This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Remnants of a Virus still remain?

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have removed some viruses from this Vista laptop. Everything seems to be working fine now, except connections to the internet through the browser. Some registry mods were made to the laptop (like DisableTaskMgr). However, after fixing these issues, I have been unable to recover browser functionality. E-mail works fine. Ping works fine (replies from correct IPs). Only the browser does not work (any browser).

Here is the latest HijackThis! log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:42:49 AM, on 1/21/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\regedit.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5515
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos1.walmart.com/WalmartActivia.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe

–
End of file - 6598 bytes
Hello & Welcome to What the Tech

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Options, then click Track this topic. Make sure it is set to Immediate Email Notification, then click Proceed.

In the meantime please note the following:
  • Any recommendations made are for your computer problems only and should NOT be used on any other computer.
  • Please DO NOT run any scans/tools or other fixes unless I ask you to. This is very important for several reasons. Here are just two of them:
    1. The tools that we use are very powerful and can cause >>irreparable damage<< to your computer if not used correctly.
    2. Commercial scanners, for the most part can not completely remove some of the more "resistant" infections. This makes it much more difficult to get rid of completely.
  • If you get stuck or are unsure of something please ask for a further explanation, do not guess.
  • It will require more than one round to properly clean your system. Continue to respond to this thread until I give you the All Clean! even if symptoms seemingly abate.
Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave & if there is no contact for that amount of time I will have to assume you have abandoned your topic.

Thanks

DDS
Download DDS.scr by sUBs from one of the following links & save it to your desktop.
Link 1
Link 2
  • Double-Click on dds.scr and a command window will appear. This is normal
  • Shortly after two logs will appear, DDS.txt & Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply
Gmer
Download GMER Rootkit Scanner from here.
  • Right click the .exe file then choose Run as Administrator to run the program. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post
  • Save it where you can easily find it, such as your desktop, and post it in reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Note: Do not run any programs while Gmer is running.

To post in next reply:
Contents of DDS log
Contents of Attach.txt
Contents of Gmer log
DDS.txt

DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 14:12:31.72 on Sat 01/23/2010
Internet Explorer: 8.0.6001.18865
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.2813.1388 [GMT -5:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Windows\sYSteM32\SvchOst.eXE -k fioo32
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\dllhost.exe
C:\Windows\System32\msdtc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WUDFHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Windows Sidebar\SideBar.exe
C:\Program Files\Windows Sidebar\SideBar.exe
C:\Users\BILLY\Documents\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Bar = Preserve
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vb32&d=0609&m=aspire_5515
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\adobe acrobat 7.0\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos1.walmart.com/WalmartActivia.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL,avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\billy\appdata\roaming\mozilla\firefox\profiles\eucroqre.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R?2 fioo32;fioo32;c:\windows\system32\SvchOst.eXE -k fioo32 [2008-1-20 21504]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-6 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-6 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-6 108552]
R1 fio32;fio32;c:\windows\system32\drivers\fio32.sys [2009-12-29 59520]
R2 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2007-7-20 557056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2010-1-6 298776]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2009-6-26 24576]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-26 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-26 131072]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-12-4 24064]

=============== Created Last 30 ================

2010-01-20 22:31:18 0 d—–w- c:\program files\Trend Micro
2010-01-11 20:06:02 0 —-a-w- c:\windows\system32\29358.exe
2010-01-11 19:46:02 0 —-a-w- c:\windows\system32\11478.exe
2010-01-06 19:48:48 161144 —-a-w- C:\FxNetsky.exe
2010-01-06 19:16:57 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-06 19:16:54 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-06 19:16:46 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-06 19:16:42 0 d—–w- c:\windows\system32\drivers\Avg
2010-01-06 19:16:40 0 d—–w- c:\programdata\AVG Security Toolbar
2010-01-06 19:16:26 0 d—–w- c:\program files\AVG
2010-01-06 19:16:25 0 d—–w- c:\programdata\avg8
2010-01-04 04:05:42 0 —-a-w- c:\windows\system32\15724.exe
2010-01-04 03:44:59 0 —-a-w- c:\windows\system32\19169.exe
2010-01-04 03:24:59 0 —-a-w- c:\windows\system32\26500.exe
2010-01-04 03:04:59 0 —-a-w- c:\windows\system32\6334.exe
2009-12-29 20:48:34 0 —-a-w- c:\windows\system32\winhelper86.dll
2009-12-29 20:07:01 19313 —-a-w- c:\windows\fs1235.dat
2009-12-29 20:01:19 92672 —-a-w- c:\windows\rdr_1262116871.exe
2009-12-29 19:50:32 0 —-a-w- c:\windows\system32\18467.exe
2009-12-29 19:43:03 92672 —-a-w- c:\windows\rdr_1262115781.exe
2009-12-29 19:26:39 0 —-a-w- c:\windows\rdr_1262114799.exe
2009-12-29 18:57:26 0 —-a-w- c:\windows\system32\41.exe
2009-12-29 18:53:53 0 —-a-w- c:\windows\system32\AVR10.exe
2009-12-29 18:53:43 2854 —-a-w- c:\windows\system32\critical_warning.html
2009-12-29 18:53:40 23552 —-a-w- c:\windows\system32\winlogon86.exe
2009-12-29 18:46:17 34 —-a-w- c:\windows\bk20856.dat
2009-12-29 18:41:36 92672 —-a-w- c:\windows\rdr_1262112093.exe
2009-12-29 15:18:20 0 d—–w- c:\program files\Lavasoft
2009-12-29 15:18:19 0 d—–w- c:\programdata\Lavasoft
2009-12-29 15:17:17 0 d—–w- c:\program files\common files\Wise Installation Wizard
2009-12-29 13:48:59 0 d—–w- c:\program files\Yahoo!
2009-12-29 13:48:55 0 d—–w- c:\program files\CCleaner
2009-12-29 13:22:37 1 —-a-w- c:\windows\fdgg34353edfgdfdf
2009-12-29 13:22:23 59520 —-a-w- c:\windows\system32\drivers\fio32.sys
2009-12-29 13:22:23 50688 —-a-w- c:\windows\system32\fio32.dll
2009-12-29 13:22:09 2 —-a-w- c:\windows\0101120101465450.xxe
2009-12-29 13:22:09 1 —h–w- c:\windows\mmsmark3.dat
2009-12-29 13:22:08 1 —h–w- c:\windows\bk23567.dat
2009-12-29 13:22:07 2 —-a-w- c:\windows\0101120101465755.xxe
2009-12-29 13:22:05 2 —-a-w- c:\windows\010112010146111103.xxe

==================== Find3M ====================

2009-12-16 13:10:10 86016 —-a-w- c:\windows\inf\infstor.dat
2009-12-16 13:10:10 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-12-16 13:10:10 51200 —-a-w- c:\windows\inf\infpub.dat
2009-12-16 13:10:10 143360 —-a-w- c:\windows\inf\infstrng.dat
2009-12-16 13:09:58 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-12-16 13:09:42 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-12-15 13:18:29 37665 —-a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
2009-11-21 06:40:20 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34:39 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34:39 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59:58 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-03 21:43:29 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-11-03 21:42:10 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-11-03 01:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17:42 2048 —-a-w- c:\windows\system32\tzres.dll
2008-01-21 02:57:01 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:39:34 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:39:34 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:39:34 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:39:34 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-10-22 12:38:16 245760 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

============= FINISH: 14:13:23.77 ===============


Attach.txt

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft® Windows Vista™ Home Basic
Boot Device: \Device\HarddiskVolume2
Install Date: 6/26/2009 5:32:04 PM
System Uptime: 1/23/2010 9:22:20 AM (5 hours ago)

Motherboard: Acer | | Nile
Processor: AMD Athlon™ Processor 2650e | Socket M2/S1G1 | 1600/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 70 GiB total, 29.087 GiB free.
D: is FIXED (NTFS) - 70 GiB total, 69.431 GiB free.
E: is CDROM ()
F: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP211: 12/29/2009 3:49:21 PM - Windows Defender Checkpoint
RP212: 12/30/2009 7:58:43 AM - Scheduled Checkpoint
RP214: 1/4/2010 8:58:20 AM - Windows Defender Checkpoint
RP216: 1/5/2010 8:15:47 AM - Windows Defender Checkpoint
RP218: 1/5/2010 10:17:53 AM - Windows Defender Checkpoint
RP220: 1/6/2010 12:43:27 PM - Windows Defender Checkpoint
RP221: 1/6/2010 2:16:15 PM - Installed AVG Free 8.5
RP223: 1/6/2010 3:58:04 PM - Windows Defender Checkpoint
RP224: 1/7/2010 7:51:10 AM - Scheduled Checkpoint
RP226: 1/7/2010 4:02:53 PM - Windows Defender Checkpoint
RP228: 1/11/2010 8:11:28 AM - Windows Defender Checkpoint
RP230: 1/11/2010 4:24:04 PM - Windows Defender Checkpoint
RP231: 1/18/2010 10:41:12 AM - Scheduled Checkpoint
RP233: 1/18/2010 12:22:25 PM - Removed Covenant Eyes

==== Installed Programs ======================

2007 Microsoft Office Suite Service Pack 1 (SP1)
Acer Assist
Acer Empowering Technology
Acer eRecovery Management
Acer Mobility Center Plug-In
Acer Registration
Acrobat.com
Ad-Aware 2007
Adobe Acrobat 7.0 Professional
Adobe AIR
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Creative Suite 2
Adobe Flash Player 10 ActiveX
Adobe GoLive CS2
Adobe Help Center 1.0
Adobe Illustrator CS2
Adobe InDesign CS2
Adobe Photoshop CS2
Adobe Reader 9
Adobe Shockwave Player 11.5
Adobe Stock Photos 1.0
Adobe SVG Viewer 3.0
Adobe Version Cue CS2
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
AVG Free 8.5
Bonjour
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Google Desktop
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
InterVideo WinDVD 8
iTunes
Launch Manager
LightScribe 1.4.142.1
Microsoft .NET Framework 3.5 SP1
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Standard Edition 2003
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MobileMe Control Panel
Mozilla Firefox (3.5.6)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NTI Backup Now 5
NTI Backup Now Standard
NTI Media Maker 8
QuickTime
Realtek 8169 8168 8101E 8102E Ethernet Driver
Realtek High Definition Audio Driver
Safari
SAMSUNG Mobile Modem Driver Set
Skins
Suite Specific
Synaptics Pointing Device Driver
Tribes 2
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Office 2007 (KB946691)
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
Windows Mobile® Device Handbook

==== Event Viewer Messages From Past Week ========

1/23/2010 2:09:19 PM, Error: ACPI [13] - : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.
1/20/2010 2:13:57 PM, Error: Service Control Manager [7022] - The fioo32 service hung on starting.
1/20/2010 2:13:17 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
1/20/2010 12:21:40 PM, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control.
1/20/2010 11:11:03 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.0.102 for the Network Card with network address 00242B0901FA has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

==== End Of File ===========================


Gmer.txt

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-23 15:39:35
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\BILLY\AppData\Local\Temp\fwrcqpod.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi

ComboFix
Download ComboFix from one of these locations (DO NOT download ComboFix from anywhere else but one of the provided links):
Link 1
Link 2

**IMPORTANT !!! Save ComboFix.exe to your Desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
    A guide to do this can be found here
  • Right-click on ComboFix.exe then choose Run as Administrator & follow the prompts
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


To post in next reply:
ComboFix log
Update on how the computer is running
ComboFix Log

ComboFix 10-01-23.02 - BILLY 01/23/2010 22:52:50.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.2813.1108 [GMT -5:00]
Running from: c:\users\[removed]\Documents\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\010112010146111103.xxe
c:\windows\0101120101465450.xxe
c:\windows\0101120101465755.xxe
c:\windows\bk23567.dat
c:\windows\fdgg34353edfgdfdf
c:\windows\Fonts\MyriadPro-Regular.otf
c:\windows\Help\help
c:\windows\Help\help\en-US\Help.h1c
c:\windows\Help\help\en-US\Help.H1T
c:\windows\Help\help\en-US\Help_AssetId.H1K
c:\windows\Help\help\en-US\Help_BestBet.H1K
c:\windows\Help\help\en-US\Help_LinkTerm.H1K
c:\windows\Help\help\en-US\Help_SubjectTerm.H1K
c:\windows\Help\help\en-US\resources.H1S
c:\windows\Help\help\en-US\stopwrds.stp
c:\windows\Help\help\en-US\stylec.h1s
c:\windows\mmsmark3.dat
c:\windows\rdr_1262112093.exe
c:\windows\rdr_1262114799.exe
c:\windows\rdr_1262115781.exe
c:\windows\rdr_1262116871.exe
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\29358.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\AVR10.exe
c:\windows\system32\critical_warning.html
c:\windows\system32\drivers\fio32.sys
c:\windows\system32\fio32.dll
c:\windows\system32\twain_32.dll
c:\windows\system32\winhelper86.dll
c:\windows\system32\winlogon86.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_fioo32
——-\Service_SfX
——-\Legacy_fio32
——-\Service_fio32


((((((((((((((((((((((((( Files Created from 2009-12-24 to 2010-01-24 )))))))))))))))))))))))))))))))
.

2010-01-24 04:35 . 2010-01-24 04:35 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-01-24 04:35 . 2010-01-24 04:35 ——– d—–w- c:\users\Carrie\AppData\Local\temp
2010-01-21 15:04 . 2010-01-21 16:08 ——– d—–w- c:\users\BILLY\AppData\Local\MigWiz
2010-01-20 22:31 . 2010-01-20 22:31 ——– d—–w- c:\program files\Trend Micro
2010-01-20 17:44 . 2010-01-20 17:44 ——– d—–w- c:\users\Carrie\AppData\Local\AVG Security Toolbar
2010-01-20 17:41 . 2010-01-20 17:41 ——– d—–w- c:\users\Carrie\AppData\Local\Mozilla
2010-01-20 17:41 . 2010-01-20 17:41 ——– d—–w- c:\users\Carrie\AppData\Local\Adobe
2010-01-20 17:41 . 2010-01-20 17:41 ——– d—–w- c:\users\Carrie\AppData\Roaming\ATI
2010-01-20 17:41 . 2010-01-20 17:41 ——– d—–w- c:\users\Carrie\AppData\Local\ATI
2010-01-20 17:40 . 2010-01-20 17:40 ——– d—–w- c:\users\Carrie\AppData\Local\Apple Computer
2010-01-20 17:40 . 2010-01-20 17:40 ——– d—–w- c:\users\Carrie\AppData\Roaming\Acer
2010-01-20 17:40 . 2010-01-20 17:40 73008 —-a-w- c:\users\Carrie\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-13 23:47 . 2009-06-14 21:07 1004800 —-a-w- c:\programdata\AVG Security Toolbar\IEToolbar.dll
2010-01-06 19:48 . 2010-01-06 19:44 161144 —-a-w- C:\FxNetsky.exe
2010-01-06 19:26 . 2010-01-06 19:26 ——– d—–w- c:\users\BILLY\AppData\Local\AVG Security Toolbar
2010-01-06 19:16 . 2010-01-06 19:16 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-06 19:16 . 2010-01-06 19:16 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-06 19:16 . 2010-01-06 19:16 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-06 19:16 . 2010-01-06 19:16 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-06 19:16 . 2010-01-06 19:16 ——– d—–w- c:\windows\system32\drivers\Avg
2010-01-06 19:16 . 2010-01-13 23:47 ——– d—–w- c:\programdata\AVG Security Toolbar
2010-01-06 19:16 . 2010-01-06 19:16 ——– d—–w- c:\program files\AVG
2010-01-06 19:16 . 2010-01-06 19:16 ——– d—–w- c:\programdata\avg8
2010-01-04 20:46 . 2010-01-04 20:46 0 —-a-w- c:\windows\nsreg.dat
2010-01-04 20:46 . 2010-01-04 20:46 ——– d—–w- c:\users\BILLY\AppData\Local\Mozilla
2009-12-29 20:07 . 2009-12-29 20:24 19313 —-a-w- c:\windows\fs1235.dat
2009-12-29 18:46 . 2009-12-29 18:46 34 —-a-w- c:\windows\bk20856.dat
2009-12-29 15:18 . 2009-12-29 15:18 ——– d—–w- c:\program files\Lavasoft
2009-12-29 15:18 . 2009-12-29 15:18 ——– d—–w- c:\programdata\Lavasoft
2009-12-29 15:17 . 2009-12-29 15:17 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-12-29 13:49 . 2009-12-29 13:49 ——– d—–w- c:\users\BILLY\AppData\Roaming\Yahoo!
2009-12-29 13:48 . 2009-12-29 14:17 ——– d—–w- c:\program files\Yahoo!
2009-12-29 13:48 . 2009-12-29 13:49 ——– d—–w- c:\program files\CCleaner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-24 04:37 . 2009-09-01 16:00 12 —-a-w- c:\windows\bthservsdp.dat
2010-01-18 17:24 . 2009-07-01 13:32 ——– d—–w- c:\program files\CE
2010-01-18 17:22 . 2008-12-04 12:31 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-07 13:08 . 2009-07-01 13:36 ——– d—–w- c:\users\BILLY\AppData\Roaming\CE
2009-12-29 14:16 . 2008-12-04 12:57 ——– d—–w- c:\program files\Google
2009-12-16 13:10 . 2009-12-16 13:10 ——– d—–w- c:\program files\Windows Portable Devices
2009-12-16 13:10 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-12-16 13:09 . 2009-12-16 13:09 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-12-16 13:09 . 2009-12-16 13:09 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Calendar
2009-12-15 13:39 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Sidebar
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Photo Gallery
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Defender
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Collaboration
2009-11-21 06:40 . 2009-12-09 13:23 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 13:23 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-09 13:23 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-09 13:23 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-03 21:43 . 2009-12-09 13:22 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-11-03 21:42 . 2009-12-09 13:22 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-11-03 19:41 . 2009-12-09 13:22 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-11-03 01:42 . 2009-10-02 16:00 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-12-02 13:21 2048 —-a-w- c:\windows\system32\tzres.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 21:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Assist Launcher]
2007-11-19 22:17 1261568 —-a-w- c:\program files\Acer\Acer Assist\launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 10:38 34672 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Version Cue CS2]
2005-04-04 22:58 856064 —-a-w- c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-26 05:36 28672 —-a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2008-12-04 12:57 24064 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2008-07-23 03:05 846344 —-a-w- c:\progra~1\LAUNCH~1\LManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 06:28 2153472 —-a-w- c:\windows\System32\oobefldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):ac,1b,9e,ef,8c,7d,ca,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-616536516-1222369642-2872900921-1000]
"EnableNotificationsRef"=dword:00000001

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [1/6/2010 2:16 PM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [1/6/2010 2:16 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/6/2010 2:16 PM 298776]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 4:11 PM 16384]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/26/2008 12:36 AM 45056]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [4/17/2007 7:09 PM 11032]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [6/26/2009 3:45 PM 24576]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/26/2008 12:36 AM 131072]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 9:33 PM 21504]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/4/2008 7:57 AM 24064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2009-07-27 c:\windows\Tasks\NSSstub.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2009-07-21 20:28]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0409&s;=2&o;=vb32&d;=0609&m;=aspire_5515
FF - ProfilePath - c:\users\BILLY\AppData\Roaming\Mozilla\Firefox\Profiles\eucroqre.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-23 23:41
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2010-01-23 23:46:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-24 04:46

Pre-Run: 33,182,744,576 bytes free
Post-Run: 32,828,026,880 bytes free

- - End Of File - - C27D7CC18FDEF3A62B9BCB79ED1BEE20
The laptop is now connected to the internet from the browser and from program updates. Would you be so kind as to analyze the ComboFix log and let me know which setting was causing the problem? Thank you.
Hi
Looks like you had a fairly healthy Koobface infection going on. Was probably the cause of the browser problem.

CFScript
Close any open browsers.
Open notepad and copy/paste the text in the code box below into it:

File::
c:\windows\fs1235.dat
c:\windows\bk20856.dat
Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe
If prompted by ComboFix to update, allow it to do so
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


Kaspersky Online Scan
Please make sure that all programs are closed when installing Java.
  • Click here to visit Java's website
  • Scroll down to JDK 6 Update 18 , then click on the orange Download JRE button
  • Select Windows from the drop-down list for Platform
  • Select Multi-language from the drop-down list for Language
  • Check (tick) I agree to the Java SE Runtime Environment 6 License Agreement box and click on Continue
  • Click on jre-6u18-windows-i586-p.exe link to download it and save this to a convenient location
  • Right click on jre-6u18-windows-i586-p.exe and select Run As Administrator to install Java
  • After the Java installation has finished, right click on your favourite web browser (Internet Explorer, Firefox, etc) and select Run As Administrator to run it
  • Go to Kaspersky website and perform an online antivirus scan
  • Read through the requirements and privacy statement and click on Accept button
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run
  • When the downloads have finished, click on Settings
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan
  • Once the scan is complete, it will display the results. Click on View Scan Report
  • You will see a list of infected items there. Click on Save Report As…
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button
  • Please post this log in your next reply
To post in next reply:
ComboFix log
Kaspersky Online Scan log
ComboFix Log

ComboFix 10-01-25.01 - BILLY 01/25/2010 14:56:46.2.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.2813.1518 [GMT -5:00]
Running from: c:\users\[removed]\Documents\Downloads\ComboFix.exe
Command switches used :: c:\users\BILLY\Documents\Downloads\CFScript.fix
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\windows\bk20856.dat"
"c:\windows\fs1235.dat"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\bk20856.dat
c:\windows\fs1235.dat

.
((((((((((((((((((((((((( Files Created from 2009-12-25 to 2010-01-25 )))))))))))))))))))))))))))))))
.

2010-01-25 20:06 . 2010-01-25 20:06 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-01-25 20:06 . 2010-01-25 20:06 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-01-25 20:06 . 2010-01-25 20:06 ——– d—–w- c:\users\Carrie\AppData\Local\temp
2010-01-25 19:53 . 2010-01-25 19:54 ——– d—–w- C:\32788R22FWJFW
2010-01-24 04:46 . 2010-01-25 20:06 ——– d—–w- c:\users\BILLY\AppData\Local\temp
2010-01-21 15:04 . 2010-01-21 16:08 ——– d—–w- c:\users\BILLY\AppData\Local\MigWiz
2010-01-20 22:31 . 2010-01-20 22:31 ——– d—–w- c:\program files\Trend Micro
2010-01-20 17:44 . 2010-01-20 17:44 ——– d—–w- c:\users\Carrie\AppData\Local\AVG Security Toolbar
2010-01-20 17:41 . 2010-01-20 17:41 ——– d—–w- c:\users\Carrie\AppData\Local\Mozilla
2010-01-20 17:41 . 2010-01-20 17:41 ——– d—–w- c:\users\Carrie\AppData\Local\Adobe
2010-01-20 17:41 . 2010-01-20 17:41 ——– d—–w- c:\users\Carrie\AppData\Roaming\ATI
2010-01-20 17:41 . 2010-01-20 17:41 ——– d—–w- c:\users\Carrie\AppData\Local\ATI
2010-01-20 17:40 . 2010-01-20 17:40 ——– d—–w- c:\users\Carrie\AppData\Local\Apple Computer
2010-01-20 17:40 . 2010-01-20 17:40 ——– d—–w- c:\users\Carrie\AppData\Roaming\Acer
2010-01-20 17:40 . 2010-01-20 17:40 73008 —-a-w- c:\users\Carrie\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-13 23:47 . 2009-06-14 21:07 1004800 —-a-w- c:\programdata\AVG Security Toolbar\IEToolbar.dll
2010-01-06 19:48 . 2010-01-06 19:44 161144 —-a-w- C:\FxNetsky.exe
2010-01-06 19:26 . 2010-01-06 19:26 ——– d—–w- c:\users\BILLY\AppData\Local\AVG Security Toolbar
2010-01-06 19:16 . 2010-01-06 19:16 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-06 19:16 . 2010-01-06 19:16 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-06 19:16 . 2010-01-06 19:16 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-06 19:16 . 2010-01-06 19:16 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-06 19:16 . 2010-01-06 19:16 ——– d—–w- c:\windows\system32\drivers\Avg
2010-01-06 19:16 . 2010-01-13 23:47 ——– d—–w- c:\programdata\AVG Security Toolbar
2010-01-06 19:16 . 2010-01-06 19:16 ——– d—–w- c:\program files\AVG
2010-01-06 19:16 . 2010-01-06 19:16 ——– d—–w- c:\programdata\avg8
2010-01-04 20:46 . 2010-01-04 20:46 0 —-a-w- c:\windows\nsreg.dat
2010-01-04 20:46 . 2010-01-04 20:46 ——– d—–w- c:\users\BILLY\AppData\Local\Mozilla
2009-12-29 15:18 . 2009-12-29 15:18 ——– d—–w- c:\program files\Lavasoft
2009-12-29 15:18 . 2009-12-29 15:18 ——– d—–w- c:\programdata\Lavasoft
2009-12-29 15:17 . 2009-12-29 15:17 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-12-29 13:49 . 2009-12-29 13:49 ——– d—–w- c:\users\BILLY\AppData\Roaming\Yahoo!
2009-12-29 13:48 . 2009-12-29 14:17 ——– d—–w- c:\program files\Yahoo!
2009-12-29 13:48 . 2009-12-29 13:49 ——– d—–w- c:\program files\CCleaner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 13:40 . 2009-09-01 16:00 12 —-a-w- c:\windows\bthservsdp.dat
2010-01-18 17:24 . 2009-07-01 13:32 ——– d—–w- c:\program files\CE
2010-01-18 17:22 . 2008-12-04 12:31 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-14 16:12 . 2009-10-02 16:00 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-07 13:08 . 2009-07-01 13:36 ——– d—–w- c:\users\BILLY\AppData\Roaming\CE
2009-12-29 14:16 . 2008-12-04 12:57 ——– d—–w- c:\program files\Google
2009-12-16 13:10 . 2009-12-16 13:10 ——– d—–w- c:\program files\Windows Portable Devices
2009-12-16 13:10 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-12-16 13:09 . 2009-12-16 13:09 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-12-16 13:09 . 2009-12-16 13:09 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Calendar
2009-12-15 13:39 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Sidebar
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Photo Gallery
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Defender
2009-12-15 13:39 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Collaboration
2009-11-21 06:40 . 2009-12-09 13:23 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 13:23 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-09 13:23 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-09 13:23 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-03 21:43 . 2009-12-09 13:22 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-11-03 21:42 . 2009-12-09 13:22 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-11-03 19:41 . 2009-12-09 13:22 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-29 09:17 . 2009-12-02 13:21 2048 —-a-w- c:\windows\system32\tzres.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 21:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Assist Launcher]
2007-11-19 22:17 1261568 —-a-w- c:\program files\Acer\Acer Assist\launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 10:38 34672 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Version Cue CS2]
2005-04-04 22:58 856064 —-a-w- c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-26 05:36 28672 —-a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2008-12-04 12:57 24064 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2008-07-23 03:05 846344 —-a-w- c:\progra~1\LAUNCH~1\LManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 06:28 2153472 —-a-w- c:\windows\System32\oobefldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):ac,1b,9e,ef,8c,7d,ca,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-616536516-1222369642-2872900921-1000]
"EnableNotificationsRef"=dword:00000001

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [1/6/2010 2:16 PM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [1/6/2010 2:16 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/6/2010 2:16 PM 298776]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 4:11 PM 16384]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [6/26/2009 3:45 PM 24576]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/26/2008 12:36 AM 45056]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [4/17/2007 7:09 PM 11032]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/26/2008 12:36 AM 131072]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 9:33 PM 21504]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/4/2008 7:57 AM 24064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0409&s;=2&o;=vb32&d;=0609&m;=aspire_5515
FF - ProfilePath - c:\users\BILLY\AppData\Roaming\Mozilla\Firefox\Profiles\eucroqre.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;=
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-25 15:06
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-01-25 15:11:16
ComboFix-quarantined-files.txt 2010-01-25 20:11
ComboFix2.txt 2010-01-24 04:46

Pre-Run: 31,863,578,624 bytes free
Post-Run: 31,865,458,688 bytes free

- - End Of File - - 9D84E0C1DFCA3D429FA6AC0656E1F621
The Kaspersky Online Scan found no infections and returned no results.

The "Koobface" infection's name greatly resembles that of "Facebook" where the virus was attained. Is that where it got it's name?

Were those .DAT files being loaded at startup, causing the browser issues? After looking through the startup items and registry entries, I really couldn't find anything that looked obviously wrong (like 11478.exe).
Hi

The "Koobface" infection's name greatly resembles that of "Facebook" where the virus was attained. Is that where it got it's name?

Yes: http://en.wikipedia.org/wiki/Koobface

No, I don't believe those .dat files were being loaded at start up. Appear to be leftovers of the infection.

Clean Up
Now we need to clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately.
Remove ComboFix
The following will implement some cleanup procedures as well as reset System Restore points:
Click Start > Run then copy/paste the following bolded text into the Run box and click OK:
ComboFix /Uninstall
OTC
Download OTC by Old Timer here & save it to your desktop.
Double click on OTC.exe. Click on CleanUp!.
You will receive a prompt that it needs to restart the computer to remove the files. Click Yes.
It will restart your computer automatically. If it doesn't, please restart your computer manually.
You can delete the following from your desktop:
DDS.scr
The Gmer.exe file (it will be randomly named .exe file)
Any logs that may have been saved to your desktop

You can remove the Kaspersky Online Scanner. This can be done via Programs and Features
You should also remove HijackThis. You can do this by going to C:\Program Files\Trend Micro\HijackThis
  • Double click HijackThis.exe
  • From the Main menu click Open the Misc Tools section
  • Using the scroll bar, scroll down to Uninstall HijackThis
  • Click Uninstall HijackThis & exit then click Yes at the prompt
All Clean
Congratulations, good work, your system now appears to be clean. Now that your system is safe we would like you to keep it that way.
Take the time to follow these recommendations & it will greatly reduce the risk of further infections and greatly diminish the chances of you having to visit here again.

Create a Clean System Restore Point
Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close
Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and click OK
Ensure the boxes for Temporary Files & Temporary Internet Files are checked. You can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore click Clean up… and click Yes to the prompt
Click OK and Yes to confirm.

Microsoft Windows Update
Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Install the updates immediately if they are found.
To update Windows
Go to Start > All Programs > Windows Update
To update Office
Open up any Office program.
Go to Help > Check for Updates

Malwarebytes' Anti-Malware
Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is totally free but for real-time protection you will have to pay a small one-time fee.
You can download it here & find a tutorial here. Keep it updated & run it regularly.

SpywareBlaster
Download and install Javacools SpywareBlaster from here
SpywareBlaster adds a list of ActiveX controls, tracking cookies and sites which will be blocked in either Internet Explorer or Firefox browsers. You need to manually check for updates regularly.

Download and Install a HOSTS File
A HOSTS file is a big list of bad web sites. The list has a specific format, a specific name, (name is just HOSTS with no file extension), and a specific location. Your machine always looks at that file in that location before connecting to a web site to verify the address. So the HOSTS listing can be used to "short circuit" a request to a bad website by giving it the address of your own machine.

Download BlueTack's HOSTS Manager here, using Internet Explorer (Firefox won't work):
  • A short distance down the page in the centre, click on the Download button
  • Agree to the license
  • On the next page, to the right side of where it says Download Estimates, right click on the underlined word Hosts Manager choose Save Target As and download the installer Hosts20setup.exe to your desktop
  • Double click the Installer on your desktop and let it Install the Hosts Manager
  • After the installation is complete, click on the Hosts Manager icon on your desktop. (You can delete the other Hosts Switch icon from your desktop)
  • When the Hosts Manager comes up, click the small down arrows on the right side of the bar labeled Options and Tools,
  • Click Disable DNS Service. This is important
  • In the Left Pane, click Download
  • It will load 80,000 lines or more. When it finishes, also in the left pane, click Replace, and then click Save
You can use this manager to handle your HOSTS file download, edits, and most any other HOSTS issue.
If you have a separate party firewall or Winpatrol, you may have to give permissions at various times to Unlock the present default HOSTS file and install the new one.

Web of Trust
WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop
WOT has an addon available for both Firefox and Internet Explorer.

Install WinPatrol
Download it here
You can find information about how WinPatrol works here

Read some information here on how to prevent Malware.

Hopefully these steps will help keep your computer clean.

Stand Up and Be Counted —> Malware Complaints <— where you can make difference!
The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI