This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE7 not working properly

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hey i notice one of those fake anti virus things on my computer telling me i was infected. right away i ran malwarebytes and tried to remove it. i was not able to update malwarebytes kept getting an error: An error occurred. Please report the following error code to the Malwarebyte's Anti-Malware support team. Error code: 732 (0,0) i was able to run it with the Sept updates and it found 4 files infected. i removed and restarted computer. when computer came back up i notice that IE does not work right and show like if my internet is off line. Mozilla Firefox works just fine. when i try to type an address in the address box i will get something like invalid address or page cannot be found but others will pull up just fine. with Firefox everything seems to work fine. the only problem is some web pages that i have to go to for work only work in IE so i need this resolve soon. i was finally able to update Malwarebytes and it found two more infected files. after those two infected files i tried IE7 and everything was working fine. after a reboot of my computer now IE7 is doing the same thing as before. it will not even pull up www.msn.com. i ran through the steps that say here i was able to get the log file for DDS and i used ATF as the cleaner. i was not able to run RootRepeal from any other the three links provided. i am able to install it but when i try running it the application will not open. i open task manager and it says Not Responding and i check and the CPU process is at 99. here are the two log files that i was able to get. DDS.txt DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 19:57:51.04 on Wed 12/02/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1252 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== I:\WINDOWS\system32\Ati2evxx.exe I:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe I:\WINDOWS\System32\svchost.exe -k netsvcs I:\WINDOWS\system32\svchost.exe -k WudfServiceGroup I:\Program Files\AVG\AVG9\avgchsvx.exe I:\Program Files\AVG\AVG9\avgrsx.exe I:\Program Files\AVG\AVG9\avgcsrvx.exe svchost.exe svchost.exe I:\WINDOWS\system32\spoolsv.exe I:\WINDOWS\system32\Ati2evxx.exe I:\WINDOWS\Explorer.EXE svchost.exe I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe I:\Program Files\AVG\AVG9\avgwdsvc.exe I:\Program Files\Bonjour\mDNSResponder.exe I:\Program Files\Juniper Networks\Common Files\dsNcService.exe I:\Program Files\Java\jre6\bin\jqs.exe I:\Program Files\AVG\AVG9\avgnsx.exe I:\Program Files\LogMeIn\x86\RaMaint.exe I:\Program Files\LogMeIn\x86\LogMeIn.exe I:\Program Files\LogMeIn\x86\LMIGuardian.exe I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE I:\Program Files\mobile PhoneTools\WatchDog.exe i:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe I:\Program Files\ATI Technologies\ATI.ACE\cli.exe I:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe I:\Program Files\ScanSoft\PaperPort\pptd40nt.exe I:\WINDOWS\System32\svchost.exe -k imgsvc I:\Program Files\Viewpoint\Common\ViewpointService.exe I:\WINDOWS\System32\MsPMSPSv.exe I:\Program Files\LogMeIn\x86\LogMeInSystray.exe I:\WINDOWS\system32\SearchIndexer.exe I:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe I:\Program Files\iTunes\iTunesHelper.exe I:\PROGRA~1\AVG\AVG9\avgtray.exe I:\Program Files\LogMeIn\x86\LMIGuardian.exe I:\WINDOWS\system32\svchost.exe -k netsvcs I:\WINDOWS\system32\ctfmon.exe I:\PROGRA~1\MI3AA1~1\wcescomm.exe I:\PROGRA~1\MI3AA1~1\rapimgr.exe I:\Program Files\Brother\Brmfcmon\BrMfimon.exe I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe I:\Program Files\Windows Media Player\WMPNSCFG.exe I:\WINDOWS\System32\svchost.exe -k HTTPFilter I:\Program Files\iPod\bin\iPodService.exe I:\Program Files\ATI Technologies\ATI.ACE\cli.exe I:\Program Files\ATI Technologies\ATI.ACE\cli.exe I:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE I:\Program Files\AVG\AVG9\avgcsrvx.exe I:\Program Files\Mozilla Firefox\firefox.exe I:\Program Files\AVG\AVG9\avgui.exe I:\WINDOWS\system32\wscntfy.exe I:\WINDOWS\system32\SearchProtocolHost.exe I:\Documents and Settings\Larry\Desktop\dds(2).scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyServer = http=127.0.0.1:5555 uInternet Settings,ProxyOverride = uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - i:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - i:\program files\avg\avg9\avgssie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - i:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - i:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - i:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - i:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - i:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - i:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [ctfmon.exe] i:\windows\system32\ctfmon.exe uRun: [H/PC Connection Agent] "i:\progra~1\mi3aa1~1\wcescomm.exe" uRun: [NBJ] "i:\program files\ahead\nero backitup\NBJ.exe" uRun: [swg] "i:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Aim6] uRun: [WMPNSCFG] i:\program files\windows media player\WMPNSCFG.exe mRun: [NvCplDaemon] RUNDLL32.EXE i:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [RoxioEngineUtility] "i:\program files\common files\roxio shared\system\EngUtil.exe" mRun: [WatchDog] i:\program files\mobile phonetools\WatchDog.exe mRun: [NeroFilterCheck] i:\program files\common files\ahead\lib\NeroCheck.exe mRun: [NvMediaCenter] RUNDLL32.EXE i:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [ATICCC] "i:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [CloneCDTray] "i:\program files\slysoft\clonecd\CloneCDTray.exe" /s mRun: [GrooveMonitor] "i:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [SSBkgdUpdate] "i:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] "i:\program files\scansoft\paperport\pptd40nt.exe" mRun: [IndexSearch] "i:\program files\scansoft\paperport\IndexSearch.exe" mRun: [PPort11reminder] "i:\program files\scansoft\paperport\ereg\ereg.exe" -r "i:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini mRun: [BrMfcWnd] i:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN mRun: [ControlCenter3] i:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [LogMeIn GUI] "i:\program files\logmein\x86\LogMeInSystray.exe" mRun: [iTunesHelper] "i:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "i:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [AVG9_TRAY] i:\progra~1\avg\avg9\avgtray.exe mRun: [QuickTime Task] "i:\program files\quicktime\QTTask.exe" -atboottime dRun: [DWQueuedReporting] "i:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: i:\docume~1\larry\startm~1\programs\startup\adobeg~1.lnk - i:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: i:\docume~1\larry\startm~1\programs\startup\erunta~1.lnk - i:\program files\erunt\AUTOBACK.EXE StartupFolder: i:\docume~1\larry\startm~1\programs\startup\onenot~1.lnk - i:\program files\microsoft office\office12\ONENOTEM.EXE IE: Google Sidewiki… - i:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - i:\program files\aim\aim.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - i:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - i:\progra~1\micros~2\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - i:\progra~1\mi3aa1~1\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - i:\progra~1\mi3aa1~1\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - i:\progra~1\micros~2\office12\REFIEBAR.DLL Trusted Zone: arise.com Trusted Zone: intuit.com Trusted Zone: turbotax.com Trusted Zone: willowcsn.com\cybercentral DPF: Microsoft XML Parser for Java - file:///I:/WINDOWS/Java/classes/xmldso.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://asp23.centra.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab DPF: {32564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv8dmo.cab DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182530425484 DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {95D88B35-A521-472B-A182-BB1A98356421} - hxxp://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38066.5709953704 DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_04-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://ns.arise.com/dana-cached/setup/JuniperSetupSP1.cab DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} - hxxp://asp.mathxl.com/books/_Players/MathPlayer.cab DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - i:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - i:\program files\avg\avg9\avgpp.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll Notify: LMIinit - LMIinit.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - i:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - i:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - i:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - i:\docume~1\larry\applic~1\mozilla\firefox\profiles\uz0fyw53.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxps://admintools.ariasystems.net/dashboard-idp/auth/login-aria.php?RelayState=https%3A%2F%2Fadmintools.ariasystems.net%3A443%2Fdashboard-idp%2Fsaml2%2Fidp%2FSSOService.php%3FRequestID%3D_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&spentityid=admintools.ariasystems.net&AuthId=_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&protocol=saml2&timeout=0 FF - component: i:\program files\avg\avg9\firefox\components\avgssff.dll FF - plugin: i:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: i:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: i:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: i:\program files\mozilla firefox\plugins\npican.dll FF - plugin: i:\program files\mozilla firefox\plugins\npunagi2.dll FF - plugin: i:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: i:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - i:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - i:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;i:\windows\system32\drivers\avgldx86.sys [2009-4-8 333192] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;i:\windows\system32\drivers\avgmfx86.sys [2009-4-8 28424] R1 AvgTdiX;AVG Free8 Network Redirector;i:\windows\system32\drivers\avgtdix.sys [2009-4-8 360584] R1 NEOFLTR_550_12129;Juniper Networks TDI Filter Driver (NEOFLTR_550_12129);i:\windows\system32\drivers\NEOFLTR_550_12129.sys [2007-10-3 63008] R2 avg9wd;AVG Free WatchDog;i:\program files\avg\avg9\avgwdsvc.exe [2009-11-9 285392] R2 LMIInfo;LogMeIn Kernel Information Provider;i:\program files\logmein\x86\rainfo.sys [2008-7-24 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;i:\windows\system32\drivers\LMIRfsDriver.sys [2009-2-12 47640] R2 Viewpoint Manager Service;Viewpoint Manager Service;i:\program files\viewpoint\common\ViewpointService.exe [2009-7-3 24652] R3 portio32;portio32;i:\windows\system32\drivers\portio32.sys [2009-9-7 2048] S2 gupdate1c9d3431ddff9c6;Google Update Service (gupdate1c9d3431ddff9c6);i:\program files\google\update\GoogleUpdate.exe [2009-5-12 133104] S3 NPF;Netgroup Packet Filter;i:\windows\system32\drivers\npf.sys –> i:\windows\system32\drivers\npf.sys [?] S4 LMIRfsClientNP;LMIRfsClientNP; [x] =============== Created Last 30 ================ 2009-12-02 19:54 -cd—– i:\windows\BACKUPERDNT 2009-12-02 10:28 -cd—– i:\program files\common files\AnswerWorks 4.0 2009-12-02 09:43 -cd—– i:\program files\Arise 2009-12-02 09:24 38,224 ac—— i:\windows\system32\drivers\mbamswissarmy.sys 2009-12-02 09:24 19,160 ac—— i:\windows\system32\drivers\mbam.sys 2009-12-02 09:24 -cd—– i:\program files\Malwarebytes' Anti-Malware 2009-11-21 11:15 411,368 ac—— i:\windows\system32\deploytk.dll 2009-11-21 11:15 73,728 ac—— i:\windows\system32\javacpl.cpl 2009-11-10 23:08 94,208 ac—— i:\windows\system32\QuickTimeVR.qtx 2009-11-10 23:08 69,632 ac—— i:\windows\system32\QuickTime.qts 2009-11-09 10:22 -cd-h— I:\$AVG 2009-11-09 10:21 -cd—– i:\docume~1\alluse~1\applic~1\avg9 2009-11-07 11:30 -cd—– i:\documents and settings\larry\taw 2009-11-05 16:03 -cd—– i:\program files\iPod 2009-11-05 16:03 -cd—– i:\program files\iTunes 2009-11-02 23:17 244 ac–h— I:\sqmnoopt07.sqm 2009-11-02 23:17 232 ac–h— I:\sqmdata07.sqm ==================== Find3M ==================== 2009-11-10 09:12 360,584 ac—— i:\windows\system32\drivers\avgtdix.sys 2009-11-09 10:22 333,192 ac—— i:\windows\system32\drivers\avgldx86.sys 2009-11-09 10:22 12,464 ac—— i:\windows\system32\avgrsstx.dll 2009-10-27 02:27 96,256 a——- i:\windows\system32\drivers\sptd4045.sys 2009-10-01 10:36 83,288 a——- i:\windows\system32\LMIRfsClientNP.dll 2009-10-01 10:36 28,984 ac—— i:\windows\system32\LMIport.dll 2009-10-01 10:36 87,352 a——- i:\windows\system32\LMIinit.dll 2009-09-30 13:56 73,880 ac–h— i:\windows\system32\mlfcache.dat 2009-09-11 09:33 133,632 a——- i:\windows\system32\msv1_0.dll 2009-09-08 10:35 25,248 ac—— i:\windows\system32\lmimirr.dll 2009-09-08 10:35 11,552 ac—— i:\windows\system32\lmimirr2.dll 2009-09-04 15:45 58,880 a——- i:\windows\system32\msasn1.dll 2005-07-14 13:31 27,648 ac-sh— i:\windows\system32\AVSredirect.dll ============= FINISH: 19:57:59.70 =============== Attach.txt has been attached.

Attachments:

Hi larryri42, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Open your Internet Explorer:
  • At the top click Tools, click Internet Options
  • On the Connections Tab click Lan Settings
  • Uncheck use a proxy server

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Is IE working?

Please post back with the combofix log.

Thanks
Here is my combofix log. i was able to get IE7 working. for some reason the proxy settings were checked. i removed the check applied closed and opened IE7 and it worked. i also attached the log file just in case.

Thanks.


ComboFix 09-12-07.01 - Larry 12/07/2009 16:42.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1476 [GMT -5:00]
Running from: i:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

i:\program files\ATI Technologies\ATI.ACE\atIAcmxx.dll
i:\windows\system32\14_43260.dll
i:\windows\system32\28_83260.dll
i:\windows\system32\Cache
i:\windows\system32\Ijl11.dll
i:\windows\system32\images
i:\windows\system32\images\toolbar\calendar.gif
i:\windows\system32\images\toolbar\crlogo.gif
i:\windows\system32\images\toolbar\export.gif
i:\windows\system32\images\toolbar\export_over.gif
i:\windows\system32\images\toolbar\exportd.gif
i:\windows\system32\images\toolbar\First.gif
i:\windows\system32\images\toolbar\first_over.gif
i:\windows\system32\images\toolbar\Firstd.gif
i:\windows\system32\images\toolbar\gotopage.gif
i:\windows\system32\images\toolbar\gotopage_over.gif
i:\windows\system32\images\toolbar\gotopaged.gif
i:\windows\system32\images\toolbar\grouptree.gif
i:\windows\system32\images\toolbar\grouptree_over.gif
i:\windows\system32\images\toolbar\grouptreed.gif
i:\windows\system32\images\toolbar\grouptreepressed.gif
i:\windows\system32\images\toolbar\Last.gif
i:\windows\system32\images\toolbar\last_over.gif
i:\windows\system32\images\toolbar\Lastd.gif
i:\windows\system32\images\toolbar\Next.gif
i:\windows\system32\images\toolbar\next_over.gif
i:\windows\system32\images\toolbar\Nextd.gif
i:\windows\system32\images\toolbar\Prev.gif
i:\windows\system32\images\toolbar\prev_over.gif
i:\windows\system32\images\toolbar\Prevd.gif
i:\windows\system32\images\toolbar\print.gif
i:\windows\system32\images\toolbar\print_over.gif
i:\windows\system32\images\toolbar\printd.gif
i:\windows\system32\images\toolbar\Refresh.gif
i:\windows\system32\images\toolbar\refresh_over.gif
i:\windows\system32\images\toolbar\refreshd.gif
i:\windows\system32\images\toolbar\Search.gif
i:\windows\system32\images\toolbar\search_over.gif
i:\windows\system32\images\toolbar\searchd.gif
i:\windows\system32\images\toolbar\up.gif
i:\windows\system32\images\toolbar\up_over.gif
i:\windows\system32\images\toolbar\upd.gif
i:\windows\system32\images\tree\begindots.gif
i:\windows\system32\images\tree\beginminus.gif
i:\windows\system32\images\tree\beginplus.gif
i:\windows\system32\images\tree\blank.gif
i:\windows\system32\images\tree\blankdots.gif
i:\windows\system32\images\tree\dots.gif
i:\windows\system32\images\tree\lastdots.gif
i:\windows\system32\images\tree\lastminus.gif
i:\windows\system32\images\tree\lastplus.gif
i:\windows\system32\images\tree\Magnify.gif
i:\windows\system32\images\tree\minus.gif
i:\windows\system32\images\tree\minusbox.gif
i:\windows\system32\images\tree\plus.gif
i:\windows\system32\images\tree\plusbox.gif
i:\windows\system32\images\tree\singleminus.gif
i:\windows\system32\images\tree\singleplus.gif
i:\windows\twain_16.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-11-07 to 2009-12-07 )))))))))))))))))))))))))))))))
.

2009-12-07 21:28 . 2009-12-07 21:28 194464 -c–a-w- i:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-04 13:46 . 2009-12-04 13:46 ——– dc—-w- i:\documents and settings\LocalService\Local Settings\Application Data\IsolatedStorage
2009-12-04 13:41 . 2009-12-04 13:41 ——– dc—-w- i:\documents and settings\Larry\Local Settings\Application Data\IsolatedStorage
2009-12-03 23:38 . 2009-12-03 23:38 81920 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connecthook.dll
2009-12-03 23:38 . 2009-12-03 23:38 158720 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectsprd.dll
2009-12-03 23:38 . 2009-12-03 23:38 3553680 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectaddin6x5.exe
2009-12-03 13:44 . 2008-08-19 14:46 1848608 -c–a-w- i:\windows\system32\acXMLParser.dll
2009-12-03 13:44 . 2008-08-19 14:46 3523872 -c–a-w- i:\windows\system32\cdintf300.dll
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\HaB\Custom\billmind.exe
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\RPM\Custom\billmind.exe
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\Premier\Custom\billmind.exe
2009-12-03 13:44 . 2009-12-03 13:44 ——– dc—-w- i:\program files\Quicken
2009-12-03 01:04 . 2009-12-03 01:44 34816 -c–a-w- i:\windows\system32\drivers\rootrepeal2.sys
2009-12-03 00:54 . 2009-12-03 00:54 ——– dc—-w- i:\windows\BACKUPERDNT
2009-12-03 00:53 . 2009-12-03 00:53 ——– dc—-w- i:\program files\ERUNT
2009-12-02 15:28 . 2009-12-02 15:28 ——– dc—-w- i:\program files\Common Files\AnswerWorks 4.0
2009-12-02 14:43 . 2009-12-02 14:43 ——– dc—-w- i:\program files\Arise
2009-12-02 14:24 . 2009-09-10 19:54 38224 -c–a-w- i:\windows\system32\drivers\mbamswissarmy.sys
2009-12-02 14:24 . 2009-09-10 19:53 19160 -c–a-w- i:\windows\system32\drivers\mbam.sys
2009-12-02 14:24 . 2009-12-02 14:24 ——– dc—-w- i:\program files\Malwarebytes' Anti-Malware
2009-12-01 02:39 . 2009-12-01 03:17 ——– dc—-w- i:\documents and settings\Larry\Local Settings\Application Data\smsgij
2009-11-24 13:37 . 2009-12-07 18:23 86016 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\meetingconvertor.dll
2009-11-24 13:37 . 2009-12-07 18:23 81920 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connecthook.dll
2009-11-24 13:37 . 2009-12-07 17:58 303104 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectsprd.dll
2009-11-24 05:08 . 2009-11-24 05:08 ——– dc—-w- i:\program files\QuickTime
2009-11-23 20:15 . 2009-11-23 20:15 4736992 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe
2009-11-21 16:15 . 2009-11-21 16:14 411368 -c–a-w- i:\windows\system32\deploytk.dll
2009-11-21 16:14 . 2009-11-21 16:14 152576 -c–a-w- i:\documents and settings\Larry\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-20 14:28 . 2009-11-09 15:21 877848 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2009-11-12 14:24 . 2009-11-10 14:12 4026136 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-11-12 14:23 . 2009-11-10 14:12 2016536 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-11-12 14:23 . 2009-11-10 14:12 1257240 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2009-11-12 14:23 . 2009-11-12 14:22 3963648 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-12 14:23 . 2009-11-12 14:22 497944 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2009-11-12 14:23 . 2009-11-09 15:21 600344 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgnsx.exe
2009-11-10 14:12 . 2009-11-09 15:21 360584 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2009-11-10 14:11 . 2009-11-10 14:11 1657112 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2009-11-10 14:11 . 2009-11-09 15:21 610072 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2009-11-09 15:22 . 2009-11-09 15:26 ——– dc—-w- I:\$AVG
2009-11-09 15:21 . 2009-11-09 15:21 ——– dc—-w- i:\documents and settings\All Users\Application Data\avg9

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-07 19:25 . 2009-05-12 20:46 ——– dc—-w- i:\documents and settings\All Users\Application Data\Google Updater
2009-12-07 13:34 . 2009-02-13 03:50 ——– dc—-w- i:\program files\LogMeIn
2009-12-06 01:30 . 2006-06-04 00:28 ——– dc—-w- i:\documents and settings\Larry\Application Data\uTorrent
2009-12-04 13:41 . 2008-03-02 16:35 ——– dc—-w- i:\program files\TurboTax
2009-12-04 13:36 . 2007-01-28 21:43 ——– dc—-w- i:\program files\Common Files\Intuit
2009-12-03 13:45 . 2009-03-09 23:33 ——– dc—-w- i:\program files\Common Files\AnswerWorks 5.0
2009-12-03 13:45 . 2004-03-22 01:19 ——– dc-h–w- i:\program files\InstallShield Installation Information
2009-12-03 13:44 . 2007-01-28 21:45 ——– dc—-w- i:\documents and settings\Larry\Application Data\Intuit
2009-12-03 13:43 . 2007-01-28 21:44 ——– dc—-w- i:\documents and settings\All Users\Application Data\Intuit
2009-12-02 13:53 . 2007-06-22 16:06 ——– dc—-w- i:\documents and settings\Larry\Application Data\Juniper Networks
2009-12-02 13:43 . 2006-07-28 22:21 ——– dc—-w- i:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-02 04:36 . 2007-06-22 16:25 38881 -c–a-w- i:\documents and settings\Larry\Application Data\Juniper Networks\Host Checker\uninstall.exe
2009-11-24 14:33 . 2007-06-22 16:06 ——– dc—-w- i:\program files\Juniper Networks
2009-11-21 16:14 . 2004-06-04 02:13 ——– dc—-w- i:\program files\Java
2009-11-10 14:12 . 2009-04-08 23:20 360584 -c–a-w- i:\windows\system32\drivers\avgtdix.sys
2009-11-09 15:22 . 2009-04-08 23:20 12464 -c–a-w- i:\windows\system32\avgrsstx.dll
2009-11-09 15:22 . 2009-04-08 23:20 333192 -c–a-w- i:\windows\system32\drivers\avgldx86.sys
2009-11-09 15:22 . 2009-04-08 23:20 28424 -c–a-w- i:\windows\system32\drivers\avgmfx86.sys
2009-11-09 15:21 . 2009-04-08 23:20 ——– dc—-w- i:\program files\AVG
2009-11-05 21:04 . 2009-11-05 21:03 ——– dc—-w- i:\program files\iTunes
2009-11-05 21:03 . 2009-11-05 21:03 ——– dc—-w- i:\program files\iPod
2009-11-05 21:03 . 2007-10-17 23:07 ——– dc—-w- i:\program files\Common Files\Apple
2009-11-05 20:57 . 2009-11-05 20:57 79144 -c–a-w- i:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-03 01:39 . 2004-03-21 01:14 ——– dc—-w- i:\program files\SlySoft
2009-11-02 05:12 . 2009-10-30 19:04 ——– dc—-w- i:\program files\DVDneXtCOPY3
2009-10-30 19:04 . 2009-10-30 18:48 ——– dc—-w- i:\program files\Common Files\DistributeShield
2009-10-27 11:37 . 2004-07-07 13:50 92920 -c–a-w- i:\documents and settings\Larry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-27 07:27 . 2006-10-31 03:28 96256 —-a-w- i:\windows\system32\drivers\sptd4045.sys
2009-10-27 07:06 . 2007-04-06 15:03 ——– dc—-w- i:\program files\Microsoft Works
2009-10-27 07:03 . 2006-07-28 22:21 ——– dc—-w- i:\program files\Microsoft Visual Studio 8
2009-10-25 06:50 . 2009-05-25 22:13 ——– dc—-w- i:\program files\abgx360
2009-10-22 01:42 . 2009-10-22 01:40 ——– dc—-w- i:\program files\NetBeans 6.0.1
2009-10-22 01:41 . 2009-10-22 01:41 ——– dc—-w- i:\program files\Apache Software Foundation
2009-10-19 13:47 . 2009-10-19 13:47 6 -c–a-w- i:\windows\Fonts\wfonts.key
2009-10-15 22:02 . 2009-10-15 22:02 ——– dc—-w- i:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-14 07:16 . 2006-07-28 22:41 ——– dc—-w- i:\program files\Microsoft SQL Server
2009-10-14 07:09 . 2009-02-20 03:26 18368 -c–a-w- i:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2009-10-14 07:09 . 2009-02-20 03:26 1680064 -c–a-w- i:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2009-10-01 15:36 . 2009-02-13 03:51 83288 —-a-w- i:\windows\system32\LMIRfsClientNP.dll
2009-10-01 15:36 . 2009-02-13 03:51 28984 -c–a-w- i:\windows\system32\LMIport.dll
2009-10-01 15:36 . 2009-02-13 03:51 87352 —-a-w- i:\windows\system32\LMIinit.dll
2009-09-30 18:56 . 2009-09-30 18:56 73880 -c-ha-w- i:\windows\system32\mlfcache.dat
2009-09-24 22:59 . 2009-09-24 22:59 104512 -c–a-w- i:\windows\system32\drivers\AnyDVD.sys
2009-09-11 17:08 . 2009-09-11 17:08 24744 -c–a-w- i:\windows\system32\drivers\ElbyCDIO.sys
2009-09-11 14:33 . 2001-08-23 12:00 133632 —-a-w- i:\windows\system32\msv1_0.dll
2005-09-08 23:05 . 2008-05-21 21:41 24848 -c–a-w- i:\program files\mozilla firefox\plugins\cgpcfg.dll
2005-09-08 23:05 . 2008-05-21 21:41 74000 -c–a-w- i:\program files\mozilla firefox\plugins\cgpcore.dll
2005-09-08 23:05 . 2008-05-21 21:41 45328 -c–a-w- i:\program files\mozilla firefox\plugins\icalogon.dll
2005-09-08 23:05 . 2008-05-21 21:41 28944 -c–a-w- i:\program files\mozilla firefox\plugins\pscript.dll
2005-09-08 23:05 . 2008-05-21 21:41 69904 -c–a-w- i:\program files\mozilla firefox\plugins\sslsdk_b.dll
2005-09-08 23:05 . 2008-05-21 21:41 24848 -c–a-w- i:\program files\mozilla firefox\plugins\tcppserv.dll
2007-12-15 15:34 . 2007-12-15 15:24 72 -csh–w- i:\windows\S8A12DB73.tmp
2005-07-14 18:31 . 2006-05-24 16:37 27648 -csha-w- i:\windows\system32\AVSredirect.dll
.

——- Sigcheck ——-

[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . i:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[-] 2004-08-04 06:59 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [——] . . i:\windows\system32\drivers\atapi.sys
[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . i:\windows\ServicePackFiles\i386\atapi.sys
[7] 2002-08-29 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . i:\windows\$NtServicePackUninstall$\atapi.sys
[-] 2001-08-23 . A64013E98426E1877CB653685C5C0009 . 86656 . . [5.1.2600.0] . . i:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="i:\progra~1\MI3AA1~1\wcescomm.exe" [2006-06-21 1207080]
"NBJ"="i:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-01-04 1937408]
"swg"="i:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
"WMPNSCFG"="i:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"nwiz"="nwiz.exe" [2005-04-01 1495040]
"RoxioEngineUtility"="i:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"WatchDog"="i:\program files\mobile PhoneTools\WatchDog.exe" [2004-08-14 36864]
"NeroFilterCheck"="i:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"NvMediaCenter"="i:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"ATICCC"="i:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"CloneCDTray"="i:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 57344]
"GrooveMonitor"="i:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SSBkgdUpdate"="i:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="i:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-30 30248]
"IndexSearch"="i:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-30 46632]
"PPort11reminder"="i:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"BrMfcWnd"="i:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-23 663552]
"ControlCenter3"="i:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"LogMeIn GUI"="i:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"iTunesHelper"="i:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Malwarebytes Anti-Malware (reboot)"="i:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"AVG9_TRAY"="i:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-12 2020120]
"QuickTime Task"="i:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="i:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

i:\documents and settings\Larry\Start Menu\Programs\Startup\
Adobe Gamma.lnk - i:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
ERUNT AutoBackup.lnk - i:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - i:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "i:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-09 15:22 12464 -c–a-w- i:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-01 15:36 87352 —-a-w- i:\windows\system32\LMIinit.dll

[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
backup=i:\windows\pss\Windows Desktop Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2005-12-10 14:57 133016 -c–a-w- i:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 -c–a-w- i:\program files\QuickTime\QTTask.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"i:\\Program Files\\Java\\j2re1.4.2_04\\bin\\javaw.exe"=
"i:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"i:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"i:\\Program Files\\Messenger\\msmsgs.exe"=
"i:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"i:\\Program Files\\AIM\\aim.exe"=
"i:\program files\Microsoft ActiveSync\rapimgr.exe"= i:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"i:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"i:\\Program Files\\Citrix\\ICA Client\\pn.exe"=
"i:\\WINDOWS\\system32\\sessmgr.exe"=
"i:\\Documents and Settings\\Larry\\taw\\winvnc.exe"=
"i:\\Program Files\\AIM6\\aim6.exe"=
"i:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"i:\\Program Files\\MSN Messenger\\livecall.exe"=
"i:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"i:\\Program Files\\Java\\jdk1.6.0_03\\jre\\bin\\java.exe"=
"i:\\Program Files\\Brother\\Brmfl07a\\FAXRX.exe"=
"i:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"i:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"i:\\Program Files\\LimeWire\\LimeWire.exe"=
"i:\\Program Files\\Trillian\\trillian.exe"=
"i:\\Program Files\\uTorrent\\uTorrent.exe"=
"i:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"i:\\Program Files\\Java\\jre1.5.0_02\\bin\\javaw.exe"=
"i:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"i:\\Program Files\\Java\\jdk1.6.0_03\\bin\\java.exe"=
"i:\\Program Files\\iTunes\\iTunes.exe"=
"i:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"i:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"i:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"i:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"54925:UDP"= 54925:UDP:Brother Network Scanner
"55270:UDP"= 55270:UDP:Utorrent
"55270:TCP"= 55270:TCP:Utorrent

R0 a347bus;a347bus;i:\windows\system32\drivers\a347bus.sys [11/2/2006 9:20 PM 160640]
R0 a347scsi;a347scsi;i:\windows\system32\drivers\a347scsi.sys [11/2/2006 9:20 PM 5248]
R0 sptd;sptd;i:\windows\system32\drivers\sptd.sys [10/30/2006 10:28 PM 643072]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;i:\windows\system32\drivers\avgldx86.sys [4/8/2009 6:20 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;i:\windows\system32\drivers\avgtdix.sys [4/8/2009 6:20 PM 360584]
R1 NEOFLTR_550_12129;Juniper Networks TDI Filter Driver (NEOFLTR_550_12129);i:\windows\system32\drivers\NEOFLTR_550_12129.sys [10/3/2007 3:20 PM 63008]
R2 avg9wd;AVG Free WatchDog;i:\program files\AVG\AVG9\avgwdsvc.exe [11/9/2009 10:21 AM 285392]
R2 LMIInfo;LogMeIn Kernel Information Provider;i:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;i:\windows\system32\drivers\LMIRfsDriver.sys [2/12/2009 10:51 PM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;i:\program files\Viewpoint\Common\ViewpointService.exe [7/3/2009 3:59 PM 24652]
R3 portio32;portio32;i:\windows\system32\drivers\portio32.sys [9/7/2009 2:19 PM 2048]
S2 gupdate1c9d3431ddff9c6;Google Update Service (gupdate1c9d3431ddff9c6);i:\program files\Google\Update\GoogleUpdate.exe [5/12/2009 3:49 PM 133104]
S3 rootrepeal2;rootrepeal2;i:\windows\system32\drivers\rootrepeal2.sys [12/2/2009 8:04 PM 34816]
S3 vaxscsi;vaxscsi;i:\windows\system32\drivers\vaxscsi.sys [10/30/2006 10:30 PM 223128]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki… - i:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: arise.com
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
Trusted Zone: willowcsn.com\cybercentral
DPF: Microsoft XML Parser for Java - file:///I:/WINDOWS/Java/classes/xmldso.cab
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://asp23.centra.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
FF - ProfilePath - i:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\uz0fyw53.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://admintools.ariasystems.net/dashboard-idp/auth/login-aria.php?RelayState=https%3A%2F%2Fadmintools.ariasystems.net%3A443%2Fdashboard-idp%2Fsaml2%2Fidp%2FSSOService.php%3FRequestID%3D_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&spentityid=admintools.ariasystems.net&AuthId=_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&protocol=saml2&timeout=0
FF - component: i:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: i:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: i:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: i:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npican.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: i:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - i:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)
AddRemove-abgx360 - i:\program files\abgx360\uninstall.exe
AddRemove-Citrix Program Neighborhood - i:\windows\ISUNINST.EXE -fi:\progra~1\Citrix\ICACLI~1\Uninst.isu -ci:\progra~1\Citrix\ICACLI~1\uninstpn.dll
AddRemove-Tweak UI 2.10 - i:\windows\System32\mshta.exe res://i:\windows\System32\TweakUI.exe/uninstall.hta
AddRemove-UT2004 - k:\ut2004\System\Setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-07 16:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe >>UNKNOWN [0x8AB7EBF8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x8ab7ebf8
\Driver\ACPI -> ACPI.sys @ 0xba66ecb8
\Driver\atapi -> 0x8a829008
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x8057807e
ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x8057807e
ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
NDIS: NVIDIA nForce 10/100/1000 Mbps Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xba4bcba0
PacketIndicateHandler -> NDIS.sys @ 0xba4c9b21
SendHandler -> NDIS.sys @ 0xba4a787b
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(888)
i:\windows\system32\Ati2evxx.dll
i:\windows\system32\LMIinit.dll

- - - - - - - > 'explorer.exe'(4612)
i:\windows\system32\WININET.dll
i:\windows\system32\ieframe.dll
i:\windows\system32\WPDShServiceObj.dll
i:\windows\system32\PortableDeviceTypes.dll
i:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
i:\windows\system32\Ati2evxx.exe
i:\program files\AVG\AVG9\avgchsvx.exe
i:\program files\AVG\AVG9\avgrsx.exe
i:\program files\AVG\AVG9\avgcsrvx.exe
i:\windows\system32\Ati2evxx.exe
i:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
i:\program files\Bonjour\mDNSResponder.exe
i:\program files\Juniper Networks\Common Files\dsNcService.exe
i:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
i:\program files\AVG\AVG9\avgnsx.exe
i:\program files\Java\jre6\bin\jqs.exe
i:\program files\LogMeIn\x86\RaMaint.exe
i:\program files\LogMeIn\x86\LogMeIn.exe
i:\program files\LogMeIn\x86\LMIGuardian.exe
i:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
i:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
i:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
i:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
i:\program files\LogMeIn\x86\LMIGuardian.exe
i:\windows\System32\MsPMSPSv.exe
i:\windows\system32\SearchIndexer.exe
i:\windows\system32\wscntfy.exe
i:\program files\Brother\Brmfcmon\BrMfimon.exe
i:\progra~1\MI3AA1~1\rapimgr.exe
i:\program files\Windows Media Player\WMPNetwk.exe
i:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-12-07 17:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-07 22:07

Pre-Run: 46,463,344,640 bytes free
Post-Run: 46,203,211,776 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
i:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - A7BF54BAC0B005C2CD35168CF42748E0

Attachments:

Hi larryri42,

You have a program that may interfer with our tools. I'll have you download and run a little tool that will temporarily disable the programs drivers.

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers.
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
Do not re-enable these drivers until otherwise instructed.

I will give you the instructions to re-enable the drivers later in the fix.

Next

We will use combofix again but run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = 

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Please post back with the combofix log.

How is Internet Explorer, any redirects?

Thanks
IE seems to be working okay now. no redirects at all so that seems good. here is the new Log file from Combo Fix:

ComboFix 09-12-07.05 - Larry 12/07/2009 23:19.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1408 [GMT -5:00]
Running from: i:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: i:\documents and settings\Larry\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-11-08 to 2009-12-08 )))))))))))))))))))))))))))))))
.

2009-12-07 21:28 . 2009-12-07 21:28 194464 -c–a-w- i:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-04 13:46 . 2009-12-04 13:46 ——– dc—-w- i:\documents and settings\LocalService\Local Settings\Application Data\IsolatedStorage
2009-12-04 13:41 . 2009-12-04 13:41 ——– dc—-w- i:\documents and settings\Larry\Local Settings\Application Data\IsolatedStorage
2009-12-03 23:38 . 2009-12-03 23:38 81920 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connecthook.dll
2009-12-03 23:38 . 2009-12-03 23:38 158720 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectsprd.dll
2009-12-03 23:38 . 2009-12-03 23:38 3553680 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectaddin6x5.exe
2009-12-03 13:44 . 2008-08-19 14:46 1848608 -c–a-w- i:\windows\system32\acXMLParser.dll
2009-12-03 13:44 . 2008-08-19 14:46 3523872 -c–a-w- i:\windows\system32\cdintf300.dll
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\HaB\Custom\billmind.exe
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\RPM\Custom\billmind.exe
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\Premier\Custom\billmind.exe
2009-12-03 13:44 . 2009-12-03 13:44 ——– dc—-w- i:\program files\Quicken
2009-12-03 01:04 . 2009-12-03 01:44 34816 -c–a-w- i:\windows\system32\drivers\rootrepeal2.sys
2009-12-03 00:54 . 2009-12-03 00:54 ——– dc—-w- i:\windows\BACKUPERDNT
2009-12-03 00:53 . 2009-12-03 00:53 ——– dc—-w- i:\program files\ERUNT
2009-12-02 15:28 . 2009-12-02 15:28 ——– dc—-w- i:\program files\Common Files\AnswerWorks 4.0
2009-12-02 14:43 . 2009-12-02 14:43 ——– dc—-w- i:\program files\Arise
2009-12-02 14:24 . 2009-09-10 19:54 38224 -c–a-w- i:\windows\system32\drivers\mbamswissarmy.sys
2009-12-02 14:24 . 2009-09-10 19:53 19160 -c–a-w- i:\windows\system32\drivers\mbam.sys
2009-12-02 14:24 . 2009-12-02 14:24 ——– dc—-w- i:\program files\Malwarebytes' Anti-Malware
2009-12-01 02:39 . 2009-12-01 03:17 ——– dc—-w- i:\documents and settings\Larry\Local Settings\Application Data\smsgij
2009-11-24 13:37 . 2009-12-07 18:23 86016 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\meetingconvertor.dll
2009-11-24 13:37 . 2009-12-07 18:23 81920 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connecthook.dll
2009-11-24 13:37 . 2009-12-07 17:58 303104 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectsprd.dll
2009-11-24 05:08 . 2009-11-24 05:08 ——– dc—-w- i:\program files\QuickTime
2009-11-23 20:15 . 2009-11-23 20:15 4736992 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe
2009-11-21 16:15 . 2009-11-21 16:14 411368 -c–a-w- i:\windows\system32\deploytk.dll
2009-11-21 16:14 . 2009-11-21 16:14 152576 -c–a-w- i:\documents and settings\Larry\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-20 14:28 . 2009-11-09 15:21 877848 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2009-11-12 14:24 . 2009-11-10 14:12 4026136 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-11-12 14:23 . 2009-11-10 14:12 2016536 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-11-12 14:23 . 2009-11-10 14:12 1257240 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2009-11-12 14:23 . 2009-11-12 14:22 3963648 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-12 14:23 . 2009-11-12 14:22 497944 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2009-11-12 14:23 . 2009-11-09 15:21 600344 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgnsx.exe
2009-11-10 14:12 . 2009-11-09 15:21 360584 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2009-11-10 14:11 . 2009-11-10 14:11 1657112 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2009-11-10 14:11 . 2009-11-09 15:21 610072 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2009-11-09 15:22 . 2009-11-09 15:26 ——– dc—-w- I:\$AVG
2009-11-09 15:21 . 2009-11-09 15:21 ——– dc—-w- i:\documents and settings\All Users\Application Data\avg9

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-07 19:25 . 2009-05-12 20:46 ——– dc—-w- i:\documents and settings\All Users\Application Data\Google Updater
2009-12-07 13:34 . 2009-02-13 03:50 ——– dc—-w- i:\program files\LogMeIn
2009-12-06 01:30 . 2006-06-04 00:28 ——– dc—-w- i:\documents and settings\Larry\Application Data\uTorrent
2009-12-04 13:41 . 2008-03-02 16:35 ——– dc—-w- i:\program files\TurboTax
2009-12-04 13:36 . 2007-01-28 21:43 ——– dc—-w- i:\program files\Common Files\Intuit
2009-12-03 13:45 . 2009-03-09 23:33 ——– dc—-w- i:\program files\Common Files\AnswerWorks 5.0
2009-12-03 13:45 . 2004-03-22 01:19 ——– dc-h–w- i:\program files\InstallShield Installation Information
2009-12-03 13:44 . 2007-01-28 21:45 ——– dc—-w- i:\documents and settings\Larry\Application Data\Intuit
2009-12-03 13:43 . 2007-01-28 21:44 ——– dc—-w- i:\documents and settings\All Users\Application Data\Intuit
2009-12-02 13:53 . 2007-06-22 16:06 ——– dc—-w- i:\documents and settings\Larry\Application Data\Juniper Networks
2009-12-02 13:43 . 2006-07-28 22:21 ——– dc—-w- i:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-02 04:36 . 2007-06-22 16:25 38881 -c–a-w- i:\documents and settings\Larry\Application Data\Juniper Networks\Host Checker\uninstall.exe
2009-11-24 14:33 . 2007-06-22 16:06 ——– dc—-w- i:\program files\Juniper Networks
2009-11-21 16:14 . 2004-06-04 02:13 ——– dc—-w- i:\program files\Java
2009-11-10 14:12 . 2009-04-08 23:20 360584 -c–a-w- i:\windows\system32\drivers\avgtdix.sys
2009-11-09 15:22 . 2009-04-08 23:20 12464 -c–a-w- i:\windows\system32\avgrsstx.dll
2009-11-09 15:22 . 2009-04-08 23:20 333192 -c–a-w- i:\windows\system32\drivers\avgldx86.sys
2009-11-09 15:22 . 2009-04-08 23:20 28424 -c–a-w- i:\windows\system32\drivers\avgmfx86.sys
2009-11-09 15:21 . 2009-04-08 23:20 ——– dc—-w- i:\program files\AVG
2009-11-05 21:04 . 2009-11-05 21:03 ——– dc—-w- i:\program files\iTunes
2009-11-05 21:03 . 2009-11-05 21:03 ——– dc—-w- i:\program files\iPod
2009-11-05 21:03 . 2007-10-17 23:07 ——– dc—-w- i:\program files\Common Files\Apple
2009-11-05 20:57 . 2009-11-05 20:57 79144 -c–a-w- i:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-03 01:39 . 2004-03-21 01:14 ——– dc—-w- i:\program files\SlySoft
2009-11-02 05:12 . 2009-10-30 19:04 ——– dc—-w- i:\program files\DVDneXtCOPY3
2009-10-30 19:04 . 2009-10-30 18:48 ——– dc—-w- i:\program files\Common Files\DistributeShield
2009-10-27 11:37 . 2004-07-07 13:50 92920 -c–a-w- i:\documents and settings\Larry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-27 07:27 . 2006-10-31 03:28 96256 —-a-w- i:\windows\system32\drivers\sptd4045.sys
2009-10-27 07:06 . 2007-04-06 15:03 ——– dc—-w- i:\program files\Microsoft Works
2009-10-27 07:03 . 2006-07-28 22:21 ——– dc—-w- i:\program files\Microsoft Visual Studio 8
2009-10-25 06:50 . 2009-05-25 22:13 ——– dc—-w- i:\program files\abgx360
2009-10-22 01:42 . 2009-10-22 01:40 ——– dc—-w- i:\program files\NetBeans 6.0.1
2009-10-22 01:41 . 2009-10-22 01:41 ——– dc—-w- i:\program files\Apache Software Foundation
2009-10-19 13:47 . 2009-10-19 13:47 6 -c–a-w- i:\windows\Fonts\wfonts.key
2009-10-15 22:02 . 2009-10-15 22:02 ——– dc—-w- i:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-14 07:16 . 2006-07-28 22:41 ——– dc—-w- i:\program files\Microsoft SQL Server
2009-10-14 07:09 . 2009-02-20 03:26 18368 -c–a-w- i:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2009-10-14 07:09 . 2009-02-20 03:26 1680064 -c–a-w- i:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2009-10-01 15:36 . 2009-02-13 03:51 83288 —-a-w- i:\windows\system32\LMIRfsClientNP.dll
2009-10-01 15:36 . 2009-02-13 03:51 28984 -c–a-w- i:\windows\system32\LMIport.dll
2009-10-01 15:36 . 2009-02-13 03:51 87352 —-a-w- i:\windows\system32\LMIinit.dll
2009-09-30 18:56 . 2009-09-30 18:56 73880 -c-ha-w- i:\windows\system32\mlfcache.dat
2009-09-24 22:59 . 2009-09-24 22:59 104512 -c–a-w- i:\windows\system32\drivers\AnyDVD.sys
2009-09-11 17:08 . 2009-09-11 17:08 24744 -c–a-w- i:\windows\system32\drivers\ElbyCDIO.sys
2009-09-11 14:33 . 2001-08-23 12:00 133632 —-a-w- i:\windows\system32\msv1_0.dll
2005-09-08 23:05 . 2008-05-21 21:41 24848 -c–a-w- i:\program files\mozilla firefox\plugins\cgpcfg.dll
2005-09-08 23:05 . 2008-05-21 21:41 74000 -c–a-w- i:\program files\mozilla firefox\plugins\cgpcore.dll
2005-09-08 23:05 . 2008-05-21 21:41 45328 -c–a-w- i:\program files\mozilla firefox\plugins\icalogon.dll
2005-09-08 23:05 . 2008-05-21 21:41 28944 -c–a-w- i:\program files\mozilla firefox\plugins\pscript.dll
2005-09-08 23:05 . 2008-05-21 21:41 69904 -c–a-w- i:\program files\mozilla firefox\plugins\sslsdk_b.dll
2005-09-08 23:05 . 2008-05-21 21:41 24848 -c–a-w- i:\program files\mozilla firefox\plugins\tcppserv.dll
2007-12-15 15:34 . 2007-12-15 15:24 72 -csh–w- i:\windows\S8A12DB73.tmp
2005-07-14 18:31 . 2006-05-24 16:37 27648 -csha-w- i:\windows\system32\AVSredirect.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-12-07_21.55.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-08 04:08 . 2009-12-08 04:08 16384 i:\windows\Temp\Perflib_Perfdata_a10.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="i:\progra~1\MI3AA1~1\wcescomm.exe" [2006-06-21 1207080]
"NBJ"="i:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-01-04 1937408]
"swg"="i:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
"WMPNSCFG"="i:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"nwiz"="nwiz.exe" [2005-04-01 1495040]
"RoxioEngineUtility"="i:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"WatchDog"="i:\program files\mobile PhoneTools\WatchDog.exe" [2004-08-14 36864]
"NeroFilterCheck"="i:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"NvMediaCenter"="i:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"ATICCC"="i:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"CloneCDTray"="i:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 57344]
"GrooveMonitor"="i:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SSBkgdUpdate"="i:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="i:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-30 30248]
"IndexSearch"="i:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-30 46632]
"PPort11reminder"="i:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"BrMfcWnd"="i:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-23 663552]
"ControlCenter3"="i:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"LogMeIn GUI"="i:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"iTunesHelper"="i:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Malwarebytes Anti-Malware (reboot)"="i:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"AVG9_TRAY"="i:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-12 2020120]
"QuickTime Task"="i:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="i:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

i:\documents and settings\Larry\Start Menu\Programs\Startup\
Adobe Gamma.lnk - i:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
ERUNT AutoBackup.lnk - i:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - i:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "i:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-09 15:22 12464 -c–a-w- i:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-01 15:36 87352 —-a-w- i:\windows\system32\LMIinit.dll

[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
backup=i:\windows\pss\Windows Desktop Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2005-12-10 14:57 133016 -c–a-w- i:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 -c–a-w- i:\program files\QuickTime\QTTask.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"i:\\Program Files\\Java\\j2re1.4.2_04\\bin\\javaw.exe"=
"i:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"i:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"i:\\Program Files\\Messenger\\msmsgs.exe"=
"i:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"i:\\Program Files\\AIM\\aim.exe"=
"i:\program files\Microsoft ActiveSync\rapimgr.exe"= i:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"i:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"i:\\Program Files\\Citrix\\ICA Client\\pn.exe"=
"i:\\WINDOWS\\system32\\sessmgr.exe"=
"i:\\Documents and Settings\\Larry\\taw\\winvnc.exe"=
"i:\\Program Files\\AIM6\\aim6.exe"=
"i:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"i:\\Program Files\\MSN Messenger\\livecall.exe"=
"i:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"i:\\Program Files\\Java\\jdk1.6.0_03\\jre\\bin\\java.exe"=
"i:\\Program Files\\Brother\\Brmfl07a\\FAXRX.exe"=
"i:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"i:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"i:\\Program Files\\LimeWire\\LimeWire.exe"=
"i:\\Program Files\\Trillian\\trillian.exe"=
"i:\\Program Files\\uTorrent\\uTorrent.exe"=
"i:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"i:\\Program Files\\Java\\jre1.5.0_02\\bin\\javaw.exe"=
"i:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"i:\\Program Files\\Java\\jdk1.6.0_03\\bin\\java.exe"=
"i:\\Program Files\\iTunes\\iTunes.exe"=
"i:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"i:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"i:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"i:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"54925:UDP"= 54925:UDP:Brother Network Scanner
"55270:UDP"= 55270:UDP:Utorrent
"55270:TCP"= 55270:TCP:Utorrent

R1 AvgLdx86;AVG Free AVI Loader Driver x86;i:\windows\system32\drivers\avgldx86.sys [4/8/2009 6:20 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;i:\windows\system32\drivers\avgtdix.sys [4/8/2009 6:20 PM 360584]
R1 NEOFLTR_550_12129;Juniper Networks TDI Filter Driver (NEOFLTR_550_12129);i:\windows\system32\drivers\NEOFLTR_550_12129.sys [10/3/2007 3:20 PM 63008]
R2 avg9wd;AVG Free WatchDog;i:\program files\AVG\AVG9\avgwdsvc.exe [11/9/2009 10:21 AM 285392]
R2 LMIInfo;LogMeIn Kernel Information Provider;i:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;i:\windows\system32\drivers\LMIRfsDriver.sys [2/12/2009 10:51 PM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;i:\program files\Viewpoint\Common\ViewpointService.exe [7/3/2009 3:59 PM 24652]
R3 portio32;portio32;i:\windows\system32\drivers\portio32.sys [9/7/2009 2:19 PM 2048]
S2 gupdate1c9d3431ddff9c6;Google Update Service (gupdate1c9d3431ddff9c6);i:\program files\Google\Update\GoogleUpdate.exe [5/12/2009 3:49 PM 133104]
S3 rootrepeal2;rootrepeal2;i:\windows\system32\drivers\rootrepeal2.sys [12/2/2009 8:04 PM 34816]
S3 vaxscsi;vaxscsi;i:\windows\system32\drivers\vaxscsi.sys [10/30/2006 10:30 PM 223128]
S4 a347bus;a347bus;i:\windows\system32\drivers\a347bus.sys [11/2/2006 9:20 PM 160640]
S4 a347scsi;a347scsi;i:\windows\system32\drivers\a347scsi.sys [11/2/2006 9:20 PM 5248]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 sptd;sptd;i:\windows\system32\drivers\sptd.sys [10/30/2006 10:28 PM 643072]
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki… - i:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: arise.com
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
Trusted Zone: willowcsn.com\cybercentral
DPF: Microsoft XML Parser for Java - file:///I:/WINDOWS/Java/classes/xmldso.cab
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://asp23.centra.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
FF - ProfilePath - i:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\uz0fyw53.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://admintools.ariasystems.net/dashboard-idp/auth/login-aria.php?RelayState=https%3A%2F%2Fadmintools.ariasystems.net%3A443%2Fdashboard-idp%2Fsaml2%2Fidp%2FSSOService.php%3FRequestID%3D_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&spentityid=admintools.ariasystems.net&AuthId=_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&protocol=saml2&timeout=0
FF - component: i:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: i:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: i:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: i:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npican.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: i:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - i:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
i:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-07 23:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(808)
i:\windows\system32\Ati2evxx.dll
i:\windows\system32\LMIinit.dll

- - - - - - - > 'explorer.exe'(4796)
i:\windows\system32\WININET.dll
i:\windows\system32\ieframe.dll
i:\windows\system32\WPDShServiceObj.dll
i:\windows\system32\PortableDeviceTypes.dll
i:\windows\system32\PortableDeviceApi.dll
i:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-12-07 23:37
ComboFix-quarantined-files.txt 2009-12-08 04:36
ComboFix2.txt 2009-12-07 22:07

Pre-Run: 46,103,777,280 bytes free
Post-Run: 46,073,278,464 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - AEACC932805F6F6081E9E44239023427
Hi larryri42,

You used to to use Symantec (Norton) and have uninstalled it?

µTorrent
You have µTorrent, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it. It's not the program itself but what can be downloaded with it, usually from an unknown source.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

You have some old vulnerable java installed. Go to ad/remove programs and uninstall

Java 2 Runtime Environment, SE v1.4.2_04
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 2
Java™ SE Development Kit 6 Update 3


Do not uninstall Java™ 6 Update 17

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel. (looks like a coffee cup)
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK


Next

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Please post back with the Kaspersky log and info regarding Norton.

Thanks
i have never used Norton. i did however have Mcafee for a long time but now i am using AVG free edition. here is the log for Kaspersky. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, December 9, 2009 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, December 08, 2009 18:00:11 Records in database: 3344158 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: D:\ E:\ F:\ G:\ H:\ I:\ K:\ R:\ Scan statistics: Objects scanned: 201319 Threats found: 4 Infected objects found: 5 Suspicious objects found: 0 Scan duration: 08:08:28 File name / Threat / Threats count I:\data Infected: Trojan-Downloader.Win32.IstBar.nh 1 I:\Documents and Settings\Larry\My Documents\My Received Files\BSINSTALL.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z 1 I:\Documents and Settings\Larry\My Documents\My Received Files\BSINSTALL.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1 I:\Documents and Settings\Larry\taw\othread2.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c 1 I:\System Volume Information\_restore{5C8E04F7-5904-4205-BE70-D4B1B7905EF2}\RP1657\A0255113.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c 1 Selected area has been scanned.
Hi Larryri42,

I asked about Norton because of this installed program

LiveUpdate 1.6 (Symantec Corporation)

Kaspersky found 2 files plus an old Restore point which will be remove when we clean up the tools.

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time if more than file is listed, into the "Suspicious files to scan" box on the top of the page:

    I:\data
  • Click on the Upload button
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

I:\Documents and Settings\Larry\My Documents\My Received Files\BSINSTALL.exe

Is related to BearShare. Something you used to use?


Locate combofix.exe on your desktop, right click it and select delete. Download a new copy from either link and download a new copy to your desktop. Do not run it.

Link 1
Link 2

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DEQUARANTINE::
C:\Qoobox\Quarantine\c\program files\ATI Technologies\ATI.ACE\Core-Static\atIAcmxx.dll.vir 

Quit::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Only a DeQuarantine.txt will be produced, please post it's contents along with the VirScan results.
hi Oldman960,

BearShare i believe its a very old application something like a P2P but i have not used that in years. As per that Norton thing if we can delete it even better.

here is the clipboard information:

VirSCAN.org Scanned Report :
Scanned time : 2009/12/09 09:06:43 (EST)
Scanner results: 32% Scanner(s) (12/37) found malware!
File Name : data
File Size : 3499 byte
File Type : ASCII C program text, with CRLF line terminators
MD5 : bb8ba1acacb123b6362cfa3bbae545bd
SHA1 : 0124e2ea1d3f6e2bed63be53f3e03febce586f12
Online report : http://virscan.org/report/2a8d23b644c3cad8…a4c68dd84d.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091209213155 2009-12-09 4.36 Trojan-Downloader.Win32.IstBar!IK
AhnLab V3 2009.12.09.03 2009.12.09 2009-12-09 1.20 -
AntiVir 8.2.1.102 7.10.1.204 2009-12-09 0.46 -
Antiy 2.0.18 20091204.3347676 2009-12-04 0.12 Trojan/Win32.IstBar.nh[Downloader]
Arcavir 2009 200912090101 2009-12-09 0.03 Downloader.Istbar.Nh
Authentium 5.1.1 200912082317 2009-12-08 1.22 -
AVAST! 4.7.4 091209-0 2009-12-09 0.00 -
AVG 8.5.288 270.14.100/2554 2009-12-09 0.31 -
BitDefender 7.81008.4706260 7.29372 2009-12-09 3.98 Trojan.Downloader.Istbar.NH
CA (VET) 35.1.0 7165 2009-12-08 8.43 -
ClamAV 0.95.2 10137 2009-12-09 0.01 -
Comodo 3.13 3191 2009-12-09 1.69 Trojan-Downloader.Win32.IstBar.nh
CP Secure 1.3.0.5 2009.12.04 2009-12-04 0.01 -
Dr.Web 4.44.0.9170 2009.12.09 2009-12-09 7.52 -
F-Prot 4.4.4.56 20091208 2009-12-08 1.47 -
F-Secure 7.02.73807 2009.12.09.04 2009-12-09 0.05 Trojan-Downloader.Win32.IstBar.nh [AVP]
Fortinet 11.141- 11.141 2009-12-09 0.20 W32/Istbar.NH!tr
GData 19.9225/19.613 20091209 2009-12-09 6.80 Trojan-Downloader.Win32.IstBar.nh [Engine:A]
ViRobot 20091209 2009.12.09 2009-12-09 0.38 -
Ikarus T3.1.01.74 2009.12.09.74709 2009-12-09 4.79 Trojan-Downloader.Win32.IstBar
JiangMin 13.0.900 2009.12.02 2009-12-02 9.81 -
Kaspersky 5.5.10 2009.12.09 2009-12-09 0.03 Trojan-Downloader.Win32.IstBar.nh
KingSoft 2009.2.5.15 2009.12.9.20 2009-12-09 1.17 -
McAfee 5.3.00 5826 2009-12-08 3.29 -
Microsoft 1.5302 2009.12.09 2009-12-09 7.99 -
Norman 6.01.09 6.01.00 2009-12-09 4.01 -
Panda 9.05.01 2009.12.07 2009-12-07 4.38 -
Trend Micro 9.000-1003 6.682.04 2009-12-09 0.02 -
Quick Heal 10.00 2009.12.09 2009-12-09 1.96 -
Rising 20.0 22.25.02.09 2009-12-09 0.42 -
Sophos 3.02.0 4.48 2009-12-09 2.96 -
Sunbelt 3.9.2381.2 5550 2009-12-08 1.93 -
Symantec 1.3.0.24 20091208.002 2009-12-08 0.19 -
nProtect 20091209.02 6543022 2009-12-09 5.55 Trojan.Downloader.Istbar.NH
The Hacker 6.5.0.2 v00011 2009-09-18 0.73 -
VBA32 [removed] 20091208.1706 2009-12-08 2.21 Trojan-Downloader.Win32.IstBar.nh
VirusBuster 4.5.11.10 10.115.4/2011277 2009-12-08 2.37 -



here is the Log for COmbofix:

ComboFix 09-12-08.05 - Larry 12/09/2009 9:17.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1041 [GMT -5:00]
Running from: i:\documents and settings\[removed]\My Documents\downloads\ComboFix.exe
Command switches used :: i:\documents and settings\Larry\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))))))
.

2009-12-08 04:48 . 2009-12-08 04:48 4844296 -c–a-w- i:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-04 13:41 . 2009-12-04 13:41 ——– dc—-w- i:\documents and settings\Larry\Local Settings\Application Data\IsolatedStorage
2009-12-03 23:38 . 2009-12-03 23:38 81920 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connecthook.dll
2009-12-03 23:38 . 2009-12-03 23:38 158720 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectsprd.dll
2009-12-03 23:38 . 2009-12-03 23:38 3553680 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectaddin6x5.exe
2009-12-03 13:44 . 2008-08-19 14:46 1848608 -c–a-w- i:\windows\system32\acXMLParser.dll
2009-12-03 13:44 . 2008-08-19 14:46 3523872 -c–a-w- i:\windows\system32\cdintf300.dll
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\HaB\Custom\billmind.exe
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\RPM\Custom\billmind.exe
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\Premier\Custom\billmind.exe
2009-12-03 13:44 . 2009-12-03 13:44 ——– dc—-w- i:\program files\Quicken
2009-12-03 01:04 . 2009-12-03 01:44 34816 -c–a-w- i:\windows\system32\drivers\rootrepeal2.sys
2009-12-03 00:54 . 2009-12-03 00:54 ——– dc—-w- i:\windows\BACKUPERDNT
2009-12-03 00:53 . 2009-12-03 00:53 ——– dc—-w- i:\program files\ERUNT
2009-12-02 15:28 . 2009-12-02 15:28 ——– dc—-w- i:\program files\Common Files\AnswerWorks 4.0
2009-12-02 14:43 . 2009-12-02 14:43 ——– dc—-w- i:\program files\Arise
2009-12-02 14:24 . 2009-12-03 21:14 38224 -c–a-w- i:\windows\system32\drivers\mbamswissarmy.sys
2009-12-02 14:24 . 2009-12-03 21:13 19160 -c–a-w- i:\windows\system32\drivers\mbam.sys
2009-12-02 14:24 . 2009-12-08 04:48 ——– dc—-w- i:\program files\Malwarebytes' Anti-Malware
2009-12-01 02:39 . 2009-12-01 03:17 ——– dc—-w- i:\documents and settings\Larry\Local Settings\Application Data\smsgij
2009-11-24 13:37 . 2009-12-09 13:40 86016 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\meetingconvertor.dll
2009-11-24 13:37 . 2009-12-09 13:40 81920 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connecthook.dll
2009-11-24 13:37 . 2009-12-09 13:40 303104 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectsprd.dll
2009-11-24 05:08 . 2009-11-24 05:08 ——– dc—-w- i:\program files\QuickTime
2009-11-23 20:15 . 2009-11-23 20:15 4736992 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe
2009-11-21 16:15 . 2009-11-21 16:14 411368 -c–a-w- i:\windows\system32\deploytk.dll
2009-11-21 16:14 . 2009-11-21 16:14 152576 -c–a-w- i:\documents and settings\Larry\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-20 14:28 . 2009-11-09 15:21 877848 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2009-11-12 14:24 . 2009-11-10 14:12 4026136 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-11-12 14:23 . 2009-11-10 14:12 2016536 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-11-12 14:23 . 2009-11-10 14:12 1257240 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2009-11-12 14:23 . 2009-11-12 14:22 3963648 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-12 14:23 . 2009-11-12 14:22 497944 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2009-11-12 14:23 . 2009-11-09 15:21 600344 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgnsx.exe
2009-11-10 14:12 . 2009-11-09 15:21 360584 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2009-11-10 14:11 . 2009-11-10 14:11 1657112 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2009-11-10 14:11 . 2009-11-09 15:21 610072 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2009-11-09 15:22 . 2009-11-09 15:26 ——– dc—-w- I:\$AVG
2009-11-09 15:21 . 2009-11-09 15:21 ——– dc—-w- i:\documents and settings\All Users\Application Data\avg9

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-09 13:37 . 2009-02-13 03:50 ——– dc—-w- i:\program files\LogMeIn
2009-12-08 21:17 . 2004-06-04 02:13 ——– dc—-w- i:\program files\Java
2009-12-08 20:26 . 2009-05-12 20:46 ——– dc—-w- i:\documents and settings\All Users\Application Data\Google Updater
2009-12-06 01:30 . 2006-06-04 00:28 ——– dc—-w- i:\documents and settings\Larry\Application Data\uTorrent
2009-12-04 13:41 . 2008-03-02 16:35 ——– dc—-w- i:\program files\TurboTax
2009-12-04 13:36 . 2007-01-28 21:43 ——– dc—-w- i:\program files\Common Files\Intuit
2009-12-03 13:45 . 2009-03-09 23:33 ——– dc—-w- i:\program files\Common Files\AnswerWorks 5.0
2009-12-03 13:45 . 2004-03-22 01:19 ——– dc-h–w- i:\program files\InstallShield Installation Information
2009-12-03 13:44 . 2007-01-28 21:45 ——– dc—-w- i:\documents and settings\Larry\Application Data\Intuit
2009-12-03 13:43 . 2007-01-28 21:44 ——– dc—-w- i:\documents and settings\All Users\Application Data\Intuit
2009-12-02 13:53 . 2007-06-22 16:06 ——– dc—-w- i:\documents and settings\Larry\Application Data\Juniper Networks
2009-12-02 13:43 . 2006-07-28 22:21 ——– dc—-w- i:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-02 04:36 . 2007-06-22 16:25 38881 -c–a-w- i:\documents and settings\Larry\Application Data\Juniper Networks\Host Checker\uninstall.exe
2009-11-24 14:33 . 2007-06-22 16:06 ——– dc—-w- i:\program files\Juniper Networks
2009-11-10 14:12 . 2009-04-08 23:20 360584 -c–a-w- i:\windows\system32\drivers\avgtdix.sys
2009-11-09 15:22 . 2009-04-08 23:20 12464 -c–a-w- i:\windows\system32\avgrsstx.dll
2009-11-09 15:22 . 2009-04-08 23:20 333192 -c–a-w- i:\windows\system32\drivers\avgldx86.sys
2009-11-09 15:22 . 2009-04-08 23:20 28424 -c–a-w- i:\windows\system32\drivers\avgmfx86.sys
2009-11-09 15:21 . 2009-04-08 23:20 ——– dc—-w- i:\program files\AVG
2009-11-05 21:04 . 2009-11-05 21:03 ——– dc—-w- i:\program files\iTunes
2009-11-05 21:03 . 2009-11-05 21:03 ——– dc—-w- i:\program files\iPod
2009-11-05 21:03 . 2007-10-17 23:07 ——– dc—-w- i:\program files\Common Files\Apple
2009-11-05 20:57 . 2009-11-05 20:57 79144 -c–a-w- i:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-03 01:39 . 2004-03-21 01:14 ——– dc—-w- i:\program files\SlySoft
2009-11-02 05:12 . 2009-10-30 19:04 ——– dc—-w- i:\program files\DVDneXtCOPY3
2009-10-30 19:04 . 2009-10-30 18:48 ——– dc—-w- i:\program files\Common Files\DistributeShield
2009-10-27 11:37 . 2004-07-07 13:50 92920 -c–a-w- i:\documents and settings\Larry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-27 07:27 . 2006-10-31 03:28 96256 —-a-w- i:\windows\system32\drivers\sptd4045.sys
2009-10-27 07:06 . 2007-04-06 15:03 ——– dc—-w- i:\program files\Microsoft Works
2009-10-27 07:03 . 2006-07-28 22:21 ——– dc—-w- i:\program files\Microsoft Visual Studio 8
2009-10-25 06:50 . 2009-05-25 22:13 ——– dc—-w- i:\program files\abgx360
2009-10-22 01:42 . 2009-10-22 01:40 ——– dc—-w- i:\program files\NetBeans 6.0.1
2009-10-22 01:41 . 2009-10-22 01:41 ——– dc—-w- i:\program files\Apache Software Foundation
2009-10-19 13:47 . 2009-10-19 13:47 6 -c–a-w- i:\windows\Fonts\wfonts.key
2009-10-15 22:02 . 2009-10-15 22:02 ——– dc—-w- i:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-14 07:16 . 2006-07-28 22:41 ——– dc—-w- i:\program files\Microsoft SQL Server
2009-10-14 07:09 . 2009-02-20 03:26 18368 -c–a-w- i:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2009-10-14 07:09 . 2009-02-20 03:26 1680064 -c–a-w- i:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2009-10-01 15:36 . 2009-02-13 03:51 83288 —-a-w- i:\windows\system32\LMIRfsClientNP.dll
2009-10-01 15:36 . 2009-02-13 03:51 28984 -c–a-w- i:\windows\system32\LMIport.dll
2009-10-01 15:36 . 2009-02-13 03:51 87352 —-a-w- i:\windows\system32\LMIinit.dll
2009-09-30 18:56 . 2009-09-30 18:56 73880 -c-ha-w- i:\windows\system32\mlfcache.dat
2009-09-24 22:59 . 2009-09-24 22:59 104512 -c–a-w- i:\windows\system32\drivers\AnyDVD.sys
2009-09-11 17:08 . 2009-09-11 17:08 24744 -c–a-w- i:\windows\system32\drivers\ElbyCDIO.sys
2009-09-11 14:33 . 2001-08-23 12:00 133632 —-a-w- i:\windows\system32\msv1_0.dll
2005-09-08 23:05 . 2008-05-21 21:41 24848 -c–a-w- i:\program files\mozilla firefox\plugins\cgpcfg.dll
2005-09-08 23:05 . 2008-05-21 21:41 74000 -c–a-w- i:\program files\mozilla firefox\plugins\cgpcore.dll
2005-09-08 23:05 . 2008-05-21 21:41 45328 -c–a-w- i:\program files\mozilla firefox\plugins\icalogon.dll
2005-09-08 23:05 . 2008-05-21 21:41 28944 -c–a-w- i:\program files\mozilla firefox\plugins\pscript.dll
2005-09-08 23:05 . 2008-05-21 21:41 69904 -c–a-w- i:\program files\mozilla firefox\plugins\sslsdk_b.dll
2005-09-08 23:05 . 2008-05-21 21:41 24848 -c–a-w- i:\program files\mozilla firefox\plugins\tcppserv.dll
2007-12-15 15:34 . 2007-12-15 15:24 72 -csh–w- i:\windows\S8A12DB73.tmp
2005-07-14 18:31 . 2006-05-24 16:37 27648 -csha-w- i:\windows\system32\AVSredirect.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-12-07_21.55.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-08 21:24 . 2009-12-08 21:24 16384 i:\windows\Temp\Perflib_Perfdata_a08.dat
+ 2009-12-08 21:25 . 2009-12-08 21:25 245760 i:\windows\ERDNT\AutoBackup\12-8-2009\Users\00000002\UsrClass.dat
+ 2009-12-08 21:25 . 2005-10-20 17:02 163328 i:\windows\ERDNT\AutoBackup\12-8-2009\ERDNT.EXE
+ 2009-12-08 21:25 . 2009-12-08 21:25 13168640 i:\windows\ERDNT\AutoBackup\12-8-2009\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="i:\progra~1\MI3AA1~1\wcescomm.exe" [2006-06-21 1207080]
"NBJ"="i:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-01-04 1937408]
"swg"="i:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
"WMPNSCFG"="i:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"nwiz"="nwiz.exe" [2005-04-01 1495040]
"RoxioEngineUtility"="i:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"WatchDog"="i:\program files\mobile PhoneTools\WatchDog.exe" [2004-08-14 36864]
"NeroFilterCheck"="i:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"NvMediaCenter"="i:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"ATICCC"="i:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"CloneCDTray"="i:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 57344]
"GrooveMonitor"="i:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SSBkgdUpdate"="i:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="i:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-30 30248]
"IndexSearch"="i:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-30 46632]
"PPort11reminder"="i:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"BrMfcWnd"="i:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-23 663552]
"ControlCenter3"="i:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"LogMeIn GUI"="i:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"iTunesHelper"="i:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"AVG9_TRAY"="i:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-12 2020120]
"QuickTime Task"="i:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"SunJavaUpdateSched"="i:\program files\Java\jre6\bin\jusched.exe" [2009-11-21 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="i:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

i:\documents and settings\Larry\Start Menu\Programs\Startup\
Adobe Gamma.lnk - i:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
ERUNT AutoBackup.lnk - i:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - i:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "i:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-09 15:22 12464 -c–a-w- i:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-01 15:36 87352 —-a-w- i:\windows\system32\LMIinit.dll

[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
backup=i:\windows\pss\Windows Desktop Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2005-12-10 14:57 133016 -c–a-w- i:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 -c–a-w- i:\program files\QuickTime\QTTask.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"i:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"i:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"i:\\Program Files\\Messenger\\msmsgs.exe"=
"i:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"i:\\Program Files\\AIM\\aim.exe"=
"i:\program files\Microsoft ActiveSync\rapimgr.exe"= i:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"i:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"i:\\Program Files\\Citrix\\ICA Client\\pn.exe"=
"i:\\WINDOWS\\system32\\sessmgr.exe"=
"i:\\Documents and Settings\\Larry\\taw\\winvnc.exe"=
"i:\\Program Files\\AIM6\\aim6.exe"=
"i:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"i:\\Program Files\\MSN Messenger\\livecall.exe"=
"i:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"i:\\Program Files\\Brother\\Brmfl07a\\FAXRX.exe"=
"i:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"i:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"i:\\Program Files\\LimeWire\\LimeWire.exe"=
"i:\\Program Files\\Trillian\\trillian.exe"=
"i:\\Program Files\\uTorrent\\uTorrent.exe"=
"i:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"i:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"i:\\Program Files\\iTunes\\iTunes.exe"=
"i:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"i:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"i:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"i:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"54925:UDP"= 54925:UDP:Brother Network Scanner
"55270:UDP"= 55270:UDP:Utorrent
"55270:TCP"= 55270:TCP:Utorrent

R1 AvgLdx86;AVG Free AVI Loader Driver x86;i:\windows\system32\drivers\avgldx86.sys [4/8/2009 6:20 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;i:\windows\system32\drivers\avgtdix.sys [4/8/2009 6:20 PM 360584]
R1 NEOFLTR_550_12129;Juniper Networks TDI Filter Driver (NEOFLTR_550_12129);i:\windows\system32\drivers\NEOFLTR_550_12129.sys [10/3/2007 3:20 PM 63008]
R2 avg9wd;AVG Free WatchDog;i:\program files\AVG\AVG9\avgwdsvc.exe [11/9/2009 10:21 AM 285392]
R2 LMIInfo;LogMeIn Kernel Information Provider;i:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;i:\windows\system32\drivers\LMIRfsDriver.sys [2/12/2009 10:51 PM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;i:\program files\Viewpoint\Common\ViewpointService.exe [7/3/2009 3:59 PM 24652]
R3 portio32;portio32;i:\windows\system32\drivers\portio32.sys [9/7/2009 2:19 PM 2048]
S2 gupdate1c9d3431ddff9c6;Google Update Service (gupdate1c9d3431ddff9c6);i:\program files\Google\Update\GoogleUpdate.exe [5/12/2009 3:49 PM 133104]
S3 rootrepeal2;rootrepeal2;i:\windows\system32\drivers\rootrepeal2.sys [12/2/2009 8:04 PM 34816]
S3 vaxscsi;vaxscsi;i:\windows\system32\drivers\vaxscsi.sys [10/30/2006 10:30 PM 223128]
S4 a347bus;a347bus;i:\windows\system32\drivers\a347bus.sys [11/2/2006 9:20 PM 160640]
S4 a347scsi;a347scsi;i:\windows\system32\drivers\a347scsi.sys [11/2/2006 9:20 PM 5248]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 sptd;sptd;i:\windows\system32\drivers\sptd.sys [10/30/2006 10:28 PM 643072]
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki… - i:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: arise.com
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
Trusted Zone: willowcsn.com\cybercentral
DPF: Microsoft XML Parser for Java - file:///I:/WINDOWS/Java/classes/xmldso.cab
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://asp23.centra.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
FF - ProfilePath - i:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\uz0fyw53.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://admintools.ariasystems.net/dashboard-idp/auth/login-aria.php?RelayState=https%3A%2F%2Fadmintools.ariasystems.net%3A443%2Fdashboard-idp%2Fsaml2%2Fidp%2FSSOService.php%3FRequestID%3D_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&spentityid=admintools.ariasystems.net&AuthId=_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&protocol=saml2&timeout=0
FF - component: i:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: i:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: i:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: i:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npican.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: i:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - i:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
i:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-09 09:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


i:\docume~1\Larry\LOCALS~1\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(808)
i:\windows\system32\Ati2evxx.dll
i:\windows\system32\LMIinit.dll

- - - - - - - > 'explorer.exe'(4584)
i:\windows\system32\WININET.dll
i:\windows\system32\ieframe.dll
i:\windows\system32\WPDShServiceObj.dll
i:\windows\system32\PortableDeviceTypes.dll
i:\windows\system32\PortableDeviceApi.dll
i:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-12-09 09:31:19
ComboFix-quarantined-files.txt 2009-12-09 14:31
ComboFix2.txt 2009-12-08 04:37
ComboFix3.txt 2009-12-07 22:07

Pre-Run: 45,958,385,664 bytes free
Post-Run: 45,974,204,416 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - A94F3EC1741869EEBD3EDB15478CA5E8
Hi Larryri42,

Did you run the CFScript as posted? You should have recieved a DeQuarantine.txt instead of a full scan log. Please post the contents of this file

C:\Qoobox\ComboFix-quarantined-files.txt

Yes I know what Bearshare is and it not considered a "good" P2P. It does not show in Add/remove programs. Perhaps you uninstalled it somewhere along the way?


Go to Add/Remove programs and uninstall

LiveUpdate 1.6 (Symantec Corporation)



Next

Download the Norton Removal Tool from HERE and save it to your desktop.

Next Double click on Norton_Removal_Tool.exe to run the tool.

Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.


Next

Download OTL to your desktop.

Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Files
I:\data Infected
I:\Documents and Settings\Larry\My Documents\My Received Files\BSINSTALL.exe

:Commands
[emptytemp]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Please post the
  • ComboFix-quarantined-files.txt
  • OTL fix log
Everthing still OK?

Thanks
Hi OldMan960,

I am pretty sure i did uninstall Bearshare some time ago, i guess not all files or folders were uninstalled.

LiveUpdate 1.6 (Symantec Corporation) is Not in Add and Remove Programs


here is the I:\Qoobox\ComboFix-quarantined-files.txt

2009-12-08 04:19:11 . 2009-12-09 14:17:33 0 -c–a-w- I:\Qoobox\Quarantine\catchme.txt
2009-12-07 22:06:30 . 2009-12-07 22:06:30 564 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\AddRemove-UT2004.reg.dat
2009-12-07 22:06:30 . 2009-12-07 22:06:30 784 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\AddRemove-Tweak UI 2.10.reg.dat
2009-12-07 22:06:30 . 2009-12-07 22:06:30 658 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\AddRemove-Citrix Program Neighborhood.reg.dat
2009-12-07 22:06:30 . 2009-12-07 22:06:30 556 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\AddRemove-abgx360.reg.dat
2009-12-07 22:06:07 . 2009-12-07 22:06:07 90 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Aim6.reg.dat
2009-12-07 21:46:43 . 2009-12-07 21:46:43 2,036 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\Service_NPF.reg.dat
2009-12-07 21:46:22 . 2009-12-09 14:25:33 11,882 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2009-12-07 21:32:58 . 2009-12-09 14:16:00 255 -c–a-w- I:\Qoobox\Quarantine\catchme.log
2008-04-10 17:42:22 . 1999-08-18 14:54:22 180,224 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\ijl11.dll.vir
2007-09-07 16:02:22 . 2007-09-07 16:02:22 1,787 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\crlogo.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 273 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\printd.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 134 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\refreshd.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 1,236 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\refresh_over.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 274 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\searchd.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 1,205 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\search_over.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 122 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\up.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 898 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\upd.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 1,244 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\up_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 84 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\calendar.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 617 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\export.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 283 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\exportd.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 1,244 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\export_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 595 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\gotopage.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 1,226 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\gotopage_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 257 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\grouptree.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 230 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\grouptreed.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 179 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\grouptreepressed.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 1,215 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\grouptree_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 375 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\print.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 1,219 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\print_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 134 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Refresh.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 199 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Search.gif.vir
2005-10-19 15:17:58 . 2005-10-19 15:17:58 73,728 -c–a-w- I:\Qoobox\Quarantine\I\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll.vir
2005-03-31 16:30:54 . 2005-03-31 16:30:54 90 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\plusbox.gif.vir
2005-03-31 16:30:52 . 2005-03-31 16:30:52 86 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\minusbox.gif.vir
2005-03-31 16:29:36 . 2005-03-31 16:29:36 96 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\beginplus.gif.vir
2005-03-31 16:29:26 . 2005-03-31 16:29:26 57 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\blank.gif.vir
2005-03-31 16:29:16 . 2005-03-31 16:29:16 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\blankdots.gif.vir
2005-03-31 16:29:02 . 2005-03-31 16:29:02 75 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\dots.gif.vir
2005-03-31 16:28:48 . 2005-03-31 16:28:48 70 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\lastdots.gif.vir
2005-03-31 16:28:38 . 2005-03-31 16:28:38 93 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\lastminus.gif.vir
2005-03-31 16:28:26 . 2005-03-31 16:28:26 97 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\lastplus.gif.vir
2005-03-31 16:28:12 . 2005-03-31 16:28:12 95 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\minus.gif.vir
2005-03-31 16:27:38 . 2005-03-31 16:27:38 98 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\plus.gif.vir
2005-03-31 16:27:14 . 2005-03-31 16:27:14 89 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\singleminus.gif.vir
2005-03-31 16:27:00 . 2005-03-31 16:27:00 93 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\singleplus.gif.vir
2005-03-31 16:24:54 . 2005-03-31 16:24:54 91 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\beginminus.gif.vir
2005-03-31 16:23:34 . 2005-03-31 16:23:34 74 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\begindots.gif.vir
2004-07-15 22:37:30 . 2004-07-15 22:37:30 1,251 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\first_over.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 78 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\First.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 78 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Firstd.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 79 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Last.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 79 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Lastd.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 1,251 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\last_over.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Next.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Nextd.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 1,252 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\next_over.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Prev.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Prevd.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 1,250 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\prev_over.gif.vir
2004-07-12 00:24:44 . 2002-06-04 11:01:36 44,032 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\28_83260.dll.vir
2004-07-12 00:24:44 . 2002-06-04 11:01:36 84,992 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\14_43260.dll.vir
2004-05-06 01:15:00 . 2004-05-06 01:15:00 176 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\gotopaged.gif.vir
2003-11-24 20:41:24 . 2003-11-24 20:41:24 96 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\Magnify.gif.vir
1999-12-07 04:00:00 . 1999-12-07 04:00:00 24,956 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\twain_16.dll.vir


Old Timer Log

All processes killed
========== FILES ==========
File\Folder I:\data Infected not found.
I:\Documents and Settings\Larry\My Documents\My Received Files\BSINSTALL.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Larry
->Temp folder emptied: 19230700 bytes
->Temporary Internet Files folder emptied: 26374320 bytes
->Java cache emptied: 15671506 bytes
->FireFox cache emptied: 46404373 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 65670 bytes
->FireFox cache emptied: 520993 bytes

User: NetworkService
->Temp folder emptied: 16384 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: visual basic
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 795 bytes
->Java cache emptied: 53355 bytes
->FireFox cache emptied: 18695058 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1138395 bytes
%systemroot%\System32 .tmp files removed: 2673152 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33726 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 124.85 mb


OTL by OldTimer - Version 3.1.12.0 log created on 12092009_210341

Files\Folders moved on Reboot…
File\Folder I:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_c2c.dat not found!

Registry entries deleted on Reboot…
Hi Larryri42,

Strange it shows in your DDS uninstall list.

In OTL copy and paste this fix.

:Files
I:\data

Click the RunFix button.

Next

I forgot you have windows installed on I:\ instead of C:\. We'll restore a file from quarantine.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DEQUARANTINE::
I:\Qoobox\Quarantine\c\program files\ATI Technologies\ATI.ACE\Core-Static\atIAcmxx.dll.vir 

Quit::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Only a DeQuarantine.txt will be produced, please post it's contents along with the OTL fix results.

Thanks
hi OldMan960,

Just want to Thank you for helping me with all of this as well. :) attached is a pick of my add and remove programs application. I think it would be there. Is there anywhere else i should look for it as well?


OTL Log

========== FILES ==========
I:\data moved successfully.

OTL by OldTimer - Version 3.1.12.0 log created on 12092009_230215

here is the I:\Qoobox\ComboFix-quarantined-files.txt

2009-12-08 04:19:11 . 2009-12-10 04:07:38 0 -c–a-w- I:\Qoobox\Quarantine\catchme.txt
2009-12-07 22:06:30 . 2009-12-07 22:06:30 564 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\AddRemove-UT2004.reg.dat
2009-12-07 22:06:30 . 2009-12-07 22:06:30 784 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\AddRemove-Tweak UI 2.10.reg.dat
2009-12-07 22:06:30 . 2009-12-07 22:06:30 658 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\AddRemove-Citrix Program Neighborhood.reg.dat
2009-12-07 22:06:30 . 2009-12-07 22:06:30 556 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\AddRemove-abgx360.reg.dat
2009-12-07 22:06:07 . 2009-12-07 22:06:07 90 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Aim6.reg.dat
2009-12-07 21:46:43 . 2009-12-07 21:46:43 2,036 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\Service_NPF.reg.dat
2009-12-07 21:46:22 . 2009-12-10 04:14:32 11,882 -c–a-w- I:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2009-12-07 21:32:58 . 2009-12-10 04:06:29 357 -c–a-w- I:\Qoobox\Quarantine\catchme.log
2008-04-10 17:42:22 . 1999-08-18 14:54:22 180,224 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\ijl11.dll.vir
2007-09-07 16:02:22 . 2007-09-07 16:02:22 1,787 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\crlogo.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 273 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\printd.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 134 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\refreshd.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 1,236 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\refresh_over.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 274 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\searchd.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 1,205 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\search_over.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 122 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\up.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 898 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\upd.gif.vir
2007-05-27 04:02:52 . 2007-05-27 04:02:52 1,244 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\up_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 84 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\calendar.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 617 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\export.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 283 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\exportd.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 1,244 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\export_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 595 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\gotopage.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 1,226 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\gotopage_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 257 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\grouptree.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 230 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\grouptreed.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 179 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\grouptreepressed.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 1,215 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\grouptree_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 375 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\print.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 1,219 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\print_over.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 134 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Refresh.gif.vir
2007-05-27 04:02:50 . 2007-05-27 04:02:50 199 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Search.gif.vir
2005-10-19 15:17:58 . 2005-10-19 15:17:58 73,728 -c–a-w- I:\Qoobox\Quarantine\I\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll.vir
2005-03-31 16:30:54 . 2005-03-31 16:30:54 90 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\plusbox.gif.vir
2005-03-31 16:30:52 . 2005-03-31 16:30:52 86 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\minusbox.gif.vir
2005-03-31 16:29:36 . 2005-03-31 16:29:36 96 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\beginplus.gif.vir
2005-03-31 16:29:26 . 2005-03-31 16:29:26 57 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\blank.gif.vir
2005-03-31 16:29:16 . 2005-03-31 16:29:16 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\blankdots.gif.vir
2005-03-31 16:29:02 . 2005-03-31 16:29:02 75 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\dots.gif.vir
2005-03-31 16:28:48 . 2005-03-31 16:28:48 70 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\lastdots.gif.vir
2005-03-31 16:28:38 . 2005-03-31 16:28:38 93 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\lastminus.gif.vir
2005-03-31 16:28:26 . 2005-03-31 16:28:26 97 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\lastplus.gif.vir
2005-03-31 16:28:12 . 2005-03-31 16:28:12 95 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\minus.gif.vir
2005-03-31 16:27:38 . 2005-03-31 16:27:38 98 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\plus.gif.vir
2005-03-31 16:27:14 . 2005-03-31 16:27:14 89 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\singleminus.gif.vir
2005-03-31 16:27:00 . 2005-03-31 16:27:00 93 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\singleplus.gif.vir
2005-03-31 16:24:54 . 2005-03-31 16:24:54 91 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\beginminus.gif.vir
2005-03-31 16:23:34 . 2005-03-31 16:23:34 74 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\begindots.gif.vir
2004-07-15 22:37:30 . 2004-07-15 22:37:30 1,251 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\first_over.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 78 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\First.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 78 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Firstd.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 79 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Last.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 79 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Lastd.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 1,251 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\last_over.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Next.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Nextd.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 1,252 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\next_over.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Prev.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 73 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\Prevd.gif.vir
2004-07-13 23:49:12 . 2004-07-13 23:49:12 1,250 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\prev_over.gif.vir
2004-07-12 00:24:44 . 2002-06-04 11:01:36 44,032 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\28_83260.dll.vir
2004-07-12 00:24:44 . 2002-06-04 11:01:36 84,992 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\14_43260.dll.vir
2004-05-06 01:15:00 . 2004-05-06 01:15:00 176 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\toolbar\gotopaged.gif.vir
2003-11-24 20:41:24 . 2003-11-24 20:41:24 96 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\system32\images\tree\Magnify.gif.vir
1999-12-07 04:00:00 . 1999-12-07 04:00:00 24,956 -c–a-w- I:\Qoobox\Quarantine\I\WINDOWS\twain_16.dll.vir

Attachments:

Hi Larryri42,

You are right, it's not there. don't know why it showed in the Attach log. That's the only place it should be.

Let's try this again

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DEQUARANTINE::
I:\Qoobox\Quarantine\I\program files\ATI Technologies\ATI.ACE\Core-Static\atIAcmxx.dll.vir 

Quit::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Only a DeQuarantine.txt will be produced, please post it.

Thanks
Hi Oldman960,

For some reason after i drag and drop the CFSricpt file into the Combofix application it runs the scan again but instead of giving me a DeQuarantine.txt file it gives me a regular log.txt file. i went into I:\Qoobox and dont see one in there either. i do however see a folder called Quarantine that has the ATI info in there.

ComboFix 09-12-09.04 - Larry 12/10/2009 8:54.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1232 [GMT -5:00]
Running from: i:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: i:\documents and settings\Larry\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 )))))))))))))))))))))))))))))))
.

2009-12-10 02:03 . 2009-12-10 02:03 ——– dc—-w- I:\_OTL
2009-12-10 00:41 . 2009-12-10 00:43 ——– dc—-w- I:\Fall09Temp
2009-12-08 04:48 . 2009-12-08 04:48 4844296 -c–a-w- i:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-07 21:28 . 2009-12-07 21:28 194464 -c–a-w- i:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-04 13:46 . 2009-12-04 13:46 ——– dc—-w- i:\documents and settings\LocalService\Local Settings\Application Data\IsolatedStorage
2009-12-04 13:41 . 2009-12-04 13:41 ——– dc—-w- i:\documents and settings\Larry\Local Settings\Application Data\IsolatedStorage
2009-12-03 23:38 . 2009-12-03 23:38 81920 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connecthook.dll
2009-12-03 23:38 . 2009-12-03 23:38 158720 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectsprd.dll
2009-12-03 23:38 . 2009-12-03 23:38 3553680 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectaddin6x5.exe
2009-12-03 13:44 . 2008-08-19 14:46 1848608 -c–a-w- i:\windows\system32\acXMLParser.dll
2009-12-03 13:44 . 2008-08-19 14:46 3523872 -c–a-w- i:\windows\system32\cdintf300.dll
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\HaB\Custom\billmind.exe
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\RPM\Custom\billmind.exe
2009-12-03 13:44 . 2008-08-19 14:44 25888 -c–a-w- i:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\Premier\Custom\billmind.exe
2009-12-03 13:44 . 2009-12-03 13:44 ——– dc—-w- i:\program files\Quicken
2009-12-03 01:04 . 2009-12-03 01:44 34816 -c–a-w- i:\windows\system32\drivers\rootrepeal2.sys
2009-12-03 00:54 . 2009-12-03 00:54 ——– dc—-w- i:\windows\BACKUPERDNT
2009-12-03 00:53 . 2009-12-03 00:53 ——– dc—-w- i:\program files\ERUNT
2009-12-02 15:28 . 2009-12-02 15:28 ——– dc—-w- i:\program files\Common Files\AnswerWorks 4.0
2009-12-02 14:43 . 2009-12-02 14:43 ——– dc—-w- i:\program files\Arise
2009-12-02 14:24 . 2009-12-03 21:14 38224 -c–a-w- i:\windows\system32\drivers\mbamswissarmy.sys
2009-12-02 14:24 . 2009-12-03 21:13 19160 -c–a-w- i:\windows\system32\drivers\mbam.sys
2009-12-02 14:24 . 2009-12-08 04:48 ——– dc—-w- i:\program files\Malwarebytes' Anti-Malware
2009-12-01 02:39 . 2009-12-01 03:17 ——– dc—-w- i:\documents and settings\Larry\Local Settings\Application Data\smsgij
2009-11-24 13:37 . 2009-12-09 16:25 86016 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\meetingconvertor.dll
2009-11-24 13:37 . 2009-12-09 16:25 81920 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connecthook.dll
2009-11-24 13:37 . 2009-12-09 16:25 303104 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectsprd.dll
2009-11-24 05:08 . 2009-11-24 05:08 ——– dc—-w- i:\program files\QuickTime
2009-11-23 20:15 . 2009-11-23 20:15 4736992 -c–a-w- i:\documents and settings\Larry\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe
2009-11-21 16:15 . 2009-11-21 16:14 411368 -c–a-w- i:\windows\system32\deploytk.dll
2009-11-21 16:14 . 2009-11-21 16:14 152576 -c–a-w- i:\documents and settings\Larry\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-12 14:24 . 2009-11-10 14:12 4026136 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-11-12 14:23 . 2009-11-10 14:12 2016536 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-11-12 14:23 . 2009-11-10 14:12 1257240 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2009-11-12 14:23 . 2009-11-12 14:22 3963648 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-12 14:23 . 2009-11-12 14:22 497944 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2009-11-10 14:11 . 2009-11-10 14:11 1657112 -c–a-w- i:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-10 13:54 . 2009-02-13 03:50 ——– dc—-w- i:\program files\LogMeIn
2009-12-10 02:14 . 2007-05-12 03:10 ——– dc—-w- i:\program files\Windows Desktop Search
2009-12-10 00:58 . 2006-06-04 00:28 ——– dc—-w- i:\documents and settings\Larry\Application Data\uTorrent
2009-12-09 21:27 . 2009-05-12 20:46 ——– dc—-w- i:\documents and settings\All Users\Application Data\Google Updater
2009-12-08 21:17 . 2004-06-04 02:13 ——– dc—-w- i:\program files\Java
2009-12-04 13:41 . 2008-03-02 16:35 ——– dc—-w- i:\program files\TurboTax
2009-12-04 13:36 . 2007-01-28 21:43 ——– dc—-w- i:\program files\Common Files\Intuit
2009-12-03 13:45 . 2009-03-09 23:33 ——– dc—-w- i:\program files\Common Files\AnswerWorks 5.0
2009-12-03 13:45 . 2004-03-22 01:19 ——– dc-h–w- i:\program files\InstallShield Installation Information
2009-12-03 13:44 . 2007-01-28 21:45 ——– dc—-w- i:\documents and settings\Larry\Application Data\Intuit
2009-12-03 13:43 . 2007-01-28 21:44 ——– dc—-w- i:\documents and settings\All Users\Application Data\Intuit
2009-12-02 13:53 . 2007-06-22 16:06 ——– dc—-w- i:\documents and settings\Larry\Application Data\Juniper Networks
2009-12-02 13:43 . 2006-07-28 22:21 ——– dc—-w- i:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-02 04:36 . 2007-06-22 16:25 38881 -c–a-w- i:\documents and settings\Larry\Application Data\Juniper Networks\Host Checker\uninstall.exe
2009-11-24 14:33 . 2007-06-22 16:06 ——– dc—-w- i:\program files\Juniper Networks
2009-11-10 14:12 . 2009-04-08 23:20 360584 -c–a-w- i:\windows\system32\drivers\avgtdix.sys
2009-11-09 15:22 . 2009-04-08 23:20 12464 -c–a-w- i:\windows\system32\avgrsstx.dll
2009-11-09 15:22 . 2009-04-08 23:20 333192 -c–a-w- i:\windows\system32\drivers\avgldx86.sys
2009-11-09 15:22 . 2009-04-08 23:20 28424 -c–a-w- i:\windows\system32\drivers\avgmfx86.sys
2009-11-09 15:21 . 2009-11-09 15:21 ——– dc—-w- i:\documents and settings\All Users\Application Data\avg9
2009-11-09 15:21 . 2009-04-08 23:20 ——– dc—-w- i:\program files\AVG
2009-11-05 21:04 . 2009-11-05 21:03 ——– dc—-w- i:\program files\iTunes
2009-11-05 21:03 . 2009-11-05 21:03 ——– dc—-w- i:\program files\iPod
2009-11-05 21:03 . 2007-10-17 23:07 ——– dc—-w- i:\program files\Common Files\Apple
2009-11-05 20:57 . 2009-11-05 20:57 79144 -c–a-w- i:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-03 01:39 . 2004-03-21 01:14 ——– dc—-w- i:\program files\SlySoft
2009-11-02 05:12 . 2009-10-30 19:04 ——– dc—-w- i:\program files\DVDneXtCOPY3
2009-10-30 19:04 . 2009-10-30 18:48 ——– dc—-w- i:\program files\Common Files\DistributeShield
2009-10-27 11:37 . 2004-07-07 13:50 92920 -c–a-w- i:\documents and settings\Larry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-27 07:27 . 2006-10-31 03:28 96256 —-a-w- i:\windows\system32\drivers\sptd4045.sys
2009-10-27 07:06 . 2007-04-06 15:03 ——– dc—-w- i:\program files\Microsoft Works
2009-10-27 07:03 . 2006-07-28 22:21 ——– dc—-w- i:\program files\Microsoft Visual Studio 8
2009-10-25 06:50 . 2009-05-25 22:13 ——– dc—-w- i:\program files\abgx360
2009-10-22 01:42 . 2009-10-22 01:40 ——– dc—-w- i:\program files\NetBeans 6.0.1
2009-10-22 01:41 . 2009-10-22 01:41 ——– dc—-w- i:\program files\Apache Software Foundation
2009-10-19 13:47 . 2009-10-19 13:47 6 -c–a-w- i:\windows\Fonts\wfonts.key
2009-10-15 22:02 . 2009-10-15 22:02 ——– dc—-w- i:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-14 07:16 . 2006-07-28 22:41 ——– dc—-w- i:\program files\Microsoft SQL Server
2009-10-14 07:09 . 2009-02-20 03:26 18368 -c–a-w- i:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2009-10-14 07:09 . 2009-02-20 03:26 1680064 -c–a-w- i:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2009-10-01 15:36 . 2009-02-13 03:51 83288 —-a-w- i:\windows\system32\LMIRfsClientNP.dll
2009-10-01 15:36 . 2009-02-13 03:51 28984 -c–a-w- i:\windows\system32\LMIport.dll
2009-10-01 15:36 . 2009-02-13 03:51 87352 —-a-w- i:\windows\system32\LMIinit.dll
2009-09-30 18:56 . 2009-09-30 18:56 73880 -c-ha-w- i:\windows\system32\mlfcache.dat
2009-09-24 22:59 . 2009-09-24 22:59 104512 -c–a-w- i:\windows\system32\drivers\AnyDVD.sys
2009-09-11 17:08 . 2009-09-11 17:08 24744 -c–a-w- i:\windows\system32\drivers\ElbyCDIO.sys
2009-09-11 14:33 . 2001-08-23 12:00 133632 —-a-w- i:\windows\system32\msv1_0.dll
2005-09-08 23:05 . 2008-05-21 21:41 24848 -c–a-w- i:\program files\mozilla firefox\plugins\cgpcfg.dll
2005-09-08 23:05 . 2008-05-21 21:41 74000 -c–a-w- i:\program files\mozilla firefox\plugins\cgpcore.dll
2005-09-08 23:05 . 2008-05-21 21:41 45328 -c–a-w- i:\program files\mozilla firefox\plugins\icalogon.dll
2005-09-08 23:05 . 2008-05-21 21:41 28944 -c–a-w- i:\program files\mozilla firefox\plugins\pscript.dll
2005-09-08 23:05 . 2008-05-21 21:41 69904 -c–a-w- i:\program files\mozilla firefox\plugins\sslsdk_b.dll
2005-09-08 23:05 . 2008-05-21 21:41 24848 -c–a-w- i:\program files\mozilla firefox\plugins\tcppserv.dll
2005-07-14 18:31 . 2006-05-24 16:37 27648 -csha-w- i:\windows\system32\AVSredirect.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-12-07_21.55.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-10 02:14 . 2009-12-10 02:14 16384 i:\windows\Temp\Perflib_Perfdata_844.dat
+ 2001-08-23 12:00 . 2009-12-10 01:59 587860 i:\windows\system32\perfh009.dat
+ 2001-08-23 12:00 . 2009-12-10 01:59 131690 i:\windows\system32\perfc009.dat
+ 2009-12-10 02:21 . 2009-12-10 02:21 245760 i:\windows\ERDNT\AutoBackup\12-9-2009\Users\00000002\UsrClass.dat
+ 2009-12-10 02:21 . 2005-10-20 17:02 163328 i:\windows\ERDNT\AutoBackup\12-9-2009\ERDNT.EXE
+ 2009-12-08 21:25 . 2009-12-08 21:25 245760 i:\windows\ERDNT\AutoBackup\12-8-2009\Users\00000002\UsrClass.dat
+ 2009-12-08 21:25 . 2005-10-20 17:02 163328 i:\windows\ERDNT\AutoBackup\12-8-2009\ERDNT.EXE
+ 2009-12-10 02:21 . 2009-12-10 02:21 13185024 i:\windows\ERDNT\AutoBackup\12-9-2009\Users\00000001\ntuser.dat
+ 2009-12-08 21:25 . 2009-12-08 21:25 13168640 i:\windows\ERDNT\AutoBackup\12-8-2009\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="i:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-01-04 1937408]
"swg"="i:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
"WMPNSCFG"="i:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="i:\program files\ATI Technologies\ATI.ACE\cli.exe runtime -Delay" [X]
"SSBkgdUpdate"="i:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot" [X]
"PPort11reminder"="i:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe -r" [X]
"QuickTime Task"="i:\program files\QuickTime\QTTask.exe -atboottime" [X]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"nwiz"="nwiz.exe" [2005-04-01 1495040]
"RoxioEngineUtility"="i:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"WatchDog"="i:\program files\mobile PhoneTools\WatchDog.exe" [2004-08-14 36864]
"NeroFilterCheck"="i:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"NvMediaCenter"="i:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"CloneCDTray"="i:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 57344]
"GrooveMonitor"="i:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"PaperPort PTD"="i:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-30 30248]
"IndexSearch"="i:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-30 46632]
"BrMfcWnd"="i:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-23 663552]
"ControlCenter3"="i:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"LogMeIn GUI"="i:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"iTunesHelper"="i:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"AVG9_TRAY"="i:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-12 2020120]
"SunJavaUpdateSched"="i:\program files\Java\jre6\bin\jusched.exe" [2009-11-21 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="i:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe -t" [X]

i:\documents and settings\Larry\Start Menu\Programs\Startup\
Adobe Gamma.lnk - i:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
ERUNT AutoBackup.lnk - i:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - i:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-09 15:22 12464 -c–a-w- i:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-01 15:36 87352 —-a-w- i:\windows\system32\LMIinit.dll

[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
backup=i:\windows\pss\Windows Desktop Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
i:\program files\DAEMON Tools\daemon.exe -lang 1033 [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
i:\program files\QuickTime\qttask.exe -atboottime [X]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"i:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"i:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"i:\\Program Files\\Messenger\\msmsgs.exe"=
"i:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"i:\\Program Files\\AIM\\aim.exe"=
"i:\program files\Microsoft ActiveSync\rapimgr.exe"= i:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"i:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"i:\\Program Files\\Citrix\\ICA Client\\pn.exe"=
"i:\\WINDOWS\\system32\\sessmgr.exe"=
"i:\\Documents and Settings\\Larry\\taw\\winvnc.exe"=
"i:\\Program Files\\AIM6\\aim6.exe"=
"i:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"i:\\Program Files\\MSN Messenger\\livecall.exe"=
"i:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"i:\\Program Files\\Brother\\Brmfl07a\\FAXRX.exe"=
"i:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"i:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"i:\\Program Files\\LimeWire\\LimeWire.exe"=
"i:\\Program Files\\Trillian\\trillian.exe"=
"i:\\Program Files\\uTorrent\\uTorrent.exe"=
"i:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"i:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"i:\\Program Files\\iTunes\\iTunes.exe"=
"i:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"i:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"i:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"i:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"54925:UDP"= 54925:UDP:Brother Network Scanner
"55270:UDP"= 55270:UDP:Utorrent
"55270:TCP"= 55270:TCP:Utorrent

R1 AvgLdx86;AVG Free AVI Loader Driver x86;i:\windows\system32\drivers\avgldx86.sys [4/8/2009 6:20 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;i:\windows\system32\drivers\avgtdix.sys [4/8/2009 6:20 PM 360584]
R1 NEOFLTR_550_12129;Juniper Networks TDI Filter Driver (NEOFLTR_550_12129);i:\windows\system32\drivers\NEOFLTR_550_12129.sys [10/3/2007 3:20 PM 63008]
R2 avg9wd;AVG Free WatchDog;i:\program files\AVG\AVG9\avgwdsvc.exe [11/9/2009 10:21 AM 285392]
R2 LMIInfo;LogMeIn Kernel Information Provider;i:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;i:\windows\system32\drivers\LMIRfsDriver.sys [2/12/2009 10:51 PM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;i:\program files\Viewpoint\Common\ViewpointService.exe [7/3/2009 3:59 PM 24652]
R3 portio32;portio32;i:\windows\system32\drivers\portio32.sys [9/7/2009 2:19 PM 2048]
S2 gupdate1c9d3431ddff9c6;Google Update Service (gupdate1c9d3431ddff9c6);i:\program files\Google\Update\GoogleUpdate.exe [5/12/2009 3:49 PM 133104]
S3 rootrepeal2;rootrepeal2;i:\windows\system32\drivers\rootrepeal2.sys [12/2/2009 8:04 PM 34816]
S3 vaxscsi;vaxscsi;i:\windows\system32\drivers\vaxscsi.sys [10/30/2006 10:30 PM 223128]
S4 a347bus;a347bus;i:\windows\system32\drivers\a347bus.sys [11/2/2006 9:20 PM 160640]
S4 a347scsi;a347scsi;i:\windows\system32\drivers\a347scsi.sys [11/2/2006 9:20 PM 5248]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 sptd;sptd;i:\windows\system32\drivers\sptd.sys [10/30/2006 10:28 PM 643072]
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki… - i:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: arise.com
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
Trusted Zone: willowcsn.com\cybercentral
DPF: Microsoft XML Parser for Java - file:///I:/WINDOWS/Java/classes/xmldso.cab
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://asp23.centra.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
FF - ProfilePath - i:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\uz0fyw53.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://admintools.ariasystems.net/dashboard-idp/auth/login-aria.php?RelayState=https%3A%2F%2Fadmintools.ariasystems.net%3A443%2Fdashboard-idp%2Fsaml2%2Fidp%2FSSOService.php%3FRequestID%3D_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&spentityid=admintools.ariasystems.net&AuthId=_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&protocol=saml2&timeout=0
FF - component: i:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: i:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: i:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: i:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npican.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: i:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - i:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
i:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-10 09:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:00000003

[HKEY_USERS\S-1-5-21-1659004503-1897051121-839522115-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(804)
i:\windows\system32\Ati2evxx.dll
i:\windows\system32\LMIinit.dll

- - - - - - - > 'explorer.exe'(4556)
i:\windows\system32\WININET.dll
i:\windows\system32\ieframe.dll
i:\windows\system32\WPDShServiceObj.dll
i:\windows\system32\PortableDeviceTypes.dll
i:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-12-10 09:05:44
ComboFix-quarantined-files.txt 2009-12-10 14:05
ComboFix2.txt 2009-12-10 04:20
ComboFix3.txt 2009-12-09 14:31
ComboFix4.txt 2009-12-08 04:37
ComboFix5.txt 2009-12-10 13:52

Pre-Run: 44,593,065,984 bytes free
Post-Run: 44,586,250,240 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 04C3CBB6031996C7204229720A57F7E1

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI