This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC is painfully slow + programs freezes most of time

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Something is up in my laptop. Maybe 2 months ago I found that I couldn.t run my antivirus program "Bitdefender" It said that it had been disabled. I tried everything i knew , I tried the repair option that came with the program cd , nothing worked. I uninstalled it and reinstalled it , still showed as disabled. During all that time my laptop was showing sign of slowing down. Programs that I was using , could be anything, WORD, MUSIC, IE, KODAK, they all froze at some time ( program not responding). Also I couldn't turn my laptop off by clicking START and TURN OFF COMPUTER. The only option is to use the power button or close the lid. So I contacted BITDEFENDER 's customer support and the oked me to download the 2010 edition of their program, ( I had the 2008 version) So i did , but twice the program showed NOT RESPONDING when i put my curser on the icon in the icon tray at the bottom right of the screen. When I go in the program files and open it ,,it workes fine. All the scans show no virus. One other thing. is when the laptop is closed/off I can hear it working like the hard drive running or something. In all of this, the computer is so very slow to do anything, opening programs, outlook, IE ….. Help thanks Sellig
Hi,

Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi Catbyte Thanks for replying so fast. I'm not sure how to proceed with the reply, and how to include the log you have requested, I have them . Thanks, Sellig
Hi, open the notepads that contain the logs, one by one. at the top of the notepad > click 'Edit" > click 'Select All' > right click the highlighted text and click > copy then come to the forum topic click on 'Add reply' place your curser in the reply window > right click and select 'paste" the previous text you copied will paste into the window. do that for all the logs select "Add reply" Now the logs will be posted into the topic.
Hi

Hope these are sent ok………….




DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 14:12:11.43 on Sun 01/03/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.160 [GMT -4:00]

AV: BitDefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\dds.com
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\upgrepl.exe

============== Pseudo HJT Report ===============

uLocal Page = \blank.htm
uStart Page = hxxp://www.yahoo.ca/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: {9aa2f14f-e956-44b8-8694-a5b615cdf341} - NOW!Imaging
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2010\IEToolbar.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe
mRun: [TPNF] c:\program files\toshiba\touchpad\TPTray.exe
mRun: [TOSHIBA Accessibility] c:\program files\toshiba\accessibility\FnKeyHook.exe
mRun: [TFncKy] TFncKy.exe
mRun: [TCtryIOHook] TCtrlIOHook.exe
mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [CeEKEY] c:\program files\toshiba\e-key\CeEKey.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: []
mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2010\IEShow.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2010\bdagent.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://sra.cn.ca/dana-cached/setup/JuniperSetupSP1.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
TCP: {D05D02A5-8ED5-484B-8BF5-060A21FD5DFB} = 142.166.145.137 142.177.2.130
Notify: AtiExtEvent - Ati2evxx.dll
LSA: Notification Packages = :\WINDOW

============= SERVICES / DRIVERS ===============

R2 BDVEDISK;BDVEDISK;c:\program files\bitdefender\bitdefender 2010\bdvedisk.sys [2009-9-22 83208]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2009-12-7 152456]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2009-10-19 110984]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2009-10-19 183880]

=============== Created Last 30 ================

2010-01-03 17:46:06 4 —-a-w- c:\windows\system32\aspdict-en.dat
2010-01-03 17:46:06 16 —-a-w- c:\windows\system32\asdict.dat
2010-01-02 13:40:49 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-02 13:40:40 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-29 12:22:33 385 —-a-w- c:\windows\system32\user_gensett.xml
2009-12-20 14:19:12 0 —-a-w- c:\windows\system32\ab_bl.sig
2009-12-19 16:39:15 0 —-a-w- c:\windows\system32\wsbl.dat
2009-12-19 16:39:14 0 —-a-w- c:\windows\system32\ph_summ.dat
2009-12-19 16:39:14 0 —-a-w- c:\windows\system32\ph_spoof.sig
2009-12-19 16:39:14 0 —-a-w- c:\windows\system32\ph_sign.slf
2009-12-19 16:39:14 0 —-a-w- c:\windows\system32\ph_fuzzy.sig
2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\ph_white.dat
2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\ph_black.dat
2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\pcwords2.dat
2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\pcwords.dat
2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\pc_sign.slf
2009-12-19 16:39:12 0 —-a-w- c:\windows\system32\ab_sbl.sig
2009-12-19 15:31:10 132 —-a-w- c:\windows\system32\rezumatenoi.dat
2009-12-19 14:56:34 0 d—–w- c:\docume~1\user\applic~1\BitDefender
2009-12-19 14:55:41 0 d—–w- C:\Binaries
2009-12-19 14:54:42 0 d—–w- c:\program files\BitDefender
2009-12-19 14:54:42 0 d—–w- c:\docume~1\alluse~1\applic~1\BitDefender
2009-12-19 14:47:06 0 d—–w- c:\program files\common files\BitDefender
2009-12-19 14:31:28 0 d—–w- c:\docume~1\user\applic~1\QuickScan
2009-12-19 13:57:33 0 d—–w- c:\docume~1\alluse~1\applic~1\avg8
2009-12-19 13:49:52 0 d—–w- c:\windows\SxsCaPendDel
2009-12-16 22:11:39 345033 —-a-w- C:\BdUninstallTool2009.12.16-06.11.39.reg
2009-12-15 01:55:36 1248256 —-a-w- c:\windows\system32\sysdump.tar
2009-12-15 00:15:19 0 d—–w- c:\windows\system32\wbem\Repository
2009-12-07 22:49:08 105736 —-a-w- c:\windows\system32\drivers\bdhv.sys
2009-12-07 22:46:28 152456 —-a-w- c:\windows\system32\drivers\bdfm.sys

==================== Find3M ====================

2009-12-15 00:18:15 81984 —-a-w- c:\windows\system32\bdod.bin
2009-01-15 16:10:59 2644566 —-a-w- c:\program files\AliantAccelInstaller.exe
2009-01-11 02:34:09 726384 —-a-w- c:\program files\wpsetup.exe
2009-01-11 02:22:13 2869536 —-a-w- c:\program files\spywareblastersetup41.exe
2008-12-26 22:20:39 2271744 —-a-w- c:\program files\noadware.exe
2008-12-25 20:38:56 7506176 —-a-w- c:\program files\Yahoo_Canada_Firefox_Setup_Windows_3.0.1.exe
2008-02-19 01:17:17 5037072 —-a-w- c:\program files\spybotsd14.exe

============= FINISH: 14:15:14.00 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-03 07:44:12
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\awdoaaog.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwAllocateVirtualMemory [0xAA6A68C6]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwAssignProcessToJobObject [0xAA6A6C24]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwConnectPort [0xAA6A7C6C]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwCreateFile [0xAA6A7528]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwCreateKey [0xAA6A80BC]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwCreateProcess [0xAA6A6D6E]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwCreateProcessEx [0xAA6A6DF0]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwCreateSection [0xAA6A734C]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwCreateThread [0xAA6A64C8]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwDeviceIoControlFile [0xAA6A81BE]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwDuplicateObject [0xAA6AA3E8]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwFsControlFile [0xAA6A8310]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwLoadDriver [0xAA6A87C4]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwOpenFile [0xAA6A743C]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwOpenProcess [0xAA6AA17A]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwOpenSection [0xAA6A726C]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwOpenThread [0xAA6AA294]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwProtectVirtualMemory [0xAA6A67C4]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwQueueApcThread [0xAA6A6CC6]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwRequestPort [0xAA6A7CFC]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwRequestWaitReplyPort [0xAA6A7AB8]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwSecureConnectPort [0xAA6A7E86]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwSetContextThread [0xAA6A65B8]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwSetSystemInformation [0xAA6A69CA]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwSuspendProcess [0xAA6A6726]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwSuspendThread [0xAA6A6688]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwSystemDebugControl [0xAA6A6B82]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwTerminateProcess [0xAA6AA0DE]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwTerminateThread [0xAA6AA4F6]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender Self Protection Driver/BitDefender) ZwWriteVirtualMemory [0xAA6A63C6]

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Udfs \UdfsCdRom tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Udfs \UdfsDisk tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

AttachedDevice \Driver\Tcpip \Device\Ip bdftdif.sys (BitDefender Firewall TDI Filter Driver/BitDefender LLC)
AttachedDevice \Driver\Tcpip \Device\Tcp bdftdif.sys (BitDefender Firewall TDI Filter Driver/BitDefender LLC)
AttachedDevice \Driver\Tcpip \Device\Udp bdftdif.sys (BitDefender Firewall TDI Filter Driver/BitDefender LLC)
AttachedDevice \Driver\Tcpip \Device\RawIp bdftdif.sys (BitDefender Firewall TDI Filter Driver/BitDefender LLC)

—- EOF - GMER 1.0.15 —-

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 3/13/2006 8:32:07 PM
System Uptime: 1/3/2010 1:37:59 PM (1 hours ago)

Motherboard: TOSHIBA | | ECU00
Processor: Intel® Pentium® M processor 1.86GHz | U1 | 1861/mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 93 GiB total, 58.485 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP123: 10/12/2009 9:53:06 AM - Restore Operation
RP124: 10/16/2009 10:29:59 AM - System Checkpoint
RP125: 10/18/2009 10:41:51 AM - System Checkpoint
RP126: 10/19/2009 8:53:48 AM - Restore Operation
RP127: 10/22/2009 9:36:34 AM - System Checkpoint
RP128: 10/24/2009 11:03:19 AM - Restore Operation
RP129: 11/3/2009 2:57:57 PM - System Checkpoint
RP130: 11/6/2009 3:26:03 PM - System Checkpoint
RP131: 11/9/2009 11:21:44 AM - System Checkpoint
RP132: 11/13/2009 8:41:01 PM - System Checkpoint
RP133: 11/17/2009 2:04:03 PM - System Checkpoint
RP134: 11/21/2009 9:55:36 AM - Installed %1 %2.
RP135: 11/21/2009 9:55:47 AM - Printer Driver Microsoft XPS Document Writer Installed
RP136: 11/23/2009 12:18:43 AM - System Checkpoint
RP137: 11/30/2009 10:30:20 AM - System Checkpoint
RP138: 12/12/2009 2:32:39 AM - System Checkpoint
RP139: 12/12/2009 4:37:33 PM - Installed Guitar Pro 4
RP140: 12/14/2009 3:57:21 PM - System Checkpoint
RP141: 12/14/2009 8:12:02 PM - Restore Operation
RP142: 12/14/2009 10:47:35 PM - Installed Guitar Pro 4
RP143: 12/16/2009 7:20:48 PM - System Checkpoint
RP144: 12/18/2009 8:51:48 PM - System Checkpoint
RP145: 12/19/2009 9:57:32 AM - Installed AVG Free 8.5
RP146: 12/19/2009 10:51:09 AM - Removed AVG Free 8.5
RP147: 12/19/2009 10:53:27 AM - Installed AVG Free 8.5
RP148: 12/19/2009 10:54:32 AM - Installed BitDefender Total Security 2010
RP149: 12/20/2009 7:50:11 PM - Removed Google Earth.
RP150: 12/20/2009 7:52:09 PM - Removed Google Toolbar for Internet Explorer
RP151: 12/22/2009 2:56:11 AM - System Checkpoint
RP152: 12/23/2009 8:56:03 AM - System Checkpoint
RP153: 12/25/2009 12:18:17 PM - System Checkpoint
RP154: 12/29/2009 9:26:53 AM - System Checkpoint
RP155: 1/1/2010 12:27:59 PM - System Checkpoint
RP156: 1/2/2010 7:58:50 PM - Automatic Restore Point

==== Installed Programs ======================

Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Flash Player 9
Adobe Reader 8.1.2
AiO_Scan_CDA
AiOSoftwareNPI
ALPS Touch Pad Driver
AVIConverter 2.0
BitDefender Total Security 2010
BufferChm
C5100
c5100_Help
Canon Camera Access Library
Canon DIGITAL CAMERA Solution Disk Software Guide
Canon MOV Decoder
Canon MOV Encoder
Canon MovieEdit Task for ZoomBrowser EX
Canon Personal Printing Guide
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC 8
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities Digital Photo Professional 3.7
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
CardRd81
CCScore
CD/DVD Drive Acoustic Silencer
Corel WordPerfect Suite 8
CP_CalendarTemplates1
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Panorama1Config
cp_PosterPrintConfig
CR2
Creative MediaSource 5
Creative Removable Disk Manager
Creative System Information
Creative ZEN V Series (R2)
CueTour
CustomerResearchQFolder
Data Access Objects (DAO) 3.0
Destinations
DeviceManagementQFolder
DocProc
DocProcQFolder
DocumentViewer
DocumentViewerQFolder
DVD-RAM Driver
DVD Shrink 3.2
ERUNT 1.1j
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
essvcpt
eSupportQFolder
Fax_CDA
Free Internet Window Washer
FullDPAppQFolder
getPlus®_ocx
Guitar Pro 4
Guitar Pro 5.0
HijackThis 2.0.2
HLPPDOCK
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows Media Format SDK (KB910998)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
HP Customer Participation Program 7.0
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart Essential
HP Photosmart Premier Software 6.5
HP Photosmart, Officejet and Deskjet 7.0.A
HP Product Assistant
HP Solution Center 7.0
HP Update
HPPhotoSmartExpress
HPProductAssistant
InstantShareDevices
InstantShareDevicesMFC
Intel® Graphics Media Accelerator Driver for Mobile
InterActual Player
InterVideo WinDVD Creator 2
InterVideo WinDVD for TOSHIBA
J2SE Runtime Environment 5.0 Update 11
Java™ 6 Update 13
Java™ 6 Update 3
Juniper Networks Host Checker
Juniper Networks Setup Client
Juniper Networks Setup Client Activex Control
kgcbase
Kodak EasyShare software
KSU
Logitech SetPoint
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Office OneNote 2003
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Move Networks Media Player for Internet Explorer
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB925673)
NewCopy_CDA
Notifier
OCR Software by I.R.I.S 7.0
OfotoXMI
OTtBP
OTtBPSDK
PanoStandAlone
PhotoGallery
PhotoRecall Deluxe
Picasa 2
Polar WebLink 2.3.2
ProductContextNPI
RandMap
Readme
Realtek AC'97 Audio
Scan
ScannerCopy
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
SFR
SHASTA
ShowOff
SKIN0001
SkinsHP1
SKINXSDK
SlideShow
SolutionCenter
Sonic DLA
Sonic RecordNow!
Sonic_PrimoSDK
Spybot - Search & Destroy 1.4
staticcr
Status
Texas Instruments PCIxx21/x515 drivers.
TIxx21/x515
Toolbox
TOSHIBA Accessibility
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Controls
TOSHIBA Fn-esse
TOSHIBA Hardware Setup
TOSHIBA Hotkey Utility
TOSHIBA PC Diagnostic Tool
TOSHIBA Power Saver
TOSHIBA SD Memory Card Format
TOSHIBA Software Modem
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
Toshiba Tbiosdrv Driver
TOSHIBA Virtual Sound
TOSHIBA Zooming Utility
Touch and Launch
TouchPad On/Off Utility
TrayApp
Unload
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB973815)
Utility Common Driver
VPRINTOL
WebFldrs XP
WebReg
Windows Communication Foundation
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix - KB895316
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinPatrol 2008
WIRELESS
XML Paper Specification Shared Components Pack 1.0
Yahoo! Messenger
ZENcast Organizer

==== Event Viewer Messages From Past Week ========

1/3/2010 1:39:22 PM, error: Print [23] - Printer Corel Barista failed to initialize because a suitable Corel Barista driver could not be found.
1/3/2010 1:37:12 PM, error: Service Control Manager [7034] - The BitDefender Desktop Update Service service terminated unexpectedly. It has done this 1 time(s).

==== End Of File ===========================

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 3/13/2006 8:32:07 PM
System Uptime: 1/3/2010 1:37:59 PM (1 hours ago)

Motherboard: TOSHIBA | | ECU00
Processor: Intel® Pentium® M processor 1.86GHz | U1 | 1861/mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 93 GiB total, 58.485 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP123: 10/12/2009 9:53:06 AM - Restore Operation
RP124: 10/16/2009 10:29:59 AM - System Checkpoint
RP125: 10/18/2009 10:41:51 AM - System Checkpoint
RP126: 10/19/2009 8:53:48 AM - Restore Operation
RP127: 10/22/2009 9:36:34 AM - System Checkpoint
RP128: 10/24/2009 11:03:19 AM - Restore Operation
RP129: 11/3/2009 2:57:57 PM - System Checkpoint
RP130: 11/6/2009 3:26:03 PM - System Checkpoint
RP131: 11/9/2009 11:21:44 AM - System Checkpoint
RP132: 11/13/2009 8:41:01 PM - System Checkpoint
RP133: 11/17/2009 2:04:03 PM - System Checkpoint
RP134: 11/21/2009 9:55:36 AM - Installed %1 %2.
RP135: 11/21/2009 9:55:47 AM - Printer Driver Microsoft XPS Document Writer Installed
RP136: 11/23/2009 12:18:43 AM - System Checkpoint
RP137: 11/30/2009 10:30:20 AM - System Checkpoint
RP138: 12/12/2009 2:32:39 AM - System Checkpoint
RP139: 12/12/2009 4:37:33 PM - Installed Guitar Pro 4
RP140: 12/14/2009 3:57:21 PM - System Checkpoint
RP141: 12/14/2009 8:12:02 PM - Restore Operation
RP142: 12/14/2009 10:47:35 PM - Installed Guitar Pro 4
RP143: 12/16/2009 7:20:48 PM - System Checkpoint
RP144: 12/18/2009 8:51:48 PM - System Checkpoint
RP145: 12/19/2009 9:57:32 AM - Installed AVG Free 8.5
RP146: 12/19/2009 10:51:09 AM - Removed AVG Free 8.5
RP147: 12/19/2009 10:53:27 AM - Installed AVG Free 8.5
RP148: 12/19/2009 10:54:32 AM - Installed BitDefender Total Security 2010
RP149: 12/20/2009 7:50:11 PM - Removed Google Earth.
RP150: 12/20/2009 7:52:09 PM - Removed Google Toolbar for Internet Explorer
RP151: 12/22/2009 2:56:11 AM - System Checkpoint
RP152: 12/23/2009 8:56:03 AM - System Checkpoint
RP153: 12/25/2009 12:18:17 PM - System Checkpoint
RP154: 12/29/2009 9:26:53 AM - System Checkpoint
RP155: 1/1/2010 12:27:59 PM - System Checkpoint
RP156: 1/2/2010 7:58:50 PM - Automatic Restore Point

==== Installed Programs ======================

Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Flash Player 9
Adobe Reader 8.1.2
AiO_Scan_CDA
AiOSoftwareNPI
ALPS Touch Pad Driver
AVIConverter 2.0
BitDefender Total Security 2010
BufferChm
C5100
c5100_Help
Canon Camera Access Library
Canon DIGITAL CAMERA Solution Disk Software Guide
Canon MOV Decoder
Canon MOV Encoder
Canon MovieEdit Task for ZoomBrowser EX
Canon Personal Printing Guide
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC 8
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities Digital Photo Professional 3.7
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
CardRd81
CCScore
CD/DVD Drive Acoustic Silencer
Corel WordPerfect Suite 8
CP_CalendarTemplates1
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Panorama1Config
cp_PosterPrintConfig
CR2
Creative MediaSource 5
Creative Removable Disk Manager
Creative System Information
Creative ZEN V Series (R2)
CueTour
CustomerResearchQFolder
Data Access Objects (DAO) 3.0
Destinations
DeviceManagementQFolder
DocProc
DocProcQFolder
DocumentViewer
DocumentViewerQFolder
DVD-RAM Driver
DVD Shrink 3.2
ERUNT 1.1j
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
essvcpt
eSupportQFolder
Fax_CDA
Free Internet Window Washer
FullDPAppQFolder
getPlus®_ocx
Guitar Pro 4
Guitar Pro 5.0
HijackThis 2.0.2
HLPPDOCK
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows Media Format SDK (KB910998)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
HP Customer Participation Program 7.0
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart Essential
HP Photosmart Premier Software 6.5
HP Photosmart, Officejet and Deskjet 7.0.A
HP Product Assistant
HP Solution Center 7.0
HP Update
HPPhotoSmartExpress
HPProductAssistant
InstantShareDevices
InstantShareDevicesMFC
Intel® Graphics Media Accelerator Driver for Mobile
InterActual Player
InterVideo WinDVD Creator 2
InterVideo WinDVD for TOSHIBA
J2SE Runtime Environment 5.0 Update 11
Java™ 6 Update 13
Java™ 6 Update 3
Juniper Networks Host Checker
Juniper Networks Setup Client
Juniper Networks Setup Client Activex Control
kgcbase
Kodak EasyShare software
KSU
Logitech SetPoint
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Office OneNote 2003
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Move Networks Media Player for Internet Explorer
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB925673)
NewCopy_CDA
Notifier
OCR Software by I.R.I.S 7.0
OfotoXMI
OTtBP
OTtBPSDK
PanoStandAlone
PhotoGallery
PhotoRecall Deluxe
Picasa 2
Polar WebLink 2.3.2
ProductContextNPI
RandMap
Readme
Realtek AC'97 Audio
Scan
ScannerCopy
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
SFR
SHASTA
ShowOff
SKIN0001
SkinsHP1
SKINXSDK
SlideShow
SolutionCenter
Sonic DLA
Sonic RecordNow!
Sonic_PrimoSDK
Spybot - Search & Destroy 1.4
staticcr
Status
Texas Instruments PCIxx21/x515 drivers.
TIxx21/x515
Toolbox
TOSHIBA Accessibility
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Controls
TOSHIBA Fn-esse
TOSHIBA Hardware Setup
TOSHIBA Hotkey Utility
TOSHIBA PC Diagnostic Tool
TOSHIBA Power Saver
TOSHIBA SD Memory Card Format
TOSHIBA Software Modem
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
Toshiba Tbiosdrv Driver
TOSHIBA Virtual Sound
TOSHIBA Zooming Utility
Touch and Launch
TouchPad On/Off Utility
TrayApp
Unload
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB973815)
Utility Common Driver
VPRINTOL
WebFldrs XP
WebReg
Windows Communication Foundation
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix - KB895316
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinPatrol 2008
WIRELESS
XML Paper Specification Shared Components Pack 1.0
Yahoo! Messenger
ZENcast Organizer

==== Event Viewer Messages From Past Week ========

1/3/2010 1:39:22 PM, error: Print [23] - Printer Corel Barista failed to initialize because a suitable Corel Barista driver could not be found.
1/3/2010 1:37:12 PM, error: Service Control Manager [7034] - The BitDefender Desktop Update Service service terminated unexpectedly. It has done this 1 time(s).

==== End Of File ===========================
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hey!


ComboFix 10-01-03.03 - User 01/03/2010 23:48:13.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.224 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\FIX FILES\Catbyte\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\BitDefender\BitDefender Online Backup\ntSVc.ocx
c:\recycler\S-1-5-21-2178042772-3960084829-1456234550-1003
c:\recycler\S-1-5-21-936217405-998132377-2883199059-1006
c:\windows\EventSystem.log
c:\windows\system32\Thumbs.db
c:\windows\unins000.exe
c:\windows\winhelp.ini

.
((((((((((((((((((((((((( Files Created from 2009-12-04 to 2010-01-04 )))))))))))))))))))))))))))))))
.

2010-01-03 17:46 . 2010-01-03 17:46 4 —-a-w- c:\windows\system32\aspdict-en.dat
2010-01-03 17:46 . 2010-01-03 17:46 16 —-a-w- c:\windows\system32\asdict.dat
2010-01-02 13:40 . 2009-12-30 18:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-02 13:40 . 2009-12-30 18:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-19 16:39 . 2009-12-19 16:39 0 —-a-w- c:\windows\system32\wsbl.dat
2009-12-19 16:39 . 2009-12-19 16:39 0 —-a-w- c:\windows\system32\ph_summ.dat
2009-12-19 16:39 . 2009-12-19 16:39 0 —-a-w- c:\windows\system32\ph_white.dat
2009-12-19 16:39 . 2009-12-19 16:39 0 —-a-w- c:\windows\system32\ph_black.dat
2009-12-19 16:39 . 2009-12-19 16:39 0 —-a-w- c:\windows\system32\pcwords2.dat
2009-12-19 16:39 . 2009-12-19 16:39 0 —-a-w- c:\windows\system32\pcwords.dat
2009-12-19 15:31 . 2009-12-29 20:20 132 —-a-w- c:\windows\system32\rezumatenoi.dat
2009-12-19 14:56 . 2009-12-19 14:56 ——– d—–w- c:\documents and settings\User\Application Data\BitDefender
2009-12-19 14:55 . 2009-12-19 14:55 ——– d—–w- C:\Binaries
2009-12-19 14:54 . 2009-12-20 12:18 ——– d—–w- c:\documents and settings\All Users\Application Data\BitDefender
2009-12-19 14:54 . 2009-12-19 14:55 ——– d—–w- c:\program files\BitDefender
2009-12-19 14:47 . 2009-12-19 14:55 ——– d—–w- c:\program files\Common Files\BitDefender
2009-12-19 14:31 . 2009-12-19 14:31 ——– d—–w- c:\documents and settings\User\Application Data\QuickScan
2009-12-19 13:57 . 2009-12-19 14:52 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-12-19 13:49 . 2009-12-19 14:19 ——– d—–w- c:\windows\SxsCaPendDel
2009-12-17 12:38 . 2009-12-19 02:34 ——– d—–w- c:\windows\BDOSCAN8
2009-12-16 22:11 . 2009-12-16 22:15 345033 —-a-w- C:\BdUninstallTool2009.12.16-06.11.39.reg
2009-12-15 00:15 . 2009-12-15 00:15 ——– d—–w- c:\windows\system32\wbem\Repository
2009-12-07 22:49 . 2009-12-07 22:49 105736 —-a-w- c:\windows\system32\drivers\bdhv.sys
2009-12-07 22:46 . 2009-12-07 22:46 152456 —-a-w- c:\windows\system32\drivers\bdfm.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-03 00:04 . 2009-01-04 22:53 ——– d—–w- c:\program files\ERUNT
2010-01-02 13:40 . 2009-01-04 19:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-01 19:10 . 2008-02-19 01:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-01 14:48 . 2008-02-19 01:19 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-31 13:59 . 2009-11-21 14:13 ——– d—–w- c:\documents and settings\User\Application Data\ZoomBrowser EX
2009-12-29 12:18 . 2009-11-21 14:01 401128 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-21 00:14 . 2007-08-11 21:40 ——– d—–w- c:\program files\illiminable
2009-12-20 23:52 . 2007-11-11 03:30 ——– d—–w- c:\program files\Google
2009-12-20 15:33 . 2009-01-11 02:34 ——– d—–w- c:\documents and settings\User\Application Data\WinPatrol
2009-12-18 22:33 . 2009-12-19 14:31 684032 —-a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\d08h5rqx.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
2009-12-18 22:32 . 2009-12-19 14:31 776704 —-a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\d08h5rqx.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2009-12-15 02:47 . 2009-12-15 02:47 45056 —-a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{54A2CFDE-DC70-46E0-92AC-DC88F6303D39}\NewShortcut31_491CED7A0F134BE6957A59DCA69E8271.exe
2009-12-15 02:47 . 2009-12-15 02:47 45056 —-a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{54A2CFDE-DC70-46E0-92AC-DC88F6303D39}\NewShortcut3_07FB580BF187437F9CBB930D0129A475.exe
2009-12-15 02:47 . 2009-12-15 02:47 10134 —-a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{54A2CFDE-DC70-46E0-92AC-DC88F6303D39}\ARPPRODUCTICON.exe
2009-12-15 02:47 . 2009-05-02 23:22 ——– d—–w- c:\program files\Guitar Pro 4
2009-12-15 01:49 . 2009-11-23 13:18 79488 —-a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-15 00:18 . 2008-09-29 18:14 81984 —-a-w- c:\windows\system32\bdod.bin
2009-11-21 14:32 . 2009-11-21 14:32 ——– d—–w- c:\documents and settings\User\Application Data\Canon
2009-11-21 14:22 . 2009-11-21 14:22 ——– d—–w- c:\documents and settings\User\Application Data\CANON INC
2009-11-21 14:12 . 2006-03-13 23:25 69248 —-a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-21 14:08 . 2009-11-21 14:04 ——– d—–w- c:\program files\Canon
2009-11-21 14:04 . 2009-11-21 14:04 ——– d—–w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-11-21 14:02 . 2009-11-21 14:02 ——– d—–w- c:\program files\MSBuild
2009-11-21 13:56 . 2009-11-21 13:56 ——– d—–w- c:\program files\Reference Assemblies
2009-11-21 13:47 . 2009-11-21 13:47 ——– d—–w- c:\program files\Common Files\Canon
2009-11-14 03:02 . 2007-01-25 17:27 ——– d—–w- c:\documents and settings\User\Application Data\Juniper Networks
2009-11-13 02:57 . 2007-01-25 17:28 36948 —-a-w- c:\documents and settings\User\Application Data\Juniper Networks\Setup\uninstall.exe
2009-11-13 02:54 . 2009-11-13 02:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Juniper Networks
2009-10-19 20:04 . 2009-10-19 20:04 110984 —-a-w- c:\windows\system32\drivers\bdfndisf.sys
2009-01-15 16:10 . 2009-01-15 16:10 2644566 —-a-w- c:\program files\AliantAccelInstaller.exe
2009-01-11 02:34 . 2009-01-11 02:34 726384 —-a-w- c:\program files\wpsetup.exe
2009-01-11 02:22 . 2009-01-11 02:21 2869536 —-a-w- c:\program files\spywareblastersetup41.exe
2008-12-26 22:20 . 2008-12-26 22:20 2271744 —-a-w- c:\program files\noadware.exe
2008-12-25 20:38 . 2008-12-25 20:36 7506176 —-a-w- c:\program files\Yahoo_Canada_Firefox_Setup_Windows_3.0.1.exe
2008-02-19 01:17 . 2008-02-19 01:16 5037072 —-a-w- c:\program files\spybotsd14.exe
2009-10-19 22:59 . 2009-12-19 15:04 47104 —-a-w- c:\program files\mozilla firefox\components\FFComm.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-21 366400]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-30 53248]
"TOSHIBA Accessibility"="c:\program files\TOSHIBA\Accessibility\FnKeyHook.exe" [2005-02-22 24576]
"TFncKy"="TFncKy.exe" [BU]
"TCtryIOHook"="TCtrlIOHook.exe" [2004-05-01 28672]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 1077301]
"NDSTray.exe"="NDSTray.exe" [BU]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2005-04-29 675840]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-23 196608]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
"BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2009-12-04 1118144]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-6-7 180224]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-3-13 532480]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[BU]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [9/22/2009 8:22 AM 83208]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [12/7/2009 6:46 PM 152456]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [10/19/2009 4:04 PM 110984]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [10/19/2009 4:06 PM 183880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
bdx REG_MULTI_SZ scan
.
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.yahoo.ca/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
MSConfigStartUp-CTFMON - (no file)
AddRemove-HijackThis - E:\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-03 23:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1050954649-3925551554-65673389-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1616)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2212)
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\program files\Logitech\SetPoint\lgscroll.dll
.
———————— Other Running Processes ————————
.
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\TCtrlIOHook.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files\Apoint2K\Apntex.exe
c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-01-04 00:06:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-04 04:06
ComboFix2.txt 2009-01-07 17:46
ComboFix3.txt 2009-01-07 17:22

Pre-Run: 62,773,665,792 bytes free
Post-Run: 62,731,067,392 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - D9EB97EDA86BC0852081A9E1233761D8



Thank you


Gilles
Hi,

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Hi Catbyte I can only send you the MBAM log, the Kaspersky scan did work i think, took 2:12 hr to do, but at the end , on the top right , said that no threats found. and there is nothing in the box where the log should be, I have nothing to send you for that scan. A few posting ago, you ask that I disable my antivirus prog. so that I could scan with combofix. I did and after it was done, I enable the antivirus prog. back .. Today, thought BITDEFENDER message said " Bitdefender security service (vsserv.exe) is not available at the moment " After I send you this post, I will restart the computer. Malwarebytes' Anti-Malware 1.43 Database version: 3477 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 1/4/2010 9:42:38 AM mbam-log-2010-01-04 (09-42-38).txt Scan type: Quick Scan Objects scanned: 121603 Time elapsed: 10 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) thanks Gilles
Hi, Let me know if Bit defender starts. You may need to uninstall it completely, then re-install it. The installation may have been corrupted somehow.
Hi Yes, Bitdefender did restart ok. Catbyte, you know at the bottom right near the clock where all those icon are, now today, i see only 8 icons instead of the usual 15 or so that used to be there. Is it possible that one of the programs ( combofix MBAM etc…) scans somehow removed some of the icons related to some programs not oftenly used, Also is it normal or ok for Kaspersky to have a blank log report. What else do I need to do ? Thanks Gilles
Hi, Yes, if Kaspersky did not find any threats then there will be nothing to report. What items from your quick launch bar are you missing? Right click the area > toolbars > check the one's you wish to appear there. Please post a fresh DDS and Attach.txt and advise how your computer is running now and if there are any outstanding issues.
HI Catbyte here are the logs requested. Computer is now running fine' Thanks again Gilles UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 3/13/2006 8:32:07 PM System Uptime: 1/6/2010 1:51:39 PM (6 hours ago) Motherboard: TOSHIBA | | ECU00 Processor: Intel® Pentium® M processor 1.86GHz | U1 | 1861/mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 93 GiB total, 57.43 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP123: 10/12/2009 9:53:06 AM - Restore Operation RP124: 10/16/2009 10:29:59 AM - System Checkpoint RP125: 10/18/2009 10:41:51 AM - System Checkpoint RP126: 10/19/2009 8:53:48 AM - Restore Operation RP127: 10/22/2009 9:36:34 AM - System Checkpoint RP128: 10/24/2009 11:03:19 AM - Restore Operation RP129: 11/3/2009 2:57:57 PM - System Checkpoint RP130: 11/6/2009 3:26:03 PM - System Checkpoint RP131: 11/9/2009 11:21:44 AM - System Checkpoint RP132: 11/13/2009 8:41:01 PM - System Checkpoint RP133: 11/17/2009 2:04:03 PM - System Checkpoint RP134: 11/21/2009 9:55:36 AM - Installed %1 %2. RP135: 11/21/2009 9:55:47 AM - Printer Driver Microsoft XPS Document Writer Installed RP136: 11/23/2009 12:18:43 AM - System Checkpoint RP137: 11/30/2009 10:30:20 AM - System Checkpoint RP138: 12/12/2009 2:32:39 AM - System Checkpoint RP139: 12/12/2009 4:37:33 PM - Installed Guitar Pro 4 RP140: 12/14/2009 3:57:21 PM - System Checkpoint RP141: 12/14/2009 8:12:02 PM - Restore Operation RP142: 12/14/2009 10:47:35 PM - Installed Guitar Pro 4 RP143: 12/16/2009 7:20:48 PM - System Checkpoint RP144: 12/18/2009 8:51:48 PM - System Checkpoint RP145: 12/19/2009 9:57:32 AM - Installed AVG Free 8.5 RP146: 12/19/2009 10:51:09 AM - Removed AVG Free 8.5 RP147: 12/19/2009 10:53:27 AM - Installed AVG Free 8.5 RP148: 12/19/2009 10:54:32 AM - Installed BitDefender Total Security 2010 RP149: 12/20/2009 7:50:11 PM - Removed Google Earth. RP150: 12/20/2009 7:52:09 PM - Removed Google Toolbar for Internet Explorer RP151: 12/22/2009 2:56:11 AM - System Checkpoint RP152: 12/23/2009 8:56:03 AM - System Checkpoint RP153: 12/25/2009 12:18:17 PM - System Checkpoint RP154: 12/29/2009 9:26:53 AM - System Checkpoint RP155: 1/1/2010 12:27:59 PM - System Checkpoint RP156: 1/2/2010 7:58:50 PM - Automatic Restore Point RP157: 1/4/2010 10:01:07 AM - System Checkpoint RP158: 1/6/2010 1:12:42 PM - System Checkpoint ==== Installed Programs ====================== Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Flash Player 9 Adobe Reader 8.1.2 AiO_Scan_CDA AiOSoftwareNPI ALPS Touch Pad Driver AVIConverter 2.0 BitDefender Total Security 2010 BufferChm C5100 c5100_Help Canon Camera Access Library Canon DIGITAL CAMERA Solution Disk Software Guide Canon MOV Decoder Canon MOV Encoder Canon MovieEdit Task for ZoomBrowser EX Canon Personal Printing Guide Canon Utilities CameraWindow Canon Utilities CameraWindow DC Canon Utilities CameraWindow DC 8 Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities Digital Photo Professional 3.7 Canon Utilities MyCamera Canon Utilities MyCamera DC Canon Utilities PhotoStitch Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility CardRd81 CCScore CD/DVD Drive Acoustic Silencer Corel WordPerfect Suite 8 CP_CalendarTemplates1 cp_OnlineProjectsConfig CP_Package_Basic1 CP_Panorama1Config cp_PosterPrintConfig CR2 Creative MediaSource 5 Creative Removable Disk Manager Creative System Information Creative ZEN V Series (R2) CueTour CustomerResearchQFolder Data Access Objects (DAO) 3.0 Destinations DeviceManagementQFolder DocProc DocProcQFolder DocumentViewer DocumentViewerQFolder DVD-RAM Driver DVD Shrink 3.2 ERUNT 1.1j ESSBrwr ESSCDBK ESScore ESSgui ESShelp ESSini ESSPCD ESSPDock ESSSONIC ESSTOOLS essvatgt essvcpt eSupportQFolder Fax_CDA Free Internet Window Washer FullDPAppQFolder getPlus®_ocx Guitar Pro 4 Guitar Pro 5.0 HLPPDOCK Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows Media Format SDK (KB910998) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB970653-v3) HP Customer Participation Program 7.0 HP Document Viewer 7.0 HP Imaging Device Functions 7.0 HP Photosmart Essential HP Photosmart Premier Software 6.5 HP Photosmart, Officejet and Deskjet 7.0.A HP Product Assistant HP Solution Center 7.0 HP Update HPPhotoSmartExpress HPProductAssistant InstantShareDevices InstantShareDevicesMFC Intel® Graphics Media Accelerator Driver for Mobile InterActual Player InterVideo WinDVD Creator 2 InterVideo WinDVD for TOSHIBA J2SE Runtime Environment 5.0 Update 11 Java™ 6 Update 13 Java™ 6 Update 3 Juniper Networks Host Checker Juniper Networks Setup Client Juniper Networks Setup Client Activex Control kgcbase Kodak EasyShare software KSU Logitech SetPoint Malwarebytes' Anti-Malware MarketResearch Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft .NET Framework 3.0 Microsoft Office OneNote 2003 Microsoft Office Professional Edition 2003 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Move Networks Media Player for Internet Explorer MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser (KB925673) NewCopy_CDA Notifier OCR Software by I.R.I.S 7.0 OfotoXMI OTtBP OTtBPSDK PanoStandAlone PhotoGallery PhotoRecall Deluxe Picasa 2 Polar WebLink 2.3.2 ProductContextNPI RandMap Readme Realtek AC'97 Audio Scan ScannerCopy Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) SFR SHASTA ShowOff SKIN0001 SkinsHP1 SKINXSDK SlideShow SolutionCenter Sonic DLA Sonic RecordNow! Sonic_PrimoSDK Spybot - Search & Destroy 1.4 staticcr Status Texas Instruments PCIxx21/x515 drivers. TIxx21/x515 Toolbox TOSHIBA Accessibility TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA Controls TOSHIBA Fn-esse TOSHIBA Hardware Setup TOSHIBA Hotkey Utility TOSHIBA PC Diagnostic Tool TOSHIBA Power Saver TOSHIBA SD Memory Card Format TOSHIBA Software Modem TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 TOSHIBA Supervisor Password Toshiba Tbiosdrv Driver TOSHIBA Virtual Sound TOSHIBA Zooming Utility Touch and Launch TouchPad On/Off Utility TrayApp Unload Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB973815) Utility Common Driver VPRINTOL WebFldrs XP WebReg Windows Communication Foundation Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Live Messenger Windows Live Sign-in Assistant Windows Media Format Runtime Windows Media Player 10 Windows Media Player 10 Hotfix - KB895316 Windows Presentation Foundation Windows Workflow Foundation Windows XP Service Pack 3 WinPatrol 2008 WIRELESS XML Paper Specification Shared Components Pack 1.0 Yahoo! Messenger ZENcast Organizer ==== End Of File =========================== DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 19:00:10.45 on Wed 01/06/2010 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.172 [GMT -4:00] AV: BitDefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB} FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\TOSHIBA\TouchPad\TPTray.exe C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe C:\WINDOWS\system32\TCtrlIOHook.exe C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe C:\Program Files\Apoint2K\Apoint.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Apoint2K\Apntex.exe C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe C:\WINDOWS\explorer.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\OXIJS1IB\dds[1].com ============== Pseudo HJT Report =============== uLocal Page = \blank.htm uStart Page = hxxp://www.yahoo.ca/ uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: {9aa2f14f-e956-44b8-8694-a5b615cdf341} - NOW!Imaging BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe mRun: [TPNF] c:\program files\toshiba\touchpad\TPTray.exe mRun: [TOSHIBA Accessibility] c:\program files\toshiba\accessibility\FnKeyHook.exe mRun: [TFncKy] TFncKy.exe mRun: [TCtryIOHook] TCtrlIOHook.exe mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe mRun: [NDSTray.exe] NDSTray.exe mRun: [CeEKEY] c:\program files\toshiba\e-key\CeEKey.exe mRun: [Apoint] c:\program files\apoint2k\Apoint.exe mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2010\IEShow.exe" mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2010\bdagent.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://sra.cn.ca/dana-cached/setup/JuniperSetupSP1.cab DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab TCP: {D05D02A5-8ED5-484B-8BF5-060A21FD5DFB} = 142.166.145.137 142.177.2.130 Notify: AtiExtEvent - Ati2evxx.dll ============= SERVICES / DRIVERS =============== R2 BDVEDISK;BDVEDISK;c:\program files\bitdefender\bitdefender 2010\bdvedisk.sys [2009-9-22 83208] R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2009-12-7 152456] R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2009-10-19 110984] S3 Arrakis3;BitDefender Arrakis Server;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2009-10-19 183880] =============== Created Last 30 ================ 2010-01-04 03:42:37 0 d-sha-r- C:\cmdcons 2010-01-04 03:25:50 77312 —-a-w- c:\windows\MBR.exe 2010-01-04 03:25:50 261632 —-a-w- c:\windows\PEV.exe 2010-01-04 03:25:50 161792 —-a-w- c:\windows\SWREG.exe 2010-01-04 03:25:49 98816 —-a-w- c:\windows\sed.exe 2010-01-03 17:46:06 4 —-a-w- c:\windows\system32\aspdict-en.dat 2010-01-03 17:46:06 16 —-a-w- c:\windows\system32\asdict.dat 2010-01-02 13:40:49 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-02 13:40:40 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-12-29 12:22:33 385 —-a-w- c:\windows\system32\user_gensett.xml 2009-12-20 14:19:12 0 —-a-w- c:\windows\system32\ab_bl.sig 2009-12-19 16:39:15 0 —-a-w- c:\windows\system32\wsbl.dat 2009-12-19 16:39:14 0 —-a-w- c:\windows\system32\ph_summ.dat 2009-12-19 16:39:14 0 —-a-w- c:\windows\system32\ph_spoof.sig 2009-12-19 16:39:14 0 —-a-w- c:\windows\system32\ph_sign.slf 2009-12-19 16:39:14 0 —-a-w- c:\windows\system32\ph_fuzzy.sig 2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\ph_white.dat 2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\ph_black.dat 2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\pcwords2.dat 2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\pcwords.dat 2009-12-19 16:39:13 0 —-a-w- c:\windows\system32\pc_sign.slf 2009-12-19 16:39:12 0 —-a-w- c:\windows\system32\ab_sbl.sig 2009-12-19 15:31:10 132 —-a-w- c:\windows\system32\rezumatenoi.dat 2009-12-19 14:56:34 0 d—–w- c:\docume~1\user\applic~1\BitDefender 2009-12-19 14:55:41 0 d—–w- C:\Binaries 2009-12-19 14:54:42 0 d—–w- c:\program files\BitDefender 2009-12-19 14:54:42 0 d—–w- c:\docume~1\alluse~1\applic~1\BitDefender 2009-12-19 14:47:06 0 d—–w- c:\program files\common files\BitDefender 2009-12-19 14:31:28 0 d—–w- c:\docume~1\user\applic~1\QuickScan 2009-12-19 13:57:33 0 d—–w- c:\docume~1\alluse~1\applic~1\avg8 2009-12-19 13:49:52 0 d—–w- c:\windows\SxsCaPendDel 2009-12-16 22:11:39 345033 —-a-w- C:\BdUninstallTool2009.12.16-06.11.39.reg 2009-12-15 01:55:36 1248256 —-a-w- c:\windows\system32\sysdump.tar 2009-12-15 00:15:19 0 d—–w- c:\windows\system32\wbem\Repository ==================== Find3M ==================== 2009-12-15 00:18:15 81984 —-a-w- c:\windows\system32\bdod.bin 2009-12-07 22:49:08 105736 —-a-w- c:\windows\system32\drivers\bdhv.sys 2009-12-07 22:46:28 152456 —-a-w- c:\windows\system32\drivers\bdfm.sys 2009-01-15 16:10:59 2644566 —-a-w- c:\program files\AliantAccelInstaller.exe 2009-01-11 02:34:09 726384 —-a-w- c:\program files\wpsetup.exe 2009-01-11 02:22:13 2869536 —-a-w- c:\program files\spywareblastersetup41.exe 2008-12-26 22:20:39 2271744 —-a-w- c:\program files\noadware.exe 2008-12-25 20:38:56 7506176 —-a-w- c:\program files\Yahoo_Canada_Firefox_Setup_Windows_3.0.1.exe 2008-02-19 01:17:17 5037072 —-a-w- c:\program files\spybotsd14.exe ============= FINISH: 19:01:13.79 ===============
Hi,

Just some housekeeping to do now,

please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.2)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 17. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If there are any logs/tools remaining > right click and delete them.

NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.


  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Hi Catbyte I've done all the stuff you asked , cleaning tools etc… Computer is running great and all seems good, thanks for everything your help is greatly appreciated, good jobs you guys. I'll be making a donation thank you so much Gilles

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI