This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected With The Unknown!

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm unsure of the extent of my problems, but there has to be an infection(s) somewhere. PC been running super slow for a few weeks now and nothing I do helps more than a day or so at a time. My high speed dsl connection is slower than dial up 99% of the time. I scanned a couple of days ago with Trend Micro and Malwarebytes and all came up empty. I also use Spywareblaster and I ran Cleanup. Until tonite, nothing has been found since 12/16/09 when Malwarebytes found 1 file and 4 registry keys infected with Trojan.Buzus. I disabled windows firewall and installed Online Armour AV & Firewall a couple of days ago and it said the program would start when I restarted my computer, so I did, and every time it got to the XP welcome screen it would restart itself. I went into safe mode to msconfig and unchecked it from the startup tab it and was able to get back to my desktop. I went back to enable windows firewall again until I get this staightened out but somehow it was already back on and I don't have a clue how that happened. Last night, pc was barely puttin' along and on the verge of freezing so I checked Task Manager and CPU was at 100% again so restarted and it took a good 5-6 minutes to load. I then I updated my Revo Uninstaller and began uninstalling a game (Wizard 101) and Revo froze for like 10 minutes. When it started working again there was a severe malfunction. It said it found 10,900 left over files! Good thing I noticed it before clicking "select all + delete" because my entire C:\Games folder would have been history. I've been using Revo Uninstaller for a long time and have never had a problem with it. I checked Task Manager again and CPU was at 100% again after just restarting. As a last note, I ran Trend Micro HJT and had it analyzed at www.hijackthis.de and it recommended putting checkmarks by 3 toolbars (2 Ask and a disabled Reganam) and 1 URLSearchHook so HJT could fix them, but I didn't because I'd prefer a real person helping me. Sorry for the long post and thanks in advance for any help you can give me. Will wait to hear back from someone before doing anything else.

Here's my mbam log:


Malwarebytes' Anti-Malware 1.44
Database version: 3698
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/6/2010 7:11:44 PM
mbam-log-2010-02-06 (19-11-44).txt

Scan type: Quick Scan
Objects scanned: 109206
Time elapsed: 11 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) ->

Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Here is the GMER Report:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-06 22:05:06
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver:

C:\DOCUME~1\DAWNWA~1\LOCALS~1\Temp\kwldipog.sys


—- System - GMER 1.0.15 —-

SSDT SnopFree.sys ZwCreateProcessEx [0xF88B39E4]
SSDT SnopFree.sys ZwTerminateProcess [0xF88B39F4]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 hotcore3.sys (A part

of Paragon System Utilities/Paragon Software Group)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 hotcore3.sys (A part

of Paragon System Utilities/Paragon Software Group)

—- EOF - GMER 1.0.15 —-




Here is the DDS Log:


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:38:46.37 on Sat 02/06/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.205 [GMT

-5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Documents and Settings\Dawn Walker\Application

Data\mjusbsp\magicJack.exe
C:\Documents and Settings\Dawn Walker\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uSearch Page = hxxp://google.com/
uSearchURL,(Default) =

hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101703&gct=&gc=1&q=%s
uURLSearchHooks: DefaultSearchHook Class:

{c94e154b-1459-4a47-966b-4b843befc7db} -
BHO: Java™ Plug-In SSV Helper:

{761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program

files\java\jre6\bin\ssv.dll
BHO: {db9d7a78-a76c-4bf2-97c6-258925ee1542} - No File
BHO: Java™ Plug-In 2 SSV Helper:

{dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program

files\java\jre6\bin\jp2ssv.dll
TB: {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} - No File
uRun: [cdloader] "c:\documents and settings\dawn walker\application

data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [AOL Fast Start] "c:\program files\aol 9.1\AOL.EXE" -b
mRun: [SnoopFreeUI] SnoopFreeUI.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xport to Microsoft Excel -

c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network

Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program

files\messenger\msmsgs.exe
Trusted Zone: 0.0.0.0
DPF: Microsoft XML Parser for Java -

file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} -

hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} -

hxxp://aolsvc.aol.com/onlinegames/free-trial-emerald-city-confidential/Emerald

CityConfidential_Web.1.0.0.9.cab
DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} -

hxxp://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} -

hxxp://cdn.ll.neoedge.com/webgames/MysteryofSharkIsland/MysteryOfSharkI

slandWeb.1.0.0.8.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} -

hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} -

hxxp://www.worldwinner.com/games/v63/bjattack/bja.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} -

hxxp://aolsvc.aol.com/onlinegames/free-trial-rainforest-adventure/gamehousepl

ayer.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} -

hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} -

hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} -

hxxp://www.worldwinner.com/games/v68/clue/clue.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} -

hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} -

hxxp://www.worldwinner.com/games/v67/swapit/swapit.cab
DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} -

hxxp://www.worldwinner.com/games/v46/grandslam/grandslamtrivia.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} -

hxxp://www.worldwinner.com/games/v49/familyfeud/familyfeud.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} -

hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -

hxxp://games.pogo.com/online2/pogo/bookworm_adventures/popcaploader_v10.

cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -

hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program

files\common files\microsoft shared\web folders\PKMCDO.DLL

============= SERVICES / DRIVERS ===============

R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys

[2009-4-8 40560]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-4-6

28544]
R0 SnoopFree;SnoopFree Driver;c:\windows\system32\drivers\SnopFree.sys

[2009-7-9 9472]
R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2001-8-23

14336]
R2 SnoopFreeSvc;Snoop Free Service;System32\SnoopFreeSvc.exe –>

System32\SnoopFreeSvc.exe [?]
S3 BCASPROT;Advanced System Protector;c:\program files\systweak\advanced

system protector\sasprot32.sys [2009-5-4 6656]
S3 m4cxwxp;NDIS5.1 Miniport Driver for D-Link DGE-530T Gigabit Ethernet

Adapter;c:\windows\system32\drivers\m4cxwxp.sys –>

c:\windows\system32\drivers\m4cxwxp.sys [?]
S3 motccgp;Motorola USB Composite Device

Driver;c:\windows\system32\drivers\motccgp.sys [2009-12-25 19712]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys

[2009-12-25 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys

[2009-12-25 42752]
S3 motport;Motorola USB Diagnostic

Port;c:\windows\system32\drivers\motport.sys [2009-12-25 23680]
S4 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs

[2001-8-23 14336]

============== File Associations ===============

JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1

=============== Created Last 30 ================

2010-02-04 23:18 –d—– c:\program files\Trend Micro
2010-02-04 01:09 –d—–

c:\docume~1\dawnwa~1\applic~1\OnlineArmor
2010-02-04 01:09 –d—–

c:\docume~1\alluse~1\applic~1\OnlineArmor
2010-02-04 00:49 223,312 a——-

c:\windows\system32\drivers\OADriver.sys
2010-02-04 00:49 29,776 a——-

c:\windows\system32\drivers\OAnet.sys
2010-02-04 00:49 24,656 a——-

c:\windows\system32\drivers\OAmon.sys
2010-02-04 00:49 –d—– c:\program files\Tall Emu
2010-02-03 23:44 11,264 a–sh— c:\windows\Thumbs.db
2010-02-03 23:44 4,608 a–sh— c:\windows\system32\Thumbs.db
2010-01-29 04:25 53,680 a——-

c:\docume~1\dawnwa~1\applic~1\GDIPFONTCACHEV1.DAT
2010-01-25 23:20 –d—–

c:\docume~1\alluse~1\applic~1\GameHouse
2010-01-23 21:16 –d—– c:\docume~1\alluse~1\applic~1\PopCap
2010-01-19 18:12 –d—–

c:\docume~1\dawnwa~1\applic~1\VSRevoGroup
2010-01-19 13:49 0 a—h—

c:\windows\system32\drivers\Msft_Kernel_motport_01007.Wdf

==================== Find3M ====================

2010-01-07 16:07 38,224 a——-

c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 19,160 a——-

c:\windows\system32\drivers\mbam.sys
2009-12-25 21:40 0 a—h—

c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
2009-12-25 21:40 0 a—h—

c:\windows\system32\drivers\Msft_Kernel_motccgp_01007.Wdf
2009-12-25 20:08 0 a—h—

c:\windows\system32\drivers\Msft_Kernel_motmodem_01007.Wdf
2009-12-25 20:08 0 a—h—

c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wd

f
2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-16 18:03 216,064 a——- c:\windows\iun3405.exe
2009-12-02 05:12 4,254,224 a——- c:\windows\system32\qtp-mt334.dll
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-11-13 19:49 129,784 ——– c:\windows\system32\pxafs.dll
2009-11-13 19:49 120,056 ——– c:\windows\system32\pxcpyi64.exe
2009-11-13 19:49 118,520 ——– c:\windows\system32\pxinsi64.exe
2009-11-13 19:47 90,112 a——- c:\windows\system32\dpl100.dll
2009-11-13 19:47 856,064 a——- c:\windows\system32\divx_xx0c.dll
2009-11-13 19:47 856,064 a——- c:\windows\system32\divx_xx07.dll
2009-11-13 19:47 847,872 a——- c:\windows\system32\divx_xx0a.dll
2009-11-13 19:47 843,776 a——- c:\windows\system32\divx_xx16.dll
2009-11-13 19:47 839,680 a——- c:\windows\system32\divx_xx11.dll
2009-11-13 19:47 696,320 a——- c:\windows\system32\DivX.dll
2009-10-21 15:40 8,628 a—h— c:\program files\GMOUSE.GID
2009-10-21 15:34 12,800 a–sh— c:\program files\Thumbs.db

============= FINISH: 22:39:44.91 ===============
[external image: Posted Image]

Sorry about the delay in responding :(

Please open Notepad and uncheck Word Wrap to turn it off.

If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread.

Also please describe how your computer behaves at the moment.
Hi , Thanks for the response. Yes, I'm still having problems at the moment. Sometimes I can't copy/paste and sometimes I can't drag a file. I get a lot of HTTP 404 errors. I keep getting a popup box wanting to install Adobe Flash Player update and I let it install once but it keeps popping up and I haven't let it install again. PC will be going really slow and when I open Task Manager it shows 100% usage but before I can spot what's sucking it up it blinks and drops to 5-10%. Doesn't make any sense so I'm still stumped. I just noticed Task Manager shows 4 svchost.exe, alg.exe, and csrss.exe. HJT only reports 3 svchost.exe and alg.exe and csrss.exe did not show up on the report at all. It's almost like playing hide and seek. Any suggestions? Thanks in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:28:00 PM, on 2/9/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Documents and Settings\Dawn Walker\Application Data\mjusbsp\magicJack.exe
C:\Program Files\Common Files\aol\1230174480\ee\aolsoftware.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\AOL 9.1\shellmon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec…amp;gc=1&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirec…p;gc=1&q=%s
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
O2 - BHO: (no name) - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Dawn Walker\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} (CPlayFirstEmeraldCitControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…Web.1.0.0.9.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} (CPlayFirstmsiControl Object) - http://cdn.ll.neoedge.com/webgames/Mystery…Web.1.0.0.8.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} (Clue Control) - http://www.worldwinner.com/games/v68/clue/clue.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v57/wof/wof.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v67/swapit/swapit.cab
O16 - DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} (GrandSlamTrivia Control) - http://www.worldwinner.com/games/v46/grand…dslamtrivia.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v49/famil…/familyfeud.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/bookwor…ploader_v10.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 5974 bytes
I don't see a anti-virus program running. Get a free one.

Only run one AVG at a time.


Use an AntiVirus Software - Choose only one - More than one will conflict. It is very important that your computer has anti-virus software running to protect against viruses. Update Antivirus prior to manual scans as necessary or as used. Please only choose one, having more than one can cause problems, such as crashes and your computer to slow down.


Run a full scan and let us know what it finds along with a new HijackThis log.

Also please describe how your computer behaves at the moment
Hi, Ok, I turned my AV back on even though I was kind of reluctant to at this time because it's a new program I just bought and installed. It goes through a learning mode process and it's supposed to be installed on a clean system, so I was waiting until I made sure anything bad had been removed. My understanding is if there is a virus already on here it won't recognize it as it goes through a learning mode, but rather it will just accept it. But I'll just run it through the learn mode again after I'm sure everything is gone. I updated the AV and ran a scan. All it found was this: AV Scan found this: C:\WINDOWS\System32\DRIVERS\ntfs.sys Detection: Suspicious Infection: (alternate Data Stream) I've been in and out today so haven't had a chance to take note of any new changes but it seems to be running about the same. Here is my new HJT log. Thanks for your help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:09:16 PM, on 2/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\OAcat.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tall Emu\Online Armor\a2\AVGate.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Tall Emu\Online Armor\OAui.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Program Files\Common Files\aol\1230174480\ee\aolsoftware.exe
C:\Documents and Settings\Dawn Walker\Application Data\mjusbsp\magicJack.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec…amp;gc=1&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirec…p;gc=1&q=%s
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
O2 - BHO: (no name) - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\OAui.exe"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Dawn Walker\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} (CPlayFirstEmeraldCitControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…Web.1.0.0.9.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} (CPlayFirstmsiControl Object) - http://cdn.ll.neoedge.com/webgames/Mystery…Web.1.0.0.8.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} (Clue Control) - http://www.worldwinner.com/games/v68/clue/clue.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v57/wof/wof.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v67/swapit/swapit.cab
O16 - DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} (GrandSlamTrivia Control) - http://www.worldwinner.com/games/v46/grand…dslamtrivia.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v49/famil…/familyfeud.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/bookwor…ploader_v10.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\OAcat.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe

–
End of file - 6538 bytes
Good Morning, All the AV scan found was a suspicious infection: C:\WINDOWS\System32\DRIVERS\ntfs.sys Detection: Suspicious Infection: (alternate Data Stream). I also uploaded the file to VirusTotal twice and scanned it and it came back clean both times clean so it must be a false positive. I took no further action with it. PC is running about the same with no noticeable changes. When PC acts like it's about to freeze, I bring up task manager and it shows 100% CPU but quickly drops to less than 10%. I've never noticed it do that before. Maybe I'm just looking too hard lol? Is a root kit a possibility? Or maybe my problem lies elsewhere? I'm sorry for all the questions. At this point, the only thing I'm really sure of is….this pc is capable of going a lot faster than it does. Oh, one more thing I almost forgot to mention is, like right now, explorer.exe memory usage is 8, 952K and just one of the svchost.exe files is using 17, 188K. I read somewhere that none of the svchost.exe files should ever be larger than explorer.exe. Is that true? Thanks and have a great day!
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Good Morning! Here are the ComboFix and HJT logs. Yes, finally I can say it does seem to be running better, pages are loading faster also. I removed the magicjack and put it on a computer totally by itself and not only did it seem to help this computer but the service of the magicjack itself seems to be doing better, so I guess that must have been one thing that slowed it down so much. I can live with it now, unless you know of something else I need to do. I sure do appreciate all you've done. You've been a big help! Probably kept me from pulling my hair out lol. I'll wait to hear back from you to see if there's anything else. Have a nice day!

ComboFix 10-02-11.04 - Dawn Walker 02/11/2010 23:08:16.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.309 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\EventSystem.log
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IPRIP
——-\Service_Iprip


((((((((((((((((((((((((( Files Created from 2010-01-12 to 2010-02-12 )))))))))))))))))))))))))))))))
.

2010-02-11 22:19 . 2009-12-24 16:58 6515976 —ha-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\in00000\setup.exe
2010-02-11 22:18 . 2009-12-24 16:54 730032 —ha-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ar00000\install.exe
2010-02-07 18:00 . 2010-02-07 18:00 152576 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-07 17:56 . 2010-02-07 17:59 79488 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-06 23:28 . 2010-02-10 12:43 ——– d—–w- c:\program files\ERUNT
2010-02-05 04:18 . 2010-02-05 04:18 ——– d—–w- c:\program files\Trend Micro
2010-01-26 04:20 . 2010-01-26 04:20 ——– d—–w- c:\documents and settings\All Users\Application Data\GameHouse
2010-01-24 02:16 . 2010-01-24 02:16 ——– d—–w- c:\documents and settings\All Users\Application Data\PopCap
2010-01-19 23:12 . 2010-01-19 23:12 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\VSRevoGroup
2010-01-14 02:20 . 2010-02-01 20:00 ——– d—–w- c:\documents and settings\Dawn Walker\Local Settings\Application Data\AnVir

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-12 03:50 . 2008-12-29 22:38 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-11 22:19 . 2009-11-09 07:05 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp
2010-02-09 18:17 . 2008-12-25 03:10 ——– d—–w- c:\program files\Viewpoint
2010-02-09 18:13 . 2009-04-06 17:02 ——– d—–w- c:\program files\Panda Security
2010-02-08 16:27 . 2008-12-29 23:13 ——– d—–w- c:\program files\SpywareBlaster
2010-02-07 18:03 . 2009-03-01 10:58 ——– d—–w- c:\program files\Java
2010-02-05 01:38 . 2008-04-30 11:24 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-04 21:26 . 2009-12-16 23:04 ——– d—–w- c:\program files\Password Power
2010-02-03 19:26 . 2009-06-19 17:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-03 19:17 . 2009-11-16 05:09 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-24 01:55 . 2009-12-20 00:29 ——– d—–w- c:\program files\Multi Reminders
2010-01-19 21:28 . 2009-12-21 00:46 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\DivX
2010-01-19 18:49 . 2010-01-19 18:49 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motport_01007.Wdf
2010-01-18 21:01 . 2010-01-05 22:52 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\Dropbox
2010-01-07 21:07 . 2009-06-19 17:29 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-06-19 17:29 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 01:18 . 2010-01-06 01:18 ——– d—–w- c:\program files\Microsoft ActiveSync
2010-01-05 22:53 . 2010-01-05 22:53 89854 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\Uninstall.exe
2009-12-31 00:48 . 2009-12-31 00:48 21968784 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\Dropbox.exe
2009-12-26 03:03 . 2009-12-26 02:37 ——– d—–w- c:\program files\P2K
2009-12-26 02:40 . 2009-12-26 02:40 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
2009-12-26 02:40 . 2009-12-26 02:40 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motccgp_01007.Wdf
2009-12-26 01:08 . 2009-12-26 01:08 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01007.Wdf
2009-12-26 01:08 . 2009-12-26 01:08 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-24 16:59 . 2009-12-24 16:59 93016 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ug00000\magicJack.dll
2009-12-24 16:58 . 2010-01-05 11:20 6515976 —ha-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\Upgrade\setup2.exe
2009-12-24 16:58 . 2009-12-24 16:58 6515976 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ug00000\setup.exe
2009-12-24 16:58 . 2009-12-24 16:58 416328 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\magicJackLoader.exe
2009-12-24 16:58 . 2009-12-24 16:58 480608 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\octvqe1_apiw.dll
2009-12-24 16:58 . 2009-12-24 16:58 214360 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\TjVista.dll
2009-12-24 16:58 . 2009-12-24 16:58 337240 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\TjIpSys.dll
2009-12-24 16:58 . 2009-12-24 16:58 607600 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\SJHandsetMagicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 87384 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\st00000\mjsetup.exe
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\st00000\magicJack.dll
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\magicJack.dll
2009-12-24 16:55 . 2009-12-24 16:55 12482904 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\magicJack.exe
2009-12-24 16:54 . 2010-01-05 11:20 730032 —ha-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\Upgrade\install2.exe
2009-12-24 16:54 . 2009-12-24 16:54 730032 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ug00000\install.exe
2009-12-24 16:53 . 2009-12-24 16:53 87384 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\in00000\mjsetup.exe
2009-12-24 16:53 . 2009-12-24 16:53 93016 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\in00000\magicJack.dll
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\st00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\in00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 50520 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\cdloader2.exe
2009-12-21 19:14 . 2001-08-23 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-21 00:33 . 2009-12-21 00:32 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-12-20 00:29 . 2009-12-20 00:29 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\SolwaySoftware
2009-12-16 23:03 . 2009-03-17 04:24 216064 —-a-w- c:\windows\iun3405.exe
2009-12-09 01:19 . 2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\DropboxExt.13.dll
2009-12-02 10:12 . 2009-12-02 10:12 4254224 —-a-w- c:\windows\system32\qtp-mt334.dll
2009-12-02 10:12 . 2009-04-09 00:46 40560 —-a-w- c:\windows\system32\drivers\hotcore3.sys
2009-12-02 10:12 . 2008-12-13 18:47 385544 —-a-w- c:\windows\system32\drivers\Uim_IM.sys
2009-12-02 10:12 . 2008-12-13 18:47 34392 —-a-w- c:\windows\system32\drivers\UimBus.sys
2009-12-02 10:12 . 2008-12-13 18:47 261416 —-a-w- c:\windows\system32\drivers\UimFIO.sys
2009-12-02 05:10 . 2008-12-23 09:22 53680 —-a-w- c:\documents and settings\Dawn Walker\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-30 02:26 . 2009-11-30 02:14 43488992 —-a-w- c:\documents and settings\All Users\Application Data\Systweak\Advanced System Protector\Antispyware_Setup_11_29_2009.exe
2009-11-22 17:40 . 2009-11-21 01:21 8892928 —-a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2009-11-21 15:51 . 2001-08-23 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-10-21 20:40 . 2009-10-21 20:35 8628 —ha-w- c:\program files\GMOUSE.GID
2009-10-21 20:34 . 2009-10-21 20:33 12800 –sha-w- c:\program files\Thumbs.db
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="c:\program files\AOL 9.1\AOL.EXE" [2008-11-06 50472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=c:\windows\pss\Microsoft Find Fast.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^setup.exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\setup.exe
backup=c:\windows\pss\setup.exeCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Dawn Walker^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\documents and settings\Dawn Walker\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Dawn Walker^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=c:\documents and settings\Dawn Walker\Start Menu\Programs\Startup\PowerReg Scheduler.exe

[HKLM\~\startupfolder\C:^Documents and Settings^Dawn Walker^Start Menu^Programs^Startup^ProjectWhois.lnk]
path=c:\documents and settings\Dawn Walker\Start Menu\Programs\Startup\ProjectWhois.lnk
backup=c:\windows\pss\ProjectWhois.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2008-11-06 11:42 50472 —-a-w- c:\program files\AOL 9.1\aol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2009-12-24 16:52 50520 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\cdloader2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
2007-03-15 23:16 454784 —-a-w- c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechGalleryRepair]
2002-12-10 23:32 155648 —-a-w- c:\program files\Logitech\ImageStudio\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechImageStudioTray]
2002-12-10 23:31 61440 —-a-w- c:\program files\Logitech\ImageStudio\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
2002-12-10 22:54 127022 —-a-w- c:\program files\Common Files\Logitech\QCDriver3\LVComS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-01-07 21:07 1394000 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 –sh–w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 16:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 16:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 16:22 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 16:22 1622016 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 09:17 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RDSessMgr"=3 (0x3)
"ose"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\aol\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\aol\\1230174480\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\aol\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\att-nap\\McciBrowser.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Documents and Settings\\Dawn Walker\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Documents and Settings\\Dawn Walker\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5060:UDP"= 5060:UDP:MagicJack
"5070:UDP"= 5070:UDP:MagicJack
"3587:TCP"= 3587:TCP:*:Disabled:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:*:Disabled:Peer Name Resolution Protocol (PNRP)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [4/8/2009 7:46 PM 40560]
S3 BCASPROT;Advanced System Protector;c:\program files\Systweak\Advanced System Protector\sasprot32.sys [5/4/2009 3:08 PM 6656]
S3 m4cxwxp;NDIS5.1 Miniport Driver for D-Link DGE-530T Gigabit Ethernet Adapter;c:\windows\system32\DRIVERS\m4cxwxp.sys –> c:\windows\system32\DRIVERS\m4cxwxp.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [12/25/2009 7:46 PM 19712]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [12/25/2009 7:46 PM 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [12/25/2009 7:46 PM 42752]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [12/25/2009 7:47 PM 23680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-12 c:\windows\Tasks\User_Feed_Synchronization-{31ECF41F-8A99-45FE-8EAC-D7822BB0FA0C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101703&gct;=&gc;=1&q;=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: 0.0.0.0
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-emerald-city-confidential/EmeraldCityConfidential_Web.1.0.0.9.cab
DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} - hxxp://cdn.ll.neoedge.com/webgames/MysteryofSharkIsland/MysteryOfSharkIslandWeb.1.0.0.8.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-rainforest-adventure/gamehouseplayer.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://games.pogo.com/online2/pogo/bookworm_adventures/popcaploader_v10.cab
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
BHO-{db9d7a78-a76c-4bf2-97c6-258925ee1542} - (no file)
ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
MSConfigStartUp-@OnlineArmor GUI - c:\program files\Tall Emu\Online Armor\OAui.exe
MSConfigStartUp-ATT-SST_McciTrayApp - c:\program files\ATT-SST\McciTrayApp.exe
MSConfigStartUp-nmapp - c:\program files\Pure Networks\Network Magic\nmapp.exe
MSConfigStartUp-nmctxth - c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\qttask.exe
MSConfigStartUp-Software Informer - c:\program files\Software Informer\softinfo.exe
AddRemove-GhostMouse 2.0 - c:\program files\DeIsL1.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-11 23:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1044)
c:\windows\system32\WININET.dll
c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\windows\System32\vssvc.exe
c:\program files\AOL 9.1\waol.exe
c:\program files\AOL 9.1\shellmon.exe
.
**************************************************************************
.
Completion time: 2010-02-11 23:29:29 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-12 04:29

Pre-Run: 40,429,375,488 bytes free
Post-Run: 40,349,913,088 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut

- - End Of File - - 8C4507895F9D8D9D952197E68F4FA6E4




Here's the HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:26:07 AM, on 2/12/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec…amp;gc=1&q;=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirec…p;gc=1&q;=%s
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} (CPlayFirstEmeraldCitControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…Web.1.0.0.9.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} (CPlayFirstmsiControl Object) - http://cdn.ll.neoedge.com/webgames/Mystery…Web.1.0.0.8.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} (Clue Control) - http://www.worldwinner.com/games/v68/clue/clue.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v57/wof/wof.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v67/swapit/swapit.cab
O16 - DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} (GrandSlamTrivia Control) - http://www.worldwinner.com/games/v46/grand…dslamtrivia.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v49/famil…/familyfeud.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/bookwor…ploader_v10.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 5558 bytes
Do you use magicJack?

Do you have an anti-virus program?


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\documents and settings\Dawn Walker\Start Menu\Programs\Startup\PowerReg Scheduler.exe

Folder::
c:\documents and settings\All Users\Application Data\PopCap
c:\program files\Viewpoint

Registry::
[-HKLM\~\startupfolder\C:^Documents and Settings^Dawn Walker^Start Menu^Programs^Startup^PowerReg Scheduler.exe]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Hi, thanks for your reply. First I'll answer your questions: Do you use magicJack? Yes, I do, but I'm no longer using it on this computer. I unplugged it from this one and installed it on another computer that I designated solely for the purpose of of running the magicjack and nothing else. Not only does the magicjack work better, it also freed up some resources on this computer and made a noticeable improvement. It's running faster and more stable. The CPU usage went from 100% to less than 10% and so far it hasn't froze anymore. 2. Do you have an anti-virus program? Yes, I do. I just recently purchased Online Armor Anti Virus and Firewall. I installed it, updated it, and ran a scan. It found only one suspicious file "C:\WINDOWS\System32\ntfs.sys which I immediately uploaded to VirusTotal, had it scanned, and the file report came back clean. As a safety measure, I uploaded it again and had it rescanned. The report came back clean this time also. I feel I can trust the VirusTotal scan results so Online Armor must have reported a false positive. I haven't had time to do any research on that subject just yet but plan to as soon as time allows. I uninstalled the Online Armor due to the note that was included in the Online Armor Anti Virus and Firewall package just to be on the safe side: Note reads: Any malware on your system while in learning mode will automatically be allowed to run and ignored by Online Armor. Please be sure that your computer is free of infection before installing. So, I do plan to install Online Armor again as soon as I'm sure no more malware exists. Until then I'll continue to scan for viruses with Panda online and Trend Micro Housecall Online, use VirusTotal to scan any suspected files, weekly scans with updated Malwarebytes as well as weekly update checks for SpywareBlaster. Also, I am using the windows firewall in addition to my router's firewall. Here are the log results:

ComboFix 10-02-12.01 - Dawn Walker 02/12/2010 23:45:24.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.312 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dawn Walker\Desktop\CFScript.txt
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\PopCap
c:\documents and settings\All Users\Application Data\PopCap\PopCapLoader\Oberon\BookwormAdventures\BookwormAdventures.cab
c:\documents and settings\All Users\Application Data\PopCap\PopCapLoader\Oberon\logo.bmp
c:\documents and settings\All Users\Application Data\PopCap\PopCapLoader\Oberon\logoversion.txt
c:\program files\Viewpoint

.
((((((((((((((((((((((((( Files Created from 2010-01-13 to 2010-02-13 )))))))))))))))))))))))))))))))
.

2010-02-12 17:27 . 2010-02-12 17:27 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\Avant Profiles
2010-02-12 17:27 . 2010-02-12 17:27 ——– d—–w- c:\program files\Avant Browser
2010-02-11 22:19 . 2009-12-24 16:58 6515976 —ha-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\in00000\setup.exe
2010-02-11 22:18 . 2009-12-24 16:54 730032 —ha-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ar00000\install.exe
2010-02-07 18:00 . 2010-02-07 18:00 152576 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-07 17:56 . 2010-02-07 17:59 79488 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-06 23:28 . 2010-02-10 12:43 ——– d—–w- c:\program files\ERUNT
2010-02-05 04:18 . 2010-02-05 04:18 ——– d—–w- c:\program files\Trend Micro
2010-01-26 04:20 . 2010-01-26 04:20 ——– d—–w- c:\documents and settings\All Users\Application Data\GameHouse
2010-01-19 23:12 . 2010-01-19 23:12 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\VSRevoGroup

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-12 16:07 . 2008-12-29 22:38 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-12 11:44 . 2009-12-16 23:04 ——– d—–w- c:\program files\Password Power
2010-02-11 22:19 . 2009-11-09 07:05 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp
2010-02-09 18:13 . 2009-04-06 17:02 ——– d—–w- c:\program files\Panda Security
2010-02-08 16:27 . 2008-12-29 23:13 ——– d—–w- c:\program files\SpywareBlaster
2010-02-07 18:03 . 2009-03-01 10:58 ——– d—–w- c:\program files\Java
2010-02-05 01:38 . 2008-04-30 11:24 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-03 19:26 . 2009-06-19 17:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-03 19:17 . 2009-11-16 05:09 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-24 01:55 . 2009-12-20 00:29 ——– d—–w- c:\program files\Multi Reminders
2010-01-19 21:28 . 2009-12-21 00:46 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\DivX
2010-01-19 18:49 . 2010-01-19 18:49 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motport_01007.Wdf
2010-01-18 21:01 . 2010-01-05 22:52 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\Dropbox
2010-01-07 21:07 . 2009-06-19 17:29 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-06-19 17:29 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 01:18 . 2010-01-06 01:18 ——– d—–w- c:\program files\Microsoft ActiveSync
2010-01-05 22:53 . 2010-01-05 22:53 89854 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\Uninstall.exe
2009-12-31 00:48 . 2009-12-31 00:48 21968784 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\Dropbox.exe
2009-12-26 03:03 . 2009-12-26 02:37 ——– d—–w- c:\program files\P2K
2009-12-26 02:40 . 2009-12-26 02:40 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
2009-12-26 02:40 . 2009-12-26 02:40 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motccgp_01007.Wdf
2009-12-26 01:08 . 2009-12-26 01:08 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01007.Wdf
2009-12-26 01:08 . 2009-12-26 01:08 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-24 16:59 . 2009-12-24 16:59 93016 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ug00000\magicJack.dll
2009-12-24 16:58 . 2010-01-05 11:20 6515976 —ha-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\Upgrade\setup2.exe
2009-12-24 16:58 . 2009-12-24 16:58 6515976 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ug00000\setup.exe
2009-12-24 16:58 . 2009-12-24 16:58 416328 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\magicJackLoader.exe
2009-12-24 16:58 . 2009-12-24 16:58 480608 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\octvqe1_apiw.dll
2009-12-24 16:58 . 2009-12-24 16:58 214360 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\TjVista.dll
2009-12-24 16:58 . 2009-12-24 16:58 337240 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\TjIpSys.dll
2009-12-24 16:58 . 2009-12-24 16:58 607600 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\SJHandsetMagicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 87384 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\st00000\mjsetup.exe
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\st00000\magicJack.dll
2009-12-24 16:57 . 2009-12-24 16:57 93016 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\magicJack.dll
2009-12-24 16:55 . 2009-12-24 16:55 12482904 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\magicJack.exe
2009-12-24 16:54 . 2010-01-05 11:20 730032 —ha-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\Upgrade\install2.exe
2009-12-24 16:54 . 2009-12-24 16:54 730032 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ug00000\install.exe
2009-12-24 16:53 . 2009-12-24 16:53 87384 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\in00000\mjsetup.exe
2009-12-24 16:53 . 2009-12-24 16:53 93016 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\in00000\magicJack.dll
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\st00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\in00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 50520 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\cdloader2.exe
2009-12-21 19:14 . 2001-08-23 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-12-21 00:33 . 2009-12-21 00:32 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-12-20 00:29 . 2009-12-20 00:29 ——– d—–w- c:\documents and settings\Dawn Walker\Application Data\SolwaySoftware
2009-12-16 23:03 . 2009-03-17 04:24 216064 —-a-w- c:\windows\iun3405.exe
2009-12-09 01:19 . 2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\DropboxExt.13.dll
2009-12-02 10:12 . 2009-12-02 10:12 4254224 —-a-w- c:\windows\system32\qtp-mt334.dll
2009-12-02 10:12 . 2009-04-09 00:46 40560 —-a-w- c:\windows\system32\drivers\hotcore3.sys
2009-12-02 10:12 . 2008-12-13 18:47 385544 —-a-w- c:\windows\system32\drivers\Uim_IM.sys
2009-12-02 10:12 . 2008-12-13 18:47 34392 —-a-w- c:\windows\system32\drivers\UimBus.sys
2009-12-02 10:12 . 2008-12-13 18:47 261416 —-a-w- c:\windows\system32\drivers\UimFIO.sys
2009-12-02 05:10 . 2008-12-23 09:22 53680 —-a-w- c:\documents and settings\Dawn Walker\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-30 02:26 . 2009-11-30 02:14 43488992 —-a-w- c:\documents and settings\All Users\Application Data\Systweak\Advanced System Protector\Antispyware_Setup_11_29_2009.exe
2009-11-22 17:40 . 2009-11-21 01:21 8892928 —-a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2009-11-21 15:51 . 2001-08-23 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-10-21 20:40 . 2009-10-21 20:35 8628 —ha-w- c:\program files\GMOUSE.GID
2009-10-21 20:34 . 2009-10-21 20:33 12800 –sha-w- c:\program files\Thumbs.db
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Dawn Walker\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="c:\program files\AOL 9.1\AOL.EXE" [2008-11-06 50472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=c:\windows\pss\Microsoft Find Fast.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^setup.exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\setup.exe
backup=c:\windows\pss\setup.exeCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Dawn Walker^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\documents and settings\Dawn Walker\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Dawn Walker^Start Menu^Programs^Startup^ProjectWhois.lnk]
path=c:\documents and settings\Dawn Walker\Start Menu\Programs\Startup\ProjectWhois.lnk
backup=c:\windows\pss\ProjectWhois.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2008-11-06 11:42 50472 —-a-w- c:\program files\AOL 9.1\aol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2009-12-24 16:52 50520 —-a-w- c:\documents and settings\Dawn Walker\Application Data\mjusbsp\cdloader2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
2007-03-15 23:16 454784 —-a-w- c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechGalleryRepair]
2002-12-10 23:32 155648 —-a-w- c:\program files\Logitech\ImageStudio\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechImageStudioTray]
2002-12-10 23:31 61440 —-a-w- c:\program files\Logitech\ImageStudio\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
2002-12-10 22:54 127022 —-a-w- c:\program files\Common Files\Logitech\QCDriver3\LVComS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-01-07 21:07 1394000 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 –sh–w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 16:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 16:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 16:22 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 16:22 1622016 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 09:17 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RDSessMgr"=3 (0x3)
"ose"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\aol\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\aol\\1230174480\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\aol\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\att-nap\\McciBrowser.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Documents and Settings\\Dawn Walker\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Documents and Settings\\Dawn Walker\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5060:UDP"= 5060:UDP:MagicJack
"5070:UDP"= 5070:UDP:MagicJack
"3587:TCP"= 3587:TCP:*:Disabled:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:*:Disabled:Peer Name Resolution Protocol (PNRP)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [4/8/2009 7:46 PM 40560]
S3 BCASPROT;Advanced System Protector;c:\program files\Systweak\Advanced System Protector\sasprot32.sys [5/4/2009 3:08 PM 6656]
S3 m4cxwxp;NDIS5.1 Miniport Driver for D-Link DGE-530T Gigabit Ethernet Adapter;c:\windows\system32\DRIVERS\m4cxwxp.sys –> c:\windows\system32\DRIVERS\m4cxwxp.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [12/25/2009 7:46 PM 19712]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [12/25/2009 7:46 PM 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [12/25/2009 7:46 PM 42752]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [12/25/2009 7:47 PM 23680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-13 c:\windows\Tasks\User_Feed_Synchronization-{31ECF41F-8A99-45FE-8EAC-D7822BB0FA0C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ask.com/?o=15709&l;=dis
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101703&gct;=&gc;=1&q;=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: 0.0.0.0
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-emerald-city-confidential/EmeraldCityConfidential_Web.1.0.0.9.cab
DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} - hxxp://cdn.ll.neoedge.com/webgames/MysteryofSharkIsland/MysteryOfSharkIslandWeb.1.0.0.8.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-rainforest-adventure/gamehouseplayer.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://games.pogo.com/online2/pogo/bookworm_adventures/popcaploader_v10.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-12 23:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-02-13 00:01:50
ComboFix-quarantined-files.txt 2010-02-13 05:01
ComboFix2.txt 2010-02-12 04:29

Pre-Run: 40,355,569,664 bytes free
Post-Run: 40,316,649,472 bytes free

- - End Of File - - 3590F702073DE7E3DBFE972CA767FFDB
Just a little FYI,
Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.


Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    If you used DeFogger
    You must remember to re-enable your Emulation drivers once we are finished, double click DeFogger to run the tool.

    • The application window will appear
    • Click the Re-enable button to re-enable your CD Emulation drivers
    • Click Yes to continue
    • A 'Finished!' message will appear
    • Click OK
    • DeFogger will now ask to reboot the machine - click OK
    IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

    Your Emulation drivers are now re-enabled.


    To be on the safe side, I would also change all my passwords.



    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI