This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer slow, IE, Windows Mail, Mozilla all lag

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi y'all! I am not even sure my PC has an infection but I am at wit's end. The PC is lagging, IE, Mozilla, Windows mail, etc all open very slowly and hang up at times. I have defragged, optimized my registry, eliminated unneeded start up programs, run Spybot, etc but nothing seems to be helping so I thought maybe there is an infection or something. My internet speed seems ok, the hardware seems ok so I figure something must be fouled up in the processed or registry? Here is the requested info and I would appreciate it if y'all would take a look and if you have any idea what's going on, help me out. I was a member of this board a few years back but had to re-register for some reason…Thanks in advance!! :blush:

Root Repeal Report

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/12/06 13:30
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
——————-
Name: PCI_NTPNP6460
Image Path: \Driver\PCI_NTPNP6460
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAF10A000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
——————-
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\drivers\iksysflt.sys" at address 0xb45307a6

#: 047 Function Name: NtCreateProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\iksysflt.sys" at address 0xb452d794

#: 048 Function Name: NtCreateProcessEx
Status: Hooked by "C:\WINDOWS\system32\drivers\iksysflt.sys" at address 0xb452df1e

#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\drivers\iksysflt.sys" at address 0xb45311f0

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\drivers\iksysflt.sys" at address 0xb453142a

#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf74f2fb2

#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf74f3340

#: 119 Function Name: NtOpenKey
Status: Hooked by "sptd.sys" at address 0xf74ed0b0

#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf74f3418

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "sptd.sys" at address 0xf74f3298

#: 192 Function Name: NtRenameKey
Status: Hooked by "C:\WINDOWS\system32\drivers\iksysflt.sys" at address 0xb453212a

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\drivers\iksysflt.sys" at address 0xb453183c

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\iksysflt.sys" at address 0xb452cd0a

#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\iksysflt.sys" at address 0xb452c384

==EOF==

DDS TEXT


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 13:35:32.57 on Sun 12/06/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1324 [GMT -6:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Advanced Registry Doctor\RegManServ.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Mary\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = www.excite.com/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
uWindow Title = MSIE
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No File
TB: {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - No File
EB: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\mary\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
uPolicies-explorer: NoInstrumentation = 1 (0x1)
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoThumbnailCache = 1 (0x1)
uPolicies-explorer: HideClock = 0 (0x0)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: { - c:\program files\messenger\msmsgs.exe
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - c:\program files\eltima software\flash decompiler trillix\saveflash\iebt.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: excite.com\www
Trusted Zone: turbotax.com
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {4CCA4E6B-9259-11D9-AC6E-444553544200} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01.cab
DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A8739816-022C-11D6-A85D-00C04F9AEAFB} - hxxp://www.mikethetiger.com/cam/wg_webeye.cab
DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} - hxxp://ak.imgag.com/imgag/cp/install/Crusher.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} - hxxp://messenger.zone.msn.com/binary/Chess.cab57176.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://www.driveragent.com/files/driveragent.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech remote\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\mary\applic~1\mozilla\firefox\profiles\4rilgvt8.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.excite.com/
FF - component: c:\documents and settings\mary\application data\mozilla\firefox\profiles\4rilgvt8.default\extensions\{2bae58c2-79f9-45d1-a286-81f911301c3a}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\mary\application data\mozilla\firefox\profiles\4rilgvt8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\mary\application data\mozilla\firefox\profiles\4rilgvt8.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\mary\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\google updater\1.4.661.11671\npCIDetect7.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 600000
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: network.prefetch-next - true
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - false
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - true
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 hotcore2;hotcore2;c:\windows\system32\drivers\hotcore2.sys [2007-3-3 30808]
R0 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-5-5 42376]
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [2007-3-26 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [2007-3-26 52224]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2006-10-18 17920]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-8 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-9-14 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-8 108552]
R1 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-5-5 66952]
R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-5-5 81288]
R1 PStrip;PStrip;c:\windows\system32\drivers\PStrip.sys [2004-11-9 21968]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [2007-10-3 85760]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared anti-malware\a2service.exe [2008-8-3 425080]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-3 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-6-8 297752]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2007-11-22 388936]
S1 SuperMounter;SuperMounter; [x]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-7 14336]
S3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\drivers\lne100v5.sys [2001-10-24 36224]
S3 S3chipid;S3chipid;c:\softpaq\sp26437\driver\s3chipid.sys [2003-1-23 3712]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-5-5 747912]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-5-5 948616]

============== File Associations ===============

JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1

=============== Created Last 30 ================

2009-12-03 20:00 –d—– c:\windows\system32\XPSViewer
2009-12-03 19:57 –d—– c:\docume~1\mary\applic~1\Windows Desktop Search
2009-12-03 19:56 –d—– c:\windows\system32\GroupPolicy
2009-12-03 19:56 1,374 a——- c:\windows\imsins.BAK
2009-12-03 19:54 192,000 -c—— c:\windows\system32\dllcache\offfilt.dll
2009-12-03 19:54 98,304 -c—— c:\windows\system32\dllcache\nlhtml.dll
2009-12-03 19:54 29,696 -c—— c:\windows\system32\dllcache\mimefilt.dll
2009-12-03 19:53 –d—– c:\windows\system32\URTTemp
2009-12-03 00:07 –d—– c:\program files\Ashampoo
2009-12-02 23:52 –d—– c:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2009-12-02 23:52 –d—– c:\program files\NVIDIA Corporation
2009-12-02 23:51 8,743 a——- c:\windows\system32\nvinfo.pb
2009-12-02 23:51 2,259,560 a——- c:\windows\system32\nvcuvid.dll
2009-12-02 23:51 1,989,224 a——- c:\windows\system32\nvcuvenc.dll
2009-12-02 23:51 69,632 a——- c:\windows\system32\OpenCL.dll
2009-12-02 23:50 11,374,592 a——- c:\windows\system32\nvcompiler.dll
2009-12-02 23:50 2,293,286 a——- c:\windows\system32\nvdata.bin
2009-12-02 23:47 –d—– c:\program files\SystemRequirementsLab
2009-11-20 20:32 12,669,544 a——- c:\windows\system32\nvcpl.dll
2009-11-20 20:32 278,120 a——- c:\windows\system32\nvmccs.dll
2009-11-20 20:32 154,216 a——- c:\windows\system32\nvsvc32.exe
2009-11-20 20:32 145,000 a——- c:\windows\system32\nvcolor.exe
2009-11-20 20:32 110,184 a——- c:\windows\system32\nvmctray.dll
2009-11-20 20:32 81,920 a——- c:\windows\system32\nvwddi.dll
2009-11-20 20:32 262,558 a——- c:\windows\system32\NvApps.xml
2009-11-20 20:32 64,882 a——- c:\windows\system32\NvwsApps.xml
2009-11-10 23:08 94,208 a——- c:\windows\system32\QuickTimeVR.qtx
2009-11-10 23:08 69,632 a——- c:\windows\system32\QuickTime.qts
2009-11-10 14:45 –d—– c:\program files\iPod

==================== Find3M ====================

2009-11-20 20:34 592,488 ac—— c:\windows\system32\nvudisp.exe
2009-11-20 20:34 13,602,816 a——- c:\windows\system32\nvoglnt.dll
2009-11-20 20:34 10,235,968 a——- c:\windows\system32\drivers\nv4_mini.sys
2009-11-20 20:34 6,282,752 a——- c:\windows\system32\nv4_disp.dll
2009-11-20 20:34 4,038,656 a——- c:\windows\system32\nvcuda.dll
2009-11-20 20:34 1,056,768 a——- c:\windows\system32\nvapi.dll
2009-11-20 20:34 182,888 a——- c:\windows\system32\nvcodins.dll
2009-11-20 20:34 182,888 a——- c:\windows\system32\nvcod.dll
2009-11-19 21:42 592,488 ac—— c:\windows\system32\NVUNINST.EXE
2009-10-11 04:17 411,368 a——- c:\windows\system32\deploytk.dll
2009-10-08 14:57 611,328 a——- c:\windows\system32\uiautomationcore.dll
2009-10-08 14:57 220,160 a——- c:\windows\system32\oleacc.dll
2009-10-08 14:56 20,480 a——- c:\windows\system32\oleaccrc.dll
2009-09-11 08:18 136,192 a——- c:\windows\system32\msv1_0.dll
2006-06-07 18:37 761 ac—— c:\program files\INSTALL.LOG
2005-07-09 16:33 774,144 ac—— c:\program files\RngInterstitial.dll
2002-07-01 08:13 218 ac-sh— c:\docume~1\alluse~1\applic~1\databack.dat
2001-09-17 04:45 127 ac—— c:\program files\setup.bat
2001-09-17 04:44 1,007,761 ac—— c:\program files\unpack.exe
2001-09-17 04:43 47,385,544 ac—— c:\program files\Hoyle Card Games 5.prf
2001-08-20 09:47 4,657,152 ac—— c:\program files\CardGames.exe
2001-08-20 09:44 149,431 ac—— c:\program files\strings.txt
2001-08-17 09:55 2,420,981 ac—— c:\program files\CARD.HLP
2001-08-13 16:21 8,153 ac—— c:\program files\Readme.txt
2001-08-08 12:46 248,179 ac—— c:\program files\Bonus.prf
2001-07-13 09:55 27,648 ac—— c:\program files\startw.exe
2001-07-05 14:39 2,645 ac—— c:\program files\Sierra.inf
2001-07-03 14:26 80 ac—— c:\program files\LANGUAGE.INF
2001-07-03 14:02 782,336 ac—— c:\program files\Hoyle_Card_Games.exe
2001-06-20 13:47 31,991 ac—— c:\program files\autorun.txt
2001-06-18 16:14 75 ac—— c:\program files\autorun.ini
2001-05-09 09:49 176,128 ac—— c:\program files\INSTAIDE.DLL
2001-01-04 15:19 4,710 ac—— c:\program files\HCG5.ico
2000-09-12 14:17 27,374 ac—— c:\program files\habits.prf
2000-07-06 09:17 91,279 ac—— c:\program files\fonts.prf
2000-03-18 02:29 49,152 ac—— c:\program files\INJECT.EXE
1999-12-01 15:47 758 ac—— c:\program files\Hoyle Auto run.prf
1997-12-24 10:45 105,472 ac—— c:\program files\SOS9503.DLL
2002-07-31 18:55 108 —sh— c:\windows\WSYS049.SYS
2008-09-08 18:14 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090820080909\index.dat

============= FINISH: 13:36:16.96 ===============

Attachments:

  • [attachment removed: Attach.zip]
Hi,

Please do the following:

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thanks for your reply. I was happy to see that someone replied! Here are the results from the GMER scan. Thanks!!!

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-20 11:14:25
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Mary\LOCALS~1\Temp\uxldapob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateKey [0xB49977A6]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0xB4994794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0xB4994F1E]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteKey [0xB49981F0]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteValueKey [0xB499842A]
SSDT sptd.sys ZwEnumerateKey [0xF74F2FB2]
SSDT sptd.sys ZwEnumerateValueKey [0xF74F3340]
SSDT sptd.sys ZwOpenKey [0xF74ED0B0]
SSDT sptd.sys ZwQueryKey [0xF74F3418]
SSDT sptd.sys ZwQueryValueKey [0xF74F3298]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwRenameKey [0xB499912A]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwSetValueKey [0xB499883C]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwTerminateProcess [0xB4993D0A]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwWriteVirtualMemory [0xB4993384]

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8ABC61E8
Device \FileSystem\Fastfat \FatCdrom 8A9DD1E8

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\NetBT \Device\NetBT_Tcpip_{891AB3C2-FC95-4109-BB79-B88CF7902CEA} 8A4851E8
Device \Driver\usbuhci \Device\USBPDO-0 8A9681E8
Device \Driver\usbuhci \Device\USBPDO-1 8A9681E8
Device \Driver\usbuhci \Device\USBPDO-2 8A9681E8
Device \Driver\usbuhci \Device\USBPDO-3 8A9681E8
Device \Driver\usbehci \Device\USBPDO-4 8A9511E8

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Ftdisk \Device\HarddiskVolume1 8AB5B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8AB5B1E8
Device \Driver\Cdrom \Device\CdRom0 8A96D1E8
Device \Driver\atapi \Device\Ide\IdePort0 [F7858B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7858B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F7858B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7858B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\ViPrt \Device\Ide\ViaIdePort0 8ABC71E8
Device \Driver\ViPrt \Device\Ide\ViaIdePort1 8ABC71E8
Device \Driver\USBSTOR \Device\00000080 8A2DF1E8
Device \Driver\USBSTOR \Device\00000081 8A2DF1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A4851E8
Device \Driver\NetBT \Device\NetbiosSmb 8A4851E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{9D8F3301-AE54-425D-9F2C-779F37A64487} 8A4851E8

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBFDO-0 8A9681E8
Device \Driver\usbuhci \Device\USBFDO-1 8A9681E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A31A1E8
Device \Driver\usbuhci \Device\USBFDO-2 8A9681E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A31A1E8
Device \Driver\usbuhci \Device\USBFDO-3 8A9681E8
Device \Driver\USBSTOR \Device\0000007d 8A2DF1E8
Device \Driver\usbehci \Device\USBFDO-4 8A9511E8
Device \Driver\Ftdisk \Device\FtControl 8AB5B1E8
Device \Driver\USBSTOR \Device\0000007e 8A2DF1E8
Device \Driver\USBSTOR \Device\0000007f 8A2DF1E8
Device \FileSystem\Fastfat \Fat 8A9DD1E8

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 8A0BB790

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Control\SecurePipeServers\winreg@Description Registry Server
Reg HKLM\SYSTEM\ControlSet001\Control\SecurePipeServers\winreg\AllowedPaths (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Control\SecurePipeServers\winreg\AllowedPaths@Machine System\CurrentControlSet\Control\ProductOptions?System\CurrentControlSet\Control\Print\Printers?System\CurrentControlSet\Control\Server Applications?System\CurrentControlSet\Services\Eventlog?Software\Microsoft\OLAP Server?Software\Microsoft\Windows NT\CurrentVersion?System\CurrentControlSet\Control\ContentIndex?System\CurrentControlSet\Control\Terminal Server?System\CurrentControlSet\Control\Terminal Server\UserConfig?System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration?
Reg HKLM\SYSTEM\ControlSet002\Control\SecurePipeServers\winreg@Description Registry Server
Reg HKLM\SYSTEM\ControlSet002\Control\SecurePipeServers\winreg\AllowedPaths (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\SecurePipeServers\winreg\AllowedPaths@Machine System\CurrentControlSet\Control\ProductOptions?System\CurrentControlSet\Control\Print\Printers?System\CurrentControlSet\Control\Server Applications?System\CurrentControlSet\Services\Eventlog?Software\Microsoft\OLAP Server?Software\Microsoft\Windows NT\CurrentVersion?System\CurrentControlSet\Control\ContentIndex?System\CurrentControlSet\Control\Terminal Server?System\CurrentControlSet\Control\Terminal Server\UserConfig?System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration?
Reg HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg@Description Registry Server
Reg HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg\AllowedPaths
Reg HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg\AllowedPaths@Machine System\CurrentControlSet\Control\ProductOptions?System\CurrentControlSet\Control\Print\Printers?System\CurrentControlSet\Control\Server Applications?System\CurrentControlSet\Services\Eventlog?Software\Microsoft\OLAP Server?Software\Microsoft\Windows NT\CurrentVersion?System\CurrentControlSet\Control\ContentIndex?System\CurrentControlSet\Control\Terminal Server?System\CurrentControlSet\Control\Terminal Server\UserConfig?System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration?
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\ControlSet004\Control\SecurePipeServers\winreg@Description Registry Server
Reg HKLM\SYSTEM\ControlSet004\Control\SecurePipeServers\winreg\AllowedPaths (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Control\SecurePipeServers\winreg\AllowedPaths@Machine System\CurrentControlSet\Control\ProductOptions?System\CurrentControlSet\Control\Print\Printers?System\CurrentControlSet\Control\Server Applications?System\CurrentControlSet\Services\Eventlog?Software\Microsoft\OLAP Server?Software\Microsoft\Windows NT\CurrentVersion?System\CurrentControlSet\Control\ContentIndex?System\CurrentControlSet\Control\Terminal Server?System\CurrentControlSet\Control\Terminal Server\UserConfig?System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration?
Reg HKLM\SYSTEM\ControlSet005\Control\SecurePipeServers\winreg@Description Registry Server
Reg HKLM\SYSTEM\ControlSet005\Control\SecurePipeServers\winreg\AllowedPaths (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Control\SecurePipeServers\winreg\AllowedPaths@Machine System\CurrentControlSet\Control\ProductOptions?System\CurrentControlSet\Control\Print\Printers?System\CurrentControlSet\Control\Server Applications?System\CurrentControlSet\Services\Eventlog?Software\Microsoft\OLAP Server?Software\Microsoft\Windows NT\CurrentVersion?System\CurrentControlSet\Control\ContentIndex?System\CurrentControlSet\Control\Terminal Server?System\CurrentControlSet\Control\Terminal Server\UserConfig?System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration?
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\Implemented Categories\{F2BB56D1-DB07-11D1-AA6B-006097DB9539}
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\InprocServer32@ C:\Program Files\Microsoft Office\Office10\MSOWC.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\InprocServer32@InprocServer32 C84DVn-}f(YR]eAR6.jiOfficeWebComponents>P68C[E^qf(o_+L[xeX)y?
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\ProgID@ OWC.Spreadsheet.9
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\ToolboxBitmap32@ C:\PROGRA~1\MI1933~1\Office10\MSOWC.DLL, 1003
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\TypeLib@ {0002E540-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{114E2C3D-CC33-DA46-A1A8-3A0364D0BF84}\VersionIndependentProgID@ OWC.Spreadsheet
Reg HKLM\SOFTWARE\Classes\CLSID\{9230F769-4012-C78C-93F6-3830AEEA1402}\InprocServer32@ ole32.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\InprocServer32@ mscoree.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\InprocServer32\1.1.4322
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\InprocServer32\1.1.4322@ImplementedInThisVersion
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\InprocServer32\1.1.4322@ 1.1.4322
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\ProgID@ CorSymReader_SxS
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\Server@ diasymreader.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{BB791C78-91E0-DB32-3A99-5EA102B313A3}\TreatAs@ {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}
Reg HKCU\Software\Microsoft\Windows Live Mail@SqmSrvSuccessCount POP3 100499

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Download ComboFix from the following location:
Link 1


VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Thanks again for your reply. Here is the combofix text you requested:

ComboFix 09-12-21.01 - Mary 12/21/2009 19:29:37.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1524 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\HP_Owner\My Documents\autobackup.reg
c:\documents and settings\Mary\My Documents\autobackup.reg
c:\program files\INSTALL.LOG
c:\recycler\NPROTECT
c:\windows\patch.exe
c:\windows\system32\lo2.txtt
c:\windows\system32\ps2.bat
c:\windows\system32\skinboxer43.dll
c:\windows\system32\tmp.reg

.
((((((((((((((((((((((((( Files Created from 2009-11-22 to 2009-12-22 )))))))))))))))))))))))))))))))
.

2009-12-06 19:27 . 2009-12-06 19:27 ——– d—–w- c:\program files\ERUNT
2009-12-05 03:11 . 2009-12-05 03:11 ——– d—–w- c:\documents and settings\Mary\Local Settings\Application Data\eSupport.com
2009-12-05 03:00 . 2009-12-05 03:04 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2009-12-04 02:11 . 2009-12-04 02:13 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-12-04 02:00 . 2009-12-04 02:00 ——– d—–w- c:\windows\system32\XPSViewer
2009-12-04 02:00 . 2009-12-04 02:00 ——– d—–w- c:\program files\MSBuild
2009-12-04 01:57 . 2009-12-04 01:57 ——– d—–w- c:\documents and settings\Mary\Application Data\Windows Desktop Search
2009-12-04 01:56 . 2009-12-04 01:56 ——– d—–w- c:\windows\system32\GroupPolicy
2009-12-04 01:54 . 2008-03-07 17:02 98304 -c—-w- c:\windows\system32\dllcache\nlhtml.dll
2009-12-04 01:54 . 2008-03-07 17:02 29696 -c—-w- c:\windows\system32\dllcache\mimefilt.dll
2009-12-04 01:54 . 2008-03-07 17:02 192000 -c—-w- c:\windows\system32\dllcache\offfilt.dll
2009-12-04 01:53 . 2009-12-04 01:54 ——– d—–w- c:\windows\system32\URTTemp
2009-12-03 06:07 . 2009-12-03 06:07 ——– d—–w- c:\program files\Ashampoo
2009-12-03 05:52 . 2009-12-03 05:52 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-12-03 05:52 . 2009-12-03 05:52 ——– d—–w- c:\program files\NVIDIA Corporation
2009-12-03 05:51 . 2009-11-21 02:34 69632 —-a-w- c:\windows\system32\OpenCL.dll
2009-12-03 05:51 . 2009-11-21 02:34 2259560 —-a-w- c:\windows\system32\nvcuvid.dll
2009-12-03 05:51 . 2009-11-21 02:34 1989224 —-a-w- c:\windows\system32\nvcuvenc.dll
2009-12-03 05:50 . 2009-11-21 02:34 2293286 —-a-w- c:\windows\system32\nvdata.bin
2009-12-03 05:50 . 2009-11-21 02:34 11374592 —-a-w- c:\windows\system32\nvcompiler.dll
2009-12-03 05:47 . 2009-12-03 05:47 ——– d—–w- c:\program files\SystemRequirementsLab

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-18 02:48 . 2007-08-14 20:51 ——– d—–w- c:\documents and settings\Mary\Application Data\AdobeUM
2009-12-12 15:00 . 2009-12-12 15:01 2065688 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-12-12 05:14 . 2007-09-25 02:44 ——– d—–w- c:\program files\Advanced Registry Doctor
2009-12-06 18:52 . 2009-12-17 03:11 52224 —-a-w- c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\extensions\{2bae58c2-79f9-45d1-a286-81f911301c3a}\components\FFExternalAlert.dll
2009-12-06 18:52 . 2009-12-17 03:11 114688 —-a-w- c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\extensions\{2bae58c2-79f9-45d1-a286-81f911301c3a}\components\npmozax.dll
2009-12-05 05:23 . 2007-07-28 05:38 ——– d—–w- c:\program files\Premium Booster
2009-12-05 03:35 . 2009-08-13 02:13 ——– d—–w- c:\program files\iTunes
2009-12-05 03:33 . 2009-05-07 00:54 ——– d—–w- c:\program files\Coupons
2009-12-05 03:20 . 2004-10-10 06:52 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-05 03:18 . 2004-10-10 06:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-04 06:19 . 2007-09-30 20:59 ——– d—–w- c:\program files\Windows Desktop Search
2009-12-04 03:42 . 2007-08-12 17:34 146864 -c–a-w- c:\documents and settings\Mary\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-04 02:05 . 2009-04-07 04:15 ——– d—–w- c:\program files\LSI SoftModem
2009-12-04 01:50 . 2008-10-02 08:47 ——– d—–w- c:\program files\Driver Magician
2009-12-03 06:18 . 2008-08-03 12:02 ——– d—–w- c:\program files\a-squared Anti-Malware
2009-11-26 15:50 . 2009-12-12 15:01 3514648 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-11-26 15:50 . 2009-12-12 15:01 2029336 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-11-21 02:34 . 2007-12-05 07:41 4038656 —-a-w- c:\windows\system32\nvcuda.dll
2009-11-21 02:34 . 2007-08-10 22:33 10235968 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-11-21 02:34 . 2007-08-10 22:33 6282752 —-a-w- c:\windows\system32\nv4_disp.dll
2009-11-21 02:34 . 2007-03-01 02:09 592488 -c–a-w- c:\windows\system32\nvudisp.exe
2009-11-21 02:34 . 2006-10-22 18:22 182888 —-a-w- c:\windows\system32\nvcodins.dll
2009-11-21 02:34 . 2006-10-22 18:22 182888 —-a-w- c:\windows\system32\nvcod.dll
2009-11-21 02:34 . 2006-10-22 18:22 13602816 —-a-w- c:\windows\system32\nvoglnt.dll
2009-11-21 02:34 . 2006-10-22 18:22 1056768 —-a-w- c:\windows\system32\nvapi.dll
2009-11-21 02:32 . 2009-11-21 02:32 278120 —-a-w- c:\windows\system32\nvmccs.dll
2009-11-21 02:32 . 2009-11-21 02:32 154216 —-a-w- c:\windows\system32\nvsvc32.exe
2009-11-21 02:32 . 2009-11-21 02:32 145000 —-a-w- c:\windows\system32\nvcolor.exe
2009-11-21 02:32 . 2009-11-21 02:32 12669544 —-a-w- c:\windows\system32\nvcpl.dll
2009-11-21 02:32 . 2009-11-21 02:32 110184 —-a-w- c:\windows\system32\nvmctray.dll
2009-11-21 02:32 . 2009-11-21 02:32 81920 —-a-w- c:\windows\system32\nvwddi.dll
2009-11-20 03:42 . 2007-03-17 06:41 592488 -c–a-w- c:\windows\system32\NVUNINST.EXE
2009-11-20 03:19 . 2006-07-01 05:48 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2009-11-20 03:13 . 2008-10-04 19:27 ——– d—–w- c:\program files\Rhapsody
2009-11-19 17:48 . 2009-12-02 00:41 872960 —-a-w- c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-11-19 17:48 . 2009-12-02 00:41 43008 —-a-w- c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-11-19 17:48 . 2009-12-02 00:41 340480 —-a-w- c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-11-19 17:48 . 2009-12-02 00:41 346624 —-a-w- c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-19 05:45 . 2005-11-11 06:28 ——– d—–w- c:\program files\QuickTime
2009-11-10 20:45 . 2009-11-10 20:45 ——– d—–w- c:\program files\iPod
2009-11-10 20:45 . 2009-06-24 00:54 ——– d—–w- c:\program files\Common Files\Apple
2009-11-10 20:38 . 2009-11-10 20:38 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-04 05:05 . 2004-08-07 19:36 ——– d—–w- c:\program files\Java
2009-11-04 03:28 . 2009-11-04 03:28 152576 —-a-w- c:\documents and settings\Mary\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-10-29 07:46 . 2004-08-07 18:47 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2004-08-07 18:46 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2004-08-07 18:46 17408 ——w- c:\windows\system32\corpol.dll
2009-10-26 09:34 . 2009-03-19 04:48 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-10-21 05:38 . 2004-08-07 18:47 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-07 18:46 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-07 18:47 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-07 18:47 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-07 18:47 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-11 10:17 . 2009-04-11 02:48 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-10-08 20:57 . 2008-07-30 01:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 20:57 . 2004-08-16 21:08 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 20:56 . 2004-08-16 21:08 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2005-07-09 22:33 . 2005-07-09 22:33 774144 -c–a-w- c:\program files\RngInterstitial.dll
2001-09-17 10:45 . 2005-02-08 23:27 127 -c–a-w- c:\program files\setup.bat
2001-09-17 10:44 . 2005-02-08 23:27 1007761 -c–a-w- c:\program files\unpack.exe
2001-09-17 10:43 . 2005-02-08 23:27 47385544 -c–a-w- c:\program files\Hoyle Card Games 5.prf
2001-08-20 15:47 . 2005-02-08 23:27 4657152 -c–a-w- c:\program files\CardGames.exe
2001-08-20 15:44 . 2005-02-08 23:27 149431 -c–a-w- c:\program files\strings.txt
2001-08-17 15:55 . 2005-02-08 23:27 2420981 -c–a-w- c:\program files\CARD.HLP
2001-08-13 22:21 . 2005-02-08 23:27 8153 -c–a-w- c:\program files\Readme.txt
2001-08-08 18:46 . 2005-02-08 23:27 248179 -c–a-w- c:\program files\Bonus.prf
2001-07-13 15:55 . 2005-02-08 23:27 27648 -c–a-w- c:\program files\startw.exe
2001-07-05 20:39 . 2005-02-08 23:27 2645 -c–a-w- c:\program files\Sierra.inf
2001-07-03 20:26 . 2005-02-08 23:27 80 -c–a-w- c:\program files\LANGUAGE.INF
2001-07-03 20:02 . 2005-02-08 23:27 782336 -c–a-w- c:\program files\Hoyle_Card_Games.exe
2001-06-20 19:47 . 2005-02-08 23:27 31991 -c–a-w- c:\program files\autorun.txt
2001-06-18 22:14 . 2005-02-08 23:27 75 -c–a-w- c:\program files\autorun.ini
2001-05-09 15:49 . 2005-02-08 23:27 176128 -c–a-w- c:\program files\INSTAIDE.DLL
2001-01-04 21:19 . 2005-02-08 23:27 4710 -c–a-w- c:\program files\HCG5.ico
2000-09-12 20:17 . 2005-02-08 23:27 27374 -c–a-w- c:\program files\habits.prf
2000-07-06 15:17 . 2005-02-08 23:27 91279 -c–a-w- c:\program files\fonts.prf
2000-03-18 08:29 . 2005-02-08 23:27 49152 -c–a-w- c:\program files\INJECT.EXE
1999-12-01 21:47 . 2005-02-08 23:27 758 -c–a-w- c:\program files\Hoyle Auto run.prf
1997-12-24 16:45 . 2005-02-08 23:27 105472 -c–a-w- c:\program files\SOS9503.DLL
2002-08-01 00:55 . 2008-04-17 16:15 108 –sh–w- c:\windows\WSYS049.SYS
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-21 12669544]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-11-21 110184]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoThumbnailCache"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-18 13:34 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0SsiEfr.e\0SsiEfr.e\0SsiEfr.e\0smrgdf c:\program files\iolo\System Mechanic Professional 6\\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Mary^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Mary^Start Menu^Programs^Startup^Yahoo! Widgets.lnk]
backup=c:\windows\pss\Yahoo! Widgets.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveProtect
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCPitstop Optimize Registration Reminder
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Protector Plus InstaUpdate
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Protector Plus Taskbar Control
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rfagent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBCSTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSystemAnalyzer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a-squared]
2009-04-29 01:09 2799760 —-a-w- c:\program files\a-squared Anti-Malware\a2guard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AAWTray]
2007-10-09 02:40 87392 —-a-w- c:\program files\Lavasoft\Ad-Aware 2007\AAWTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 17:08 935288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 09:08 35696 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
2006-11-02 22:57 528384 -c–a-r- c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
2006-06-29 15:54 286720 -c–a-w- c:\program files\BlazeVideo\BlazeDVD 5 Professional\MediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CookiePatrol]
2005-01-10 15:35 73728 -c–a-w- c:\progra~1\PESTPA~1\CookiePatrol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2005-05-03 04:25 118784 -c–a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-29 02:21 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2007-04-11 21:32 56080 —-a-w- c:\windows\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 21:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-11-21 02:32 110184 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Booster]
2007-11-30 23:16 14450688 —-a-w- c:\program files\PC Booster\PCBooster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PestPatrol Control Center]
2004-11-15 17:49 98304 -c–a-w- c:\progra~1\PESTPA~1\PPControl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPMemCheck]
2004-04-02 20:11 148480 -c–a-w- c:\progra~1\PESTPA~1\PPMemCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-05-27 15:50 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecordPadRun]
2006-12-04 00:58 512004 -c–a-w- c:\program files\NCH Swift Sound\RecordPad\recordpad.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2007-04-16 20:28 577536 -c–a-w- c:\windows\soundman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 21:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite]
2008-06-19 21:48 851968 —-a-w- c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-18 23:33 68856 -c–a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
2008-03-26 00:08 1047712 —-a-w- c:\program files\TrojanHunter 5.0\THGuard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2005-03-08 09:33 53248 -c–a-w- c:\windows\system32\VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeatherMate]
2008-04-05 05:00 741466 —-a-w- c:\program files\WeatherMate\WeatherMate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-19 02:05 204288 -c–a-w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SharedAccess"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"hpsysdrv"=c:\windows\system\hpsysdrv.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"HDInspector.exe"="c:\program files\Hard Drive Inspector\HDInspector.exe"
"RAM Idle Professional"="c:\program files\TweakNow PowerPack" 2006\RAM2_XP.exe
"AGRSMMSG"=AGRSMMSG.exe
"MotiveReportAgent"="c:\program files\Common Files\Motive\McciBootStrapper.exe" /url="-url=file://c:\program files\Common Files\Motive\ReportAgent.html" /browsertype=CustomMSIE /browserpath="c:\program files\Common Files\Motive\BellSouthBrowser.exe" /hidden
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"AlcxMonitor"=ALCXMNTR.EXE
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\MARY DRIVE STUFF\\mIRC\\mirc.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Logitech Remote\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\SymplisIT\\DriverMagic\\DriverMagic.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\TVAntsnew\\Tvants.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\XP Repair Pro 2007\\XPRepairPro.exe"=
"c:\\Program Files\\LimeWire 5.0.11\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R0 hotcore2;hotcore2;c:\windows\system32\drivers\hotcore2.sys [3/3/2007 7:24 PM 30808]
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [3/26/2007 2:26 PM 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [3/26/2007 2:26 PM 52224]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [10/18/2006 4:39 PM 17920]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/8/2008 5:41 AM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/8/2008 5:41 AM 108552]
R1 PStrip;PStrip;c:\windows\system32\drivers\PStrip.sys [11/9/2004 3:32 PM 21968]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [10/3/2007 4:26 PM 85760]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [8/3/2008 6:02 AM 425080]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2008 11:43 PM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/8/2008 5:41 AM 297752]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [11/22/2007 11:23 AM 388936]
S1 SuperMounter;SuperMounter; [x]
S3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\drivers\lne100v5.sys [10/24/2001 3:16 PM 36224]
S3 S3chipid;S3chipid;c:\softpaq\SP26437\Driver\s3chipid.sys [1/23/2003 7:01 AM 3712]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [5/5/2008 8:36 PM 747912]

— Other Services/Drivers In Memory —

*Deregistered* - sptd

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
——- Supplementary Scan ——-
.
uStart Page = www.excite.com/
uDefault_Search_URL = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: { - c:\program files\Messenger\msmsgs.exe
Trusted Zone: excite.com\www
Trusted Zone: turbotax.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech Remote\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
FF - ProfilePath - c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.excite.com/
FF - component: c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\extensions\{2bae58c2-79f9-45d1-a286-81f911301c3a}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Mary\Application Data\Mozilla\Firefox\Profiles\4rilgvt8.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Mary\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\1.4.661.11671\npCIDetect7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 600000
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: network.prefetch-next - true
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - false
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - true
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-nwiz - nwiz.exe
Notify-WgaLogon - (no file)
SafeBoot-svcWRSSSDK
MSConfigStartUp-iLike - c:\program files\iLike\1.2.16\ilikesidebar.exe
MSConfigStartUp-nwiz - nwiz.exe
MSConfigStartUp-pipmon - pipmon.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-21 19:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x8AB7B8AC]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf765bf28
\Driver\ACPI -> ACPI.sys @ 0xf74accb8
\Driver\atapi -> atapi.sys @ 0xf7858b40
IoDeviceObjectType -> ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xb867ebb0
PacketIndicateHandler -> NDIS.sys @ 0xb868ba21
SendHandler -> NDIS.sys @ 0xb866987b
user & kernel MBR OK

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(4072)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Advanced Registry Doctor\RegManServ.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wscntfy.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\SearchProtocolHost.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Completion time: 2009-12-21 20:03:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-22 02:03
ComboFix2.txt 2007-09-15 21:33

Pre-Run: 69,265,199,104 bytes free
Post-Run: 69,269,651,456 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=5 Sets=,1,2,3,4,5
- - End Of File - - DFC52C91D678002C0295CF5B88BC498F
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Hi, Sorry for the delay. I'll post those reports later today. I ran the Kapersky overnight as it took forever and when I came in here to get the report to send to you, the program was closed. I guess the computer rebooted. Anyway, hang in there with me, I am trying. Thanks!
MBAM LOG

Malwarebytes' Anti-Malware 1.42
Database version: 3441
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

12/27/2009 5:08:26 PM
mbam-log-2009-12-27 (17-08-26).txt

Scan type: Quick Scan
Objects scanned: 138057
Time elapsed: 33 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\xprepairpro2007 (Rogue.XPRepairPro2007) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\SOS9503.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.

KASPERSKY SCAN RESULTS
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, December 30, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, December 29, 2009 13:21:53
Records in database: 3415909
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
H:\
I:\
J:\
K:\

Scan statistics:
Objects scanned: 322971
Threats found: 13
Infected objects found: 71
Suspicious objects found: 6
Scan duration: 16:23:32


File name / Threat / Threats count
C:\Documents and Settings\Mary\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders (1)\Recovered items\08-10-2008 29\Storage Folders\Inbox\B List\Inbox 2001-2002\6CB6726C-06AADA17.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\MARY DRIVE STUFF\backup\mail\Papfriends.dbx Infected: Email-Worm.VBS.KakWorm 1
C:\MARY DRIVE STUFF\backup\mail\Woodward.dbx Infected: Email-Worm.VBS.KakWorm 18
C:\MARY DRIVE STUFF\backup\OE\Papfriends.dbx Infected: Email-Worm.VBS.KakWorm 1
C:\MARY DRIVE STUFF\backup\OE\Woodward.dbx Infected: Email-Worm.VBS.KakWorm 18
C:\MARY DRIVE STUFF\mIRC\backups\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1
C:\MARY DRIVE STUFF\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1
C:\MARY DRIVE STUFF\Shared Programs\Grokster\adfreegrokster172.exe Infected: Trojan.Win32.Genome.twp 1
C:\MARY DRIVE STUFF\Shared Programs\Grokster\GroksterUpdate151.exe Infected: not-a-virus:AdWare.Win32.Cydoor 4
C:\MARY DRIVE STUFF\Shared Programs\Limewire Turbo 5.4.1\Limewire_Turbo_5.4.1.rar Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1
C:\MARY DRIVE STUFF\Shared Programs\Registry First Aid\Download_rfasetup-af.exe Infected: not-a-virus:Downloader.Win32.SpyNoMore.a 1
C:\MP3\Country (various)\LeAnn Rimes\crazy by lee ann rimes.mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1
C:\MP3\John Mayer\free falling john mayer.mp3 Infected: Trojan-Downloader.WMA.GetCodec.w 1
C:\Outlook Express Storage\Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Outlook Express Storage Backup 10-2005\Inbox 2001-2002.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Outlook Express Storage Backup 10-2005\Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Outlook Express Storage Backup 10-2005\Inbox.dbx Infected: Trojan-Spy.HTML.Chasfraud.q 1
C:\Outlook Express Storage Backup 10-2005\Sent Items 2001.dbx Infected: Backdoor.Win32.Agobot.qgj 1
C:\Outlook Express Storage II\Attachments.dbx Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Outlook Express Storage II\Eddie.dbx Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Outlook Express Storage II\Woodward.dbx Infected: Email-Worm.VBS.KakWorm 18
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1
C:\WINDOWS\system32\lameEnc.dll Infected: Trojan-Spy.Win32.Agent.foi 1

Selected area has been scanned.

Thanks again, in advance, for your help! :thumbup:
Hi,

Please do the following:

  • Go to Start->Run and type in notepad and hit OK.
  • Then copy and paste the content of the following codebox into Notepad:

    @echo off 
    if exist "%temp%\log.txt" del "%temp%\log.txt"
    
    for %%g in ( 
    "C:\MARY DRIVE STUFF\Shared Programs\Grokster\adfreegrokster172.exe"
    "C:\MARY DRIVE STUFF\Shared Programs\Grokster\GroksterUpdate151.exe" 
    "C:\MARY DRIVE STUFF\Shared Programs\Limewire Turbo 5.4.1\Limewire_Turbo_5.4.1.rar"
    "C:\MARY DRIVE STUFF\Shared Programs\Registry First Aid\Download_rfasetup-af.exe"
    "C:\MP3\Country (various)\LeAnn Rimes\crazy by lee ann rimes.mp3" 
    "C:\MP3\John Mayer\free falling john mayer.mp3" 
    "C:\WINDOWS\system32\lameEnc.dll" 
    ) do (
    del /a/f/q %%g >nul 2>&1
    if exist %%g echo.%%g>>"%temp%\log.txt"
    )
    if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt"
    ) else echo.Deleted Successfully !!
    pause
    del %0
  • Save the file to your DESKTOP as "find.bat". Make sure to save it with the quotes.
  • Once saved, the icon to click should look like this on your desktop:

    [external image: Posted Image]
  • Double click find.bat. to run it. A small black box should open and close - this is normal.
  • Let me know if it deletes successfully.


The other items found by Kaspersky are in your Outlook Express. Unfortunately, Kaspersky cannot Identify which particular emails are infected, so unless there is something particularly important there, delete them, especially anything with attachments such as jokes or youtube videos etc. or emails from anyone you don't know or advertizing from companies.

NEXT

Post a fresh DDS and Attach.txt and advise how your computer is running now and if there are any outstanding issues
Thanks for the quick reply. The bat file worked and all of that stuff was deleted. Was any of it significant enough to cause the sluggishness? Here are the files you asked for. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 19:40:22.28 on Wed 12/30/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1106 [GMT -6:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255} ============== Running Processes =============== C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\a-squared Anti-Malware\a2service.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\system32\agrsmsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Advanced Registry Doctor\RegManServ.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Webroot\Washer\WasherSvc.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Live\Mail\wlmail.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Mary\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = www.excite.com/ uDefault_Search_URL = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File TB: {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No File TB: {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime uPolicies-explorer: NoInstrumentation = 1 (0x1) uPolicies-explorer: NoResolveTrack = 1 (0x1) uPolicies-explorer: NoThumbnailCache = 1 (0x1) mPolicies-explorer: NoResolveTrack = 1 (0x1) mPolicies-explorer: NoFileAssociate = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000 IE: { - c:\program files\messenger\msmsgs.exe IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - c:\program files\eltima software\flash decompiler trillix\saveflash\iebt.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: excite.com\www Trusted Zone: turbotax.com DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab DPF: vzTCPConfig - hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {4CCA4E6B-9259-11D9-AC6E-444553544200} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01.cab DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {A8739816-022C-11D6-A85D-00C04F9AEAFB} - hxxp://www.mikethetiger.com/cam/wg_webeye.cab DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} - hxxp://ak.imgag.com/imgag/cp/install/Crusher.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} - hxxp://messenger.zone.msn.com/binary/Chess.cab57176.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://www.driveragent.com/files/driveragent.cab Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech remote\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\mary\applic~1\mozilla\firefox\profiles\4rilgvt8.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.excite.com/ FF - component: c:\documents and settings\mary\application data\mozilla\firefox\profiles\4rilgvt8.default\extensions\{2bae58c2-79f9-45d1-a286-81f911301c3a}\components\FFExternalAlert.dll FF - component: c:\documents and settings\mary\application data\mozilla\firefox\profiles\4rilgvt8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - component: c:\documents and settings\mary\application data\mozilla\firefox\profiles\4rilgvt8.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\documents and settings\mary\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\google\google updater\1.4.661.11671\npCIDetect7.dll FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.notify.interval - 600000 FF - user.js: content.switch.threshold - 600000 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: network.prefetch-next - true FF - user.js: layout.spellcheckDefault - 1 FF - user.js: browser.urlbar.autoFill - false FF - user.js: browser.search.openintab - false FF - user.js: browser.tabs.closeButtons - 1 FF - user.js: browser.tabs.opentabfor.middleclick - false FF - user.js: browser.tabs.tabMinWidth - 100 FF - user.js: browser.urlbar.hideGoButton - true c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 hotcore2;hotcore2;c:\windows\system32\drivers\hotcore2.sys [2007-3-3 30808] R0 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-5-5 42376] R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [2007-3-26 16896] R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [2007-3-26 52224] R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2006-10-18 17920] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-8 335240] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-9-14 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-8 108552] R1 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-5-5 66952] R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-5-5 81288] R1 PStrip;PStrip;c:\windows\system32\drivers\PStrip.sys [2004-11-9 21968] R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [2007-10-3 85760] R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared anti-malware\a2service.exe [2008-8-3 425080] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-3 908056] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-6-8 297752] R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088] R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2007-11-22 388936] S1 SuperMounter;SuperMounter; [x] S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-7 14336] S3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\drivers\lne100v5.sys [2001-10-24 36224] S3 S3chipid;S3chipid;c:\softpaq\sp26437\driver\s3chipid.sys [2003-1-23 3712] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-5-5 747912] S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-5-5 948616] ============== File Associations =============== JSEFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-12-27 15:53 –d—– c:\docume~1\mary\applic~1\Windows Search 2009-12-22 21:06 –d—– c:\docume~1\mary\applic~1\LimeWireTurbo 2009-12-22 21:06 –d—– c:\docume~1\alluse~1\applic~1\LimeWireTurbo 2009-12-22 21:06 –d—– c:\program files\LimeWireTurbo 2009-12-21 19:25 261,632 a——- c:\windows\PEV.exe 2009-12-21 19:25 161,792 a——- c:\windows\SWREG.exe 2009-12-21 19:25 98,816 a——- c:\windows\sed.exe 2009-12-21 19:25 77,312 a——- c:\windows\MBR.exe 2009-12-03 20:00 –d—– c:\windows\system32\XPSViewer 2009-12-03 19:57 –d—– c:\docume~1\mary\applic~1\Windows Desktop Search 2009-12-03 19:56 –d—– c:\windows\system32\GroupPolicy 2009-12-03 19:54 192,000 -c—— c:\windows\system32\dllcache\offfilt.dll 2009-12-03 19:54 98,304 -c—— c:\windows\system32\dllcache\nlhtml.dll 2009-12-03 19:54 29,696 -c—— c:\windows\system32\dllcache\mimefilt.dll 2009-12-03 19:53 –d—– c:\windows\system32\URTTemp 2009-12-03 00:07 –d—– c:\program files\Ashampoo 2009-12-02 23:52 –d—– c:\docume~1\alluse~1\applic~1\NVIDIA Corporation 2009-12-02 23:52 –d—– c:\program files\NVIDIA Corporation 2009-12-02 23:51 8,743 a——- c:\windows\system32\nvinfo.pb 2009-12-02 23:51 2,259,560 a——- c:\windows\system32\nvcuvid.dll 2009-12-02 23:51 1,989,224 a——- c:\windows\system32\nvcuvenc.dll 2009-12-02 23:51 69,632 a——- c:\windows\system32\OpenCL.dll 2009-12-02 23:50 11,374,592 a——- c:\windows\system32\nvcompiler.dll 2009-12-02 23:50 2,293,286 a——- c:\windows\system32\nvdata.bin 2009-12-02 23:47 –d—– c:\program files\SystemRequirementsLab ==================== Find3M ==================== 2009-12-03 16:14 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-03 16:13 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-11-20 20:34 592,488 ac—— c:\windows\system32\nvudisp.exe 2009-11-20 20:34 13,602,816 a——- c:\windows\system32\nvoglnt.dll 2009-11-20 20:34 10,235,968 a——- c:\windows\system32\drivers\nv4_mini.sys 2009-11-20 20:34 6,282,752 a——- c:\windows\system32\nv4_disp.dll 2009-11-20 20:34 4,038,656 a——- c:\windows\system32\nvcuda.dll 2009-11-20 20:34 1,056,768 a——- c:\windows\system32\nvapi.dll 2009-11-20 20:34 182,888 a——- c:\windows\system32\nvcodins.dll 2009-11-20 20:34 182,888 a——- c:\windows\system32\nvcod.dll 2009-11-20 20:32 12,669,544 a——- c:\windows\system32\nvcpl.dll 2009-11-20 20:32 278,120 a——- c:\windows\system32\nvmccs.dll 2009-11-20 20:32 154,216 a——- c:\windows\system32\nvsvc32.exe 2009-11-20 20:32 145,000 a——- c:\windows\system32\nvcolor.exe 2009-11-20 20:32 110,184 a——- c:\windows\system32\nvmctray.dll 2009-11-20 20:32 81,920 a——- c:\windows\system32\nvwddi.dll 2009-11-19 21:42 592,488 ac—— c:\windows\system32\NVUNINST.EXE 2009-10-29 01:46 832,512 ——– c:\windows\system32\wininet.dll 2009-10-29 01:46 78,336 a——- c:\windows\system32\ieencode.dll 2009-10-29 01:46 17,408 ——– c:\windows\system32\corpol.dll 2009-10-20 23:38 75,776 a——- c:\windows\system32\strmfilt.dll 2009-10-20 23:38 25,088 a——- c:\windows\system32\httpapi.dll 2009-10-13 04:30 270,336 a——- c:\windows\system32\oakley.dll 2009-10-12 07:38 149,504 a——- c:\windows\system32\rastls.dll 2009-10-12 07:38 79,872 a——- c:\windows\system32\raschap.dll 2009-10-11 04:17 411,368 a——- c:\windows\system32\deploytk.dll 2009-10-08 14:57 611,328 a——- c:\windows\system32\uiautomationcore.dll 2009-10-08 14:57 220,160 a——- c:\windows\system32\oleacc.dll 2009-10-08 14:56 20,480 a——- c:\windows\system32\oleaccrc.dll 2005-07-09 16:33 774,144 ac—— c:\program files\RngInterstitial.dll 2002-07-01 08:13 218 ac-sh— c:\docume~1\alluse~1\applic~1\databack.dat 2001-09-17 04:45 127 ac—— c:\program files\setup.bat 2001-09-17 04:44 1,007,761 ac—— c:\program files\unpack.exe 2001-09-17 04:43 47,385,544 ac—— c:\program files\Hoyle Card Games 5.prf 2001-08-20 09:47 4,657,152 ac—— c:\program files\CardGames.exe 2001-08-20 09:44 149,431 ac—— c:\program files\strings.txt 2001-08-17 09:55 2,420,981 ac—— c:\program files\CARD.HLP 2001-08-13 16:21 8,153 ac—— c:\program files\Readme.txt 2001-08-08 12:46 248,179 ac—— c:\program files\Bonus.prf 2001-07-13 09:55 27,648 ac—— c:\program files\startw.exe 2001-07-05 14:39 2,645 ac—— c:\program files\Sierra.inf 2001-07-03 14:26 80 ac—— c:\program files\LANGUAGE.INF 2001-07-03 14:02 782,336 ac—— c:\program files\Hoyle_Card_Games.exe 2001-06-20 13:47 31,991 ac—— c:\program files\autorun.txt 2001-06-18 16:14 75 ac—— c:\program files\autorun.ini 2001-05-09 09:49 176,128 ac—— c:\program files\INSTAIDE.DLL 2001-01-04 15:19 4,710 ac—— c:\program files\HCG5.ico 2000-09-12 14:17 27,374 ac—— c:\program files\habits.prf 2000-07-06 09:17 91,279 ac—— c:\program files\fonts.prf 2000-03-18 02:29 49,152 ac—— c:\program files\INJECT.EXE 1999-12-01 15:47 758 ac—— c:\program files\Hoyle Auto run.prf 2002-07-31 18:55 108 —sh— c:\windows\WSYS049.SYS 2008-09-08 18:14 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090820080909\index.dat ============= FINISH: 19:41:42.45 ===============

Attachments:

  • [attachment removed: Attach.zip]
Hi,

Your log is clean,

Time to do some housekeeping:

Please do the following:

You have some old versions of Java on your machine,

They can be removed via Add/Remove programs


Go to Start > Control Panel > Add/Remove programs

locate the following programs and select REMOVE


J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_03


Make sure you leave Java™6 update 17 in place as it is the latest version.

If your system is a bit sluggish you may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve performance.

If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.


NEXT


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Thanks for all of your help. It's still running slower than I would like but short of a full reformat, I don't know that anything would help. I do all the upkeep things regularly so I don't think that is it. Last year when IE 8 came out, I had trouble installing it and it took me ages to get back to IE 7 and get it up and running again. I wonder if there are traces of IE8 still on my hard drive that are confusing things?
Hi, Start a new topic in our Windows forums and let our expert techs take a look at what might be the issue. Link back to this topic so they can see you are clean of malware.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI