windows\system32\AutoPartNt.exe
2009-10-06 18:38 . 2009-09-13 14:51 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-10-05 18:30 . 2008-09-06 21:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-05 18:27 . 2008-10-21 05:11 ——– d—–w- c:\program files\Norton Ghost
2009-10-04 07:34 . 2008-10-22 18:51 ——– d—–w- c:\program files\Common Files\Acronis
2009-10-04 07:33 . 2009-10-04 07:33 902592 —-a-w- c:\windows\system32\drivers\tdrpm228.sys
2009-10-04 07:32 . 2008-10-22 18:52 540000 —-a-w- c:\windows\system32\drivers\timntr.sys
2009-10-04 07:32 . 2008-10-22 18:52 44704 —-a-w- c:\windows\system32\drivers\tifsfilt.sys
2009-10-04 07:32 . 2008-10-22 18:52 138208 -c–a-w- c:\windows\system32\drivers\snapman.sys
2009-09-30 12:28 . 2009-03-13 21:12 ——– d—–w- c:\program files\ThreatFire
2009-09-29 10:27 . 2007-01-03 21:06 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-23 14:07 . 2009-09-23 13:44 59664 —-a-w- c:\windows\system32\drivers\TfSysMon.sys
2009-09-23 14:07 . 2009-09-23 13:44 33552 —-a-w- c:\windows\system32\drivers\TfNetMon.sys
2009-09-23 14:07 . 2009-09-23 13:44 51984 —-a-w- c:\windows\system32\drivers\TfFsMon.sys
2009-09-23 12:22 . 2009-09-23 12:20 ——– d—–w- c:\program files\Panasonic
2009-09-22 10:38 . 2009-05-30 22:46 ——– d—–w- c:\documents and settings\Fazela\Application Data\dvdcss
2009-09-16 14:21 . 2006-12-17 14:22 33176 -c–a-w- c:\documents and settings\Fazela\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-16 14:14 . 2009-09-16 14:06 ——– d—–w- c:\program files\Windows Live
2009-09-16 14:14 . 2006-12-14 02:55 ——– d—–w- c:\program files\Windows Live Toolbar
2009-09-16 14:13 . 2009-09-16 14:13 ——– d—–w- c:\program files\Microsoft Sync Framework
2009-09-16 14:11 . 2009-09-16 14:11 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-16 14:08 . 2006-12-14 02:54 ——– d—–w- c:\program files\MSN Messenger
2009-09-16 14:07 . 2009-09-16 14:07 ——– d—–w- c:\program files\Microsoft
2009-09-16 14:07 . 2009-09-16 14:07 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-09-16 13:27 . 2009-09-16 13:27 ——– d—–w- c:\program files\Common Files\Windows Live
2009-09-14 11:00 . 2007-01-03 19:27 ——– d—–w- c:\program files\Common Files\Real
2009-09-14 10:59 . 2009-09-14 10:59 ——– d—–w- c:\program files\Common Files\xing shared
2009-09-14 03:34 . 2008-10-07 16:39 4045528 -c–a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-09-13 14:51 . 2009-08-11 02:38 ——– d—–w- c:\documents and settings\Fazela\Application Data\SUPERAntiSpyware.com
2009-09-10 19:54 . 2008-10-07 16:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2008-10-07 16:38 19160 -c–a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 14:36 . 2009-09-04 14:36 0 —-a-w- c:\windows\system32\cd.dat
2008-10-08 23:40 . 2008-10-08 23:38 50689960 -c–a-w- c:\program files\avg_free_stf_en_8_173a1373.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-11-09_03.49.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-11 23:01 . 2009-11-11 23:01 16384 c:\windows\temp\Perflib_Perfdata_ce0.dat
+ 2009-11-11 23:01 . 2009-11-11 23:01 16384 c:\windows\temp\Perflib_Perfdata_5dc.dat
+ 2009-11-11 23:01 . 2009-11-11 23:01 16384 c:\windows\temp\Perflib_Perfdata_204.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-06-20 19:08 218160 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"cdloader"="c:\documents and settings\Fazela\Application Data\mjusbsp\cdloader2.exe" [2009-08-01 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-14 198160]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-03-11 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HideSCANetwork"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Enable Labtec Wireless Desktop.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Enable Labtec Wireless Desktop.lnk
backup=c:\windows\pss\Enable Labtec Wireless Desktop.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Fazela\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"57124:TCP"= 57124:TCP:Pando Media Booster
"57124:UDP"= 57124:UDP:Pando Media Booster
"57479:TCP"= 57479:TCP:Pando Media Booster
"57479:UDP"= 57479:UDP:Pando Media Booster

R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [5/20/2008 9:32 AM 15328]
R0 tdrpman228;Acronis Try&Decide; and Restore Points filter (build 228);c:\windows\system32\drivers\tdrpm228.sys [10/4/2009 2:33 AM 902592]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [9/23/2009 8:44 AM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [9/23/2009 8:44 AM 59664]
R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [9/14/2008 3:44 PM 140800]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [9/14/2008 3:44 PM 5248]
R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [12/14/2006 8:40 AM 12964]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/4/2009 1:50 PM 9968]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\macrium reflect free\ReflectService.exe [8/6/2008 12:34 PM 216032]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [9/23/2009 8:44 AM 33552]
S1 SASKUTIL;SASKUTIL;\??\c:\superantispyware\SASKUTIL.sys –> c:\superantispyware\SASKUTIL.sys [?]
S2 IcRecUsb;IC Recorder Driver;c:\windows\system32\drivers\IcRecUsb.sys [9/23/2009 7:20 AM 17432]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [7/8/2008 1:39 PM 31712]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/4/2009 1:50 PM 7408]

— Other Services/Drivers In Memory —

*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder

2009-11-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 19:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.netscape.com/
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?e4b23bd0b5ec4cd1a429ca8bc7552c68
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?e4b23bd0b5ec4cd1a429ca8bc7552c68
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
FF - ProfilePath - c:\documents and settings\Fazela\Application Data\Mozilla\Firefox\Profiles\75umymae.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-11 18:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86DC70B8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86dc70b8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(980)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'lsass.exe'(1036)
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'explorer.exe'(3496)
c:\program files\ThreatFire\TfWah.dll
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 8\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\nexon\MapleStory\npkcmsvc.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\ThreatFire\TFService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-11-11 18:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-11 23:07
ComboFix2.txt 2009-11-10 03:06
ComboFix3.txt 2009-11-09 03:56
ComboFix4.txt 2009-03-10 00:22
ComboFix5.txt 2009-11-11 22:45

Pre-Run: 357,698,904,064 bytes free
Post-Run: 357,737,607,168 bytes free

Current=4 Default=4 Failed=0 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
- - End Of File - - 62544175B6617903260E0376A52AF7E3
Cheers and have a nice day.
Wakenaam,

There is still something going on at the root of your system. :wacko:

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.

Note: Do not run any programs while Gmer is running.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI