This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected Computer

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good evening,

My computer was infected with a trojan horse and an account on my computer was hacked into. My computer has also been very slow since this as well. I have worked through suggested instructions and will post the logs below. Please help!!

mbam-log

Malwarebytes' Anti-Malware 1.44
Database version: 3777
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

22/02/2010 20:54:21
mbam-log-2010-02-22 (20-54-21).txt

Scan type: Quick Scan
Objects scanned: 121349
Time elapsed: 12 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 30
Registry Values Infected: 1
Registry Data Items Infected: 4
Folders Infected: 3
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\safefileoperations.encryptfile (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\safefileoperations.encryptfile.1 (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\safefileoperations.securedelete (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\safefileoperations.securedelete.1 (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1d27f0f6-418c-4645-bb9b-f1d75eb4e7ef} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3213be8d-02eb-4ddf-b7f8-9501463e63d6} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6cd0567f-493a-4ac8-8542-00427917bfff} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9ae6710d-b16a-4aee-b96c-c93439cbd814} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c721e836-3e81-43f4-971f-4a6e324e2561} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e7fb27a8-a84c-4ea5-95df-732092ddc018} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{28d2c24e-7f71-4b2c-86d8-5ec1ad73afd6} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6b488e78-3548-4cbc-8828-781efb6c771b} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{0ccb715f-ea4e-4afa-aa31-9b3efc5fc803} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{19d73fc5-ba35-458e-b68d-0e79816f78bd} (Rogue.SecureFileShredder) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.AntiVirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178f3fb-2560-458f-bdee-631e2fe0dfe4} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b5141620-c2b2-4d95-9f0f-134d99c87ab0} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5c3f6257-3e00-45c2-88d5-cb0f3a17bf0e} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6f87f145-dc2d-4766-af03-3a3b96ffad98} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uss_{20cf7fd9-6c26-450b-bc5b-b4ad67438a26}_is1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\USS (Trojan.FakeAlert) -> Delete on reboot.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: c:\windows\system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\Compaq_Owner\Application Data\AntiSpywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AV9 (Rogue.AntiVirus2009) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec (Stolen.data) -> Delete on reboot.

Files Infected:
C:\WINDOWS\vbahyiy.gqh (Trojan.Gumblar) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\user.ds.lll (Stolen.data) -> Delete on reboot.
C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk (Rogue.AntiVirus2009) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sdra64.exe (Spyware.Zbot) -> Delete on reboot.

gmer

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-22 23:00:39
Windows 5.1.2600 Service Pack 3
Running: 23qdct3b.exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kgpiaaod.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 …
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x46 0x47 0x15 0xB0 …
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 …
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 …
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 …
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 …
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA …
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC …
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 …
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x37 0xA4 0xAA 0xC3 …
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 …
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0x05 0x73 0x21 0xDD …

—- Files - GMER 1.0.15 —-

File C:\$AVG\$CHJW\16769d00-455a-4acf-81e8-b3fffd90a4af 185160 bytes

—- EOF - GMER 1.0.15 —-

attach-log


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 03/12/2004 16:57:47
System Uptime: 23/02/2010 15:53:02 (1 hours ago)

Motherboard: ASUSTeK Computer INC. | | Grouper
Processor: Intel® Pentium® 4 CPU 2.66GHz | CPU 1 | 2665/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 53 GiB total, 25.743 GiB free.
D: is FIXED (FAT32) - 4 GiB total, 1.181 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP567: 13/11/2009 09:55:41 - System Checkpoint
RP568: 14/11/2009 14:05:02 - System Checkpoint
RP569: 15/11/2009 14:59:01 - System Checkpoint
RP570: 16/11/2009 15:47:14 - System Checkpoint
RP571: 17/11/2009 20:10:04 - System Checkpoint
RP572: 19/11/2009 15:33:03 - System Checkpoint
RP573: 20/11/2009 18:33:16 - System Checkpoint
RP574: 21/11/2009 18:48:29 - System Checkpoint
RP575: 22/11/2009 19:12:42 - System Checkpoint
RP576: 24/11/2009 19:34:11 - System Checkpoint
RP577: 27/11/2009 07:11:01 - Software Distribution Service 3.0
RP578: 27/11/2009 08:05:12 - Software Distribution Service 3.0
RP579: 28/11/2009 08:09:50 - System Checkpoint
RP580: 29/11/2009 10:10:56 - System Checkpoint
RP581: 30/11/2009 10:54:49 - System Checkpoint
RP582: 04/12/2009 16:26:32 - System Checkpoint
RP583: 05/12/2009 16:28:36 - System Checkpoint
RP584: 06/12/2009 17:21:30 - System Checkpoint
RP585: 09/12/2009 11:07:30 - System Checkpoint
RP586: 09/12/2009 19:38:54 - Software Distribution Service 3.0
RP587: 10/12/2009 20:20:41 - System Checkpoint
RP588: 12/12/2009 15:33:36 - System Checkpoint
RP589: 13/12/2009 15:45:24 - System Checkpoint
RP590: 14/12/2009 19:39:56 - System Checkpoint
RP591: 15/12/2009 20:49:52 - System Checkpoint
RP592: 16/12/2009 21:35:24 - System Checkpoint
RP593: 17/12/2009 21:38:31 - System Checkpoint
RP594: 19/12/2009 16:24:55 - System Checkpoint
RP595: 20/12/2009 16:39:03 - System Checkpoint
RP596: 21/12/2009 16:43:11 - System Checkpoint
RP597: 22/12/2009 17:54:22 - System Checkpoint
RP598: 23/12/2009 18:44:24 - System Checkpoint
RP599: 26/12/2009 10:26:49 - System Checkpoint
RP600: 27/12/2009 10:40:34 - System Checkpoint
RP601: 28/12/2009 11:40:38 - System Checkpoint
RP602: 29/12/2009 11:41:42 - System Checkpoint
RP603: 30/12/2009 16:57:19 - System Checkpoint
RP604: 31/12/2009 17:39:07 - System Checkpoint
RP605: 01/01/2010 18:39:11 - System Checkpoint
RP606: 03/01/2010 15:29:00 - System Checkpoint
RP607: 05/01/2010 09:36:28 - System Checkpoint
RP608: 06/01/2010 10:12:36 - System Checkpoint
RP609: 07/01/2010 10:34:40 - System Checkpoint
RP610: 08/01/2010 11:01:06 - System Checkpoint
RP611: 09/01/2010 11:48:24 - System Checkpoint
RP612: 10/01/2010 15:39:14 - System Checkpoint
RP613: 12/01/2010 20:25:48 - Software Distribution Service 3.0
RP614: 13/01/2010 20:28:02 - System Checkpoint
RP615: 14/01/2010 03:00:25 - Software Distribution Service 3.0
RP616: 17/01/2010 13:47:59 - System Checkpoint
RP617: 18/01/2010 14:05:25 - System Checkpoint
RP618: 18/01/2010 17:12:45 - Installed Windows XP KB954708.
RP619: 18/01/2010 17:14:23 - Installed DirectX
RP620: 19/01/2010 20:20:15 - System Checkpoint
RP621: 20/01/2010 21:02:36 - System Checkpoint
RP622: 21/01/2010 03:00:26 - Software Distribution Service 3.0
RP623: 22/01/2010 03:02:35 - System Checkpoint
RP624: 23/01/2010 03:00:20 - Software Distribution Service 3.0
RP625: 24/01/2010 03:34:06 - System Checkpoint
RP626: 25/01/2010 04:34:06 - System Checkpoint
RP627: 26/01/2010 05:34:04 - System Checkpoint
RP628: 27/01/2010 06:23:10 - System Checkpoint
RP629: 29/01/2010 10:13:10 - System Checkpoint
RP630: 30/01/2010 10:51:24 - System Checkpoint
RP631: 31/01/2010 11:33:18 - System Checkpoint
RP632: 02/02/2010 16:14:13 - System Checkpoint
RP633: 05/02/2010 10:25:47 - System Checkpoint
RP634: 06/02/2010 12:52:07 - System Checkpoint
RP635: 07/02/2010 13:34:49 - System Checkpoint
RP636: 08/02/2010 17:09:32 - Installed Windows Installer Clean Up
RP637: 09/02/2010 18:16:52 - System Checkpoint
RP638: 09/02/2010 19:52:28 - Software Distribution Service 3.0
RP639: 10/02/2010 19:57:49 - System Checkpoint
RP640: 11/02/2010 18:05:01 - Installed Windows Installer Clean Up
RP641: 11/02/2010 18:34:03 - Installed AVG Free 9.0
RP642: 11/02/2010 23:19:51 - Avg8 Update
RP643: 16/02/2010 18:39:01 - Removed Digimax Master
RP644: 19/02/2010 19:12:11 - Removed QUAD RegistryCleaner
RP645: 22/02/2010 17:56:55 - Restore Operation
RP646: 22/02/2010 18:16:21 - Restore Operation
RP647: 22/02/2010 20:23:56 - Automatic Restore Point

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Agere Systems PCI Soft Modem
ArcSoft Software Suite
AVG Free 9.0
Disney's Princess Royal Horse Show
Enhanced Multimedia Keyboard Solution
ERUNT 1.1j
FinePixViewer Ver.4.2
FUJIFILM USB Driver
Google Toolbar for Internet Explorer
Help and Support Additions
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Image Zone 4.2
HP PSC & OfficeJet 4.2
IBM ViaVoice Command and Control Runtime 5.3 - UK English
IBM ViaVoice Outloud Runtime - UK English
ImageMixer VCD2 for FinePix
Indeo® Software
Intel® Graphics Media Accelerator Driver
iTunes
Let's Ride 3 Day Eventing - Championship Season
Macromedia Shockwave Player
Madagascar Paint And Create
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MicroStaff WINASPI
Mozilla Firefox (3.5.8)
MSN
NetTurboPro [removed]
On2 VP3 Video for Windows Codec
Pippa Funnell
ProductContext
PS2
QuickTime
Riding Star
Samsung USB Driver
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
SmartDraw 2010
SpeedTouch USB Software
SpywareBlaster 4.2
SpywareGuard v2.2
TorrentMan Toolbar
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Essentials
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Yahoo! Toolbar

==== End Of File ===========================

dds-log


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:36:29.14 on 23/02/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13

============== Pseudo HJT Report ===============

uStart Page = hxxp://uk.search.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=presario&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=presario&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Bitlord Toolbar: {7c5c0f58-e061-457d-9033-77307f5ed00c} - c:\program files\torrentman\tbTor1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.0.1225.9868\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
TB: Bitlord Toolbar: {7c5c0f58-e061-457d-9033-77307f5ed00c} - c:\program files\torrentman\tbTor1.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [98349234292833881184332869002066] c:\program files\av9\av2009.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSKAGENTEXE] c:\progra~1\mcafee\spamki~1\MSKAgent.exe
uRun: [Acme.PCHButton] c:\progra~1\helpan~1\presario\xphwwrf4\plugin\bin\pchbutton.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [NetTurboPro] c:\program files\netturbopro\ntp.exe
mRun: [USS] "c:\program files\uss\USS.exe"
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [TalkTalk] "c:\program files\talktalk\bin\sprtcmd.exe" /P TalkTalk
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SpeedTouch USB Diagnostics] "c:\program files\virgin net broadband\Dragdiag.exe" /icon
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [VTTimer] VTTimer.exe
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [iTunesHelper] c:\program files\itunes\iTunesHelper.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Cmehi] rundll32.exe "c:\windows\upohoducexuc.dll",Startup
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
IE: {7F2F6F5A-CAE2-4954-A461-36B3757B2BFB} - c:\program files\stanjamesgibmpp\MPPoker.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214815288656
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
LSA: Notification Packages = scecli CMPInfgr.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\fc61f7j2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_uk&p=
FF - component: c:\documents and settings\compaq_owner\application data\mozilla\firefox\profiles\fc61f7j2.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}\components\FFAlert.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\all users\application data\zylom\zylomgamesplayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: XULRunner: {91968ADB-F9CC-4D4E-A13D-0120B20DF7AF} - c:\documents and settings\compaq_owner\local settings\application data\{91968ADB-F9CC-4D4E-A13D-0120B20DF7AF}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2010-02-20 11:03 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-20 11:03 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-20 11:03 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-11 18:36 –d-h— C:\$AVG
2010-02-11 18:35 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2010-02-11 18:34 –d—– c:\docume~1\alluse~1\applic~1\avg9
2010-02-10 18:46 0 a——- c:\windows\Hwiduyetofiwupu.bin
2010-02-10 18:46 120 a——- c:\windows\Ggeju.dat
2010-02-09 19:47 921 a——- c:\windows\QSFVExit.bat
2010-02-09 19:43 –d—– c:\docume~1\alluse~1\applic~1\FileCure
2010-02-09 19:43 –d—– c:\program files\ParetoLogic
2010-02-09 19:29 –d—– c:\program files\QuickSFV
2010-02-08 17:45 –d—– c:\docume~1\alluse~1\applic~1\Trymedia
2010-02-08 17:09 –d—– c:\program files\Windows Installer Clean Up
2010-02-08 17:08 –d—– c:\program files\MSECACHE
2010-02-08 15:44 –d—– c:\program files\Conduit
2010-02-08 15:44 –d—– c:\program files\TorrentMan
2010-02-02 16:33 –d-h— c:\windows\PIF

==================== Find3M ====================

2010-02-11 18:35 360,584 a——- c:\windows\system32\drivers\avgtdix.sys
2010-02-11 18:35 333,192 a——- c:\windows\system32\drivers\avgldx86.sys
2010-02-11 18:35 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-02-09 19:32 185,320 a——- c:\windows\pchealth\helpctr\config\cache\Personal_32_1033.dat
2009-12-31 16:50 353,792 a——- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-16 18:43 343,040 a——- c:\windows\system32\mspaint.exe
2009-12-14 07:08 33,280 a——- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 2,189,184 a——- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 2,066,048 a——- c:\windows\system32\ntkrnlpa.exe
2009-11-27 17:11 1,291,776 a——- c:\windows\system32\quartz.dll
2009-11-27 17:11 17,920 a——- c:\windows\system32\msyuv.dll
2009-11-27 16:07 28,672 a——- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 8,704 a——- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 84,992 a——- c:\windows\system32\avifil32.dll
2009-11-27 16:07 48,128 a——- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07 11,264 a——- c:\windows\system32\msrle32.dll
2008-07-18 13:49 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008071820080719\index.dat

============= FINISH: 16:38:58.75 ===============
Hello.

One of the infection I see is a Trojan.Stealer also known as password stealer. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Let's begin with Combofix.

Download and Run Combofix

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page on instructions on doing so.

Please include the C:\ComboFix.txt in your next reply for further review.
good evening,

thanks for help, below is the log you requested,

ComboFix 10-02-23.04 - Compaq_Owner 24/02/2010 19:03:49.7.1 - x86
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\USS
c:\program files\USS\{20CF7FD9-6C26-450b-BC5B-B4AD67438A26}\AppBase\pfilelst.xda
c:\program files\USS\{20CF7FD9-6C26-450b-BC5B-B4AD67438A26}\AppBase\wordslst.xda
c:\program files\USS\{20CF7FD9-6C26-450b-BC5B-B4AD67438A26}\bnlink.dat
c:\program files\USS\{20CF7FD9-6C26-450b-BC5B-B4AD67438A26}\DCPlugin.dll
c:\program files\USS\{20CF7FD9-6C26-450b-BC5B-B4AD67438A26}\DCPlugin.xml
c:\program files\USS\{20CF7FD9-6C26-450b-BC5B-B4AD67438A26}\ScanReport.dat
c:\program files\USS\Schedule.dat
c:\program files\USS\unins000.dat
c:\program files\USS\unins000.exe
c:\program files\USS\USS.exe
c:\windows\system32\logs
c:\windows\system32\logs\UA.log
c:\windows\system32\ps2.bat
c:\windows\system32\Vbshell.tlb

.
((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.

2010-02-23 19:00 . 2010-02-23 19:00 ——– d-sh–w- c:\documents and settings\Default User\IETldCache
2010-02-23 18:56 . 2010-02-23 18:56 ——– d—–w- c:\windows\system32\XPSViewer
2010-02-23 18:56 . 2010-02-23 18:56 ——– d—–w- c:\program files\MSBuild
2010-02-23 18:55 . 2010-02-23 18:55 ——– d—–w- c:\program files\Reference Assemblies
2010-02-23 18:55 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-02-23 18:53 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-02-23 18:53 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2010-02-23 18:53 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-02-23 18:53 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-02-23 18:53 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-02-23 18:53 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2010-02-23 18:53 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2010-02-23 18:53 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2010-02-23 18:53 . 2010-02-23 18:55 ——– d—–w- C:\593ae7cdbd7768f57473
2010-02-23 18:36 . 2010-02-23 18:36 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-02-23 17:45 . 2010-02-23 18:08 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\vlc
2010-02-22 20:02 . 2010-02-22 20:03 ——– d—–w- c:\program files\ERUNT
2010-02-20 11:03 . 2010-01-07 16:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-20 11:03 . 2010-01-07 16:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-20 11:03 . 2010-02-22 20:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-15 20:54 . 2007-10-23 09:27 110592 —-a-w- c:\documents and settings\Compaq_Owner\Application Data\U3\temp\cleanup.exe
2010-02-15 20:54 . 2008-05-02 10:41 3493888 —ha-w- c:\documents and settings\Compaq_Owner\Application Data\U3\temp\Launchpad Removal.exe
2010-02-15 18:34 . 2010-02-15 21:34 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\U3
2010-02-12 18:13 . 2010-02-12 18:13 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\AVG Security Toolbar
2010-02-11 23:19 . 2010-02-11 18:34 1260800 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-02-11 23:19 . 2010-02-11 18:34 3777280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-02-11 18:36 . 2010-02-11 18:40 ——– d—–w- C:\$AVG
2010-02-11 18:35 . 2010-02-11 18:37 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-02-11 18:34 . 2010-02-12 16:57 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-02-11 18:05 . 2010-02-11 18:05 3584 —-a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-02-10 18:46 . 2010-02-20 10:32 0 —-a-w- c:\windows\Hwiduyetofiwupu.bin
2010-02-10 18:46 . 2010-02-20 13:35 120 —-a-w- c:\windows\Ggeju.dat
2010-02-10 18:46 . 2010-02-10 18:46 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\{91968ADB-F9CC-4D4E-A13D-0120B20DF7AF}
2010-02-10 18:34 . 2010-02-10 18:34 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-02-09 19:47 . 2010-02-09 19:47 921 —-a-w- c:\windows\QSFVExit.bat
2010-02-09 19:43 . 2010-02-09 19:43 ——– d—–w- c:\documents and settings\All Users\Application Data\FileCure
2010-02-09 19:43 . 2010-02-09 19:43 ——– d—–w- c:\program files\ParetoLogic
2010-02-09 19:29 . 2010-02-09 19:29 ——– d—–w- c:\program files\QuickSFV
2010-02-08 18:03 . 2010-02-08 18:03 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Conduit
2010-02-08 18:03 . 2010-02-10 18:13 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\TorrentMan
2010-02-08 17:45 . 2010-02-08 17:45 ——– d—–w- c:\documents and settings\All Users\Application Data\Trymedia
2010-02-08 17:09 . 2010-02-11 18:05 ——– d—–w- c:\program files\Windows Installer Clean Up
2010-02-08 17:08 . 2010-02-11 18:04 ——– d—–w- c:\program files\MSECACHE
2010-02-08 15:54 . 2008-05-27 16:45 11776 —-a-w- c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\fc61f7j2.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}\components\FFAlert.dll
2010-02-08 15:54 . 2008-05-27 16:45 114688 —-a-w- c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\fc61f7j2.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}\components\npmozax.dll
2010-02-08 15:44 . 2010-02-08 15:44 ——– d—–w- c:\program files\Conduit
2010-02-08 15:44 . 2010-02-08 18:03 ——– d—–w- c:\program files\TorrentMan
2010-02-02 16:33 . 2010-02-02 16:33 ——– d–h–w- c:\windows\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-24 17:14 . 2004-12-25 17:10 35792 —-a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-20 10:27 . 2008-06-30 11:00 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-19 19:46 . 2008-06-30 11:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-19 19:10 . 2008-04-06 17:01 ——– d—–w- c:\program files\NetTurboPro
2010-02-16 18:39 . 2004-01-01 09:36 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-16 18:37 . 2005-12-14 08:58 ——– d—–w- c:\program files\BitLord
2010-02-15 18:27 . 2009-11-15 13:44 79488 —-a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-12 17:04 . 2008-02-20 09:31 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-11 18:35 . 2008-06-29 14:37 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-11 18:35 . 2008-06-29 14:37 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-02-11 18:35 . 2008-06-29 14:37 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-11 18:35 . 2008-06-29 14:37 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-11 18:34 . 2008-06-29 14:37 ——– d—–w- c:\program files\AVG
2010-02-09 19:32 . 2010-02-22 17:28 185320 —-a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1033.dat
2010-02-08 16:45 . 2009-06-14 12:00 ——– d—–w- c:\program files\SpywareBlaster
2010-01-19 16:34 . 2009-08-10 10:39 ——– d—–w- c:\program files\Windows Live
2010-01-19 16:34 . 2010-01-19 16:34 ——– d—–w- c:\program files\Microsoft Sync Framework
2010-01-18 17:13 . 2010-01-18 17:13 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2010-01-18 17:08 . 2010-01-18 17:08 ——– d—–w- c:\program files\Microsoft
2009-12-31 16:50 . 2004-01-01 21:51 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-01-01 21:52 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2004-01-01 21:50 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-01-01 21:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 . 2004-01-01 21:50 2189184 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-04 05:59 2066048 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2004-01-01 21:50 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:11 . 2004-08-04 07:56 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:11 . 2004-01-01 21:50 1291776 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 16:07 . 2004-01-01 21:50 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-18 05:36 8704 —-a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-04 07:56 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07 . 2004-01-01 21:50 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-01-01 21:42 84992 —-a-w- c:\windows\system32\avifil32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7c5c0f58-e061-457d-9033-77307f5ed00c}]
2010-02-08 18:04 2166296 —-a-w- c:\program files\TorrentMan\tbTor1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7c5c0f58-e061-457d-9033-77307f5ed00c}"= "c:\program files\TorrentMan\tbTor1.dll" [2010-02-08 2166296]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{7c5c0f58-e061-457d-9033-77307f5ed00c}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7C5C0F58-E061-457D-9033-77307F5ED00C}"= "c:\program files\TorrentMan\tbTor1.dll" [2010-02-08 2166296]

[HKEY_CLASSES_ROOT\clsid\{7c5c0f58-e061-457d-9033-77307f5ed00c}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSKAGENTEXE"="c:\progra~1\McAfee\SPAMKI~1\MSKAgent.exe" [2005-03-23 126976]
"Acme.PCHButton"="c:\progra~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe" [2004-01-01 159744]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetTurboPro"="c:\program files\NetTurboPro\ntp.exe" [2008-01-24 585728]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"TalkTalk"="c:\program files\TalkTalk\bin\sprtcmd.exe" [2005-08-16 192512]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-01-01 98304]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"SpeedTouch USB Diagnostics"="c:\program files\Virgin Net Broadband\Dragdiag.exe" [2004-01-26 866816]
"AlcWzrd"="ALCWZRD.EXE" [2005-04-06 2805248]
"SoundMan"="SOUNDMAN.EXE" [2005-04-06 90112]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 88209]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-04-21 286720]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
Media Card Companion Monitor.lnk - c:\program files\ArcSoft\Software Suite\Media Card Companion\MCC Monitor.exe [2005-12-28 98304]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-02-11 18:35 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [29/06/2008 14:37 333192]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [29/06/2008 14:37 360584]
R1 DrvPrt;DrvPrt;c:\windows\system32\drivers\drvprt.sys [25/04/2008 17:46 58396]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [11/02/2010 18:34 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/02/2010 18:34 285392]
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\FileCure Startup.job
- c:\program files\ParetoLogic\FileCure\FileCure.exe [2009-12-13 00:57]

2010-02-17 c:\windows\Tasks\FileCure.job
- c:\program files\ParetoLogic\FileCure\FileCure.exe [2009-12-13 00:57]

2010-02-24 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2009-08-29 16:21]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://uk.search.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=presario&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=presario&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: {{7F2F6F5A-CAE2-4954-A461-36B3757B2BFB} - c:\program files\stanjamesgibMPP\MPPoker.exe
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\fc61f7j2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_uk&p=
FF - component: c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\fc61f7j2.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}\components\FFAlert.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: XULRunner: {91968ADB-F9CC-4D4E-A13D-0120B20DF7AF} - c:\documents and settings\Compaq_Owner\Local Settings\Application Data\{91968ADB-F9CC-4D4E-A13D-0120B20DF7AF}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-*{7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
WebBrowser-{5CBE2611-C31B-401F-89BC-4CBB25E853D7} - (no file)
HKLM-Run-VTTimer - VTTimer.exe
HKLM-Run-Cmehi - c:\windows\upohoducexuc.dll
AddRemove-Macromedia Shockwave Player - c:\windows\system32\Macromed\SHOCKW~1\UNWISE.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-24 19:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3008)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\ALCWZRD.EXE
c:\windows\SOUNDMAN.EXE
c:\windows\AGRSMMSG.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2010-02-24 19:54:34 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-24 19:54
ComboFix2.txt 2008-06-24 19:01
ComboFix3.txt 2008-06-20 19:54

Pre-Run: 27,398,615,040 bytes free
Post-Run: 27,831,119,872 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect

- - End Of File - - 47E80B77709FE5D79BBF252FFC752023
Hi again,

I see a main infection here, related to FireFox. Do the following please…

Download and Run GooredFix

Please download GooredFix and save it to your Desktop if you lost your copy.
Alternative Download Mirror #1

Please make sure all instances of Firefox are closed at this point before proceeding.

  • Ensure all Firefox windows are closed at this time.
  • Please double-click GooredFix.exe on your Desktop to run it. If you are using Vista, please right-click and select run as administartor
  • When prompted to run the scan, click Yes.
  • The removal process will begin, please be paitent until it finishes.
  • A log will open with the file after completion, please post the contents of that log in your next reply
*Note: The log can also be found on your desktop called GooredFix.txt


Download and Run OTM

  • Please download OTM by OldTimer and save it to your desktop.
  • Double click the [external image: Posted Image] icon on your desktop If you are running on Vista, right click on the file and choose Run As Administrator.
  • Paste the following code under the [external image: Posted Image] area. Do not include the word "Code".
    :files
    c:\documents and settings\Compaq_Owner\Local Settings\Application Data\{91968ADB-F9CC-4D4E-A13D-0120B20DF7AF}
    c:\windows\Hwiduyetofiwupu.bin
    c:\windows\Ggeju.dat
    :Commands
    [CREATERESTOREPOINT]
    [emptytemp]
    [Reboot]
  • Click the large [external image: Posted Image] button.
  • If OTM requires are reboot, please allow it to do so.
  • Copy/Paste the contents under the [external image: Posted Image] line here in your next reply.
Note: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Update and Scan with MalwareBytes Anti-Malware

  • Launch Malwarebytes' Anti-Malware
  • Go to the Update tab
  • Select Check for Update and let MBAM download and install any available updates.
  • After the update is complete go to the Scanner tab.
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

With Regards,
Extremeboy
Good evening Extremeboy, Below are the logs you requested, Gooredfix, GooredFix by jpshortstuff (08.01.10.1) Log created at 18:58 on 25/02/2010 (Compaq_Owner) Firefox version 3.5.8 (en-GB) ========== GooredScan ========== Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{91968ADB-F9CC-4D4E-A13D-0120B20DF7AF} -> Success! Deleting C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\{91968ADB-F9CC-4D4E-A13D-0120B20DF7AF} -> Success! ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [11:45 30/06/2008] {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [19:08 20/01/2009] {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [09:58 28/06/2009] C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\fc61f7j2.default\extensions\ {097d3191-e6fa-4728-9826-b533d755359d} [16:05 18/01/2010] {20a82645-c095-46ed-80e3-08825760534b} [18:53 25/02/2010] {635abd67-4fe9-1b23-4f01-e679fa7484c1} [15:59 09/02/2009] {7c5c0f58-e061-457d-9033-77307f5ed00c} [15:54 08/02/2010] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [19:07 20/01/2009] "{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG9\Firefox" [18:34 11/02/2010] "avg@igeared"="C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared" [18:35 11/02/2010] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [19:03 23/02/2010] -=E.O.F=- OTM, All processes killed ========== FILES ========== File/Folder c:\documents and settings\Compaq_Owner\Local Settings\Application Data\{91968ADB-F9CC-4D4E-A13D-0120B20DF7AF} not found. c:\windows\Hwiduyetofiwupu.bin moved successfully. c:\windows\Ggeju.dat moved successfully. ========== COMMANDS ========== Restore point Set: OTM Restore Point (64424509440) [EMPTYTEMP] User: All Users User: Compaq_Owner ->Temp folder emptied: 555095 bytes ->Temporary Internet Files folder emptied: 9843881 bytes ->Java cache emptied: 93750163 bytes ->FireFox cache emptied: 63214147 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 65748 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 936541 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 4179456 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 22206 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 10953922 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 175.00 mb OTM by OldTimer - Version 3.1.9.0 log created on 02252010_190750 Files moved on Reboot… Registry entries deleted on Reboot… MBAM, Malwarebytes' Anti-Malware 1.44 Database version: 3792 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 25/02/2010 19:57:36 mbam-log-2010-02-25 (19-57-36).txt Scan type: Quick Scan Objects scanned: 116685 Time elapsed: 24 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Looking good. Let's get an online scan and a new DDS scan to make sure all is good.

Run ESET Online Scan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
You can refer to this animation by neomage if needed.

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
Good Evening, Below are the reports you requested, ESESScan C:\Documents and Settings\Compaq_Owner\My Documents\Downloads\setup.exe multiple threats deleted - quarantined C:\Program Files\Online Services\BTESAT\1890hp.exe probably a variant of Win32/Hupigon trojan cleaned by deleting - quarantined C:\QooBox\Quarantine\C\Program Files\Common Files\CryptDrive\cdcw.exe.vir probably a variant of Win32/Adware.RogueApp application cleaned by deleting - quarantined DSS, C:\Documents and Settings\Compaq_Owner\My Documents\Downloads\setup.exe multiple threats deleted - quarantined C:\Program Files\Online Services\BTESAT\1890hp.exe probably a variant of Win32/Hupigon trojan cleaned by deleting - quarantined C:\QooBox\Quarantine\C\Program Files\Common Files\CryptDrive\cdcw.exe.vir probably a variant of Win32/Adware.RogueApp application cleaned by deleting - quarantined My computer is still running slow but has improved since a few days ago, the start is especially and there are several pop ups during it. Let me know if you need to see these and what would be the best way post them. Thanks again
Hello again.

You forgot the DDS scan ;)

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply.

This is the DDS scan if you forgot what it was…

Download and run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results soon.
  • Follow the instructions that pop up for posting the results and then click Ok.
  • The black and message box window shall then disappear.
  • Please save both log files on your desktop and post the DDS.txt and zip up and attach Attach.txt as instructed.

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE
Good Morning, Sorry about that, DSS, DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 11:10:33.65 on 28/02/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.247.15 [GMT 0:00] AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe svchost.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\wscntfy.exe C:\HP\KBD\KBD.EXE ============== Pseudo HJT Report =============== uStart Page = hxxp://uk.search.yahoo.com/ uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=presario&pf=desktop uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=presario&pf=desktop uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = uSearchURL,(Default) = hxxp://www.google.com/search?q=%s uURLSearchHooks: H - No File uURLSearchHooks: H - No File BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Bitlord Toolbar: {7c5c0f58-e061-457d-9033-77307f5ed00c} - c:\program files\torrentman\tbTor1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.0.1225.9868\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File TB: Bitlord Toolbar: {7c5c0f58-e061-457d-9033-77307f5ed00c} - c:\program files\torrentman\tbTor1.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [MSKAGENTEXE] c:\progra~1\mcafee\spamki~1\MSKAgent.exe uRun: [Acme.PCHButton] c:\progra~1\helpan~1\presario\xphwwrf4\plugin\bin\pchbutton.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [NetTurboPro] c:\program files\netturbopro\ntp.exe mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [TalkTalk] "c:\program files\talktalk\bin\sprtcmd.exe" /P TalkTalk mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [SpeedTouch USB Diagnostics] "c:\program files\virgin net broadband\Dragdiag.exe" /icon mRun: [AlcWzrd] ALCWZRD.EXE mRun: [SoundMan] SOUNDMAN.EXE mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [iTunesHelper] c:\program files\itunes\iTunesHelper.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" IE: {7F2F6F5A-CAE2-4954-A461-36B3757B2BFB} - c:\program files\stanjamesgibmpp\MPPoker.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214815288656 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\fc61f7j2.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - prefs.js: browser.search.selectedEngine - Yahoo! Search FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157 FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_uk&p= FF - component: c:\documents and settings\compaq_owner\application data\mozilla\firefox\profiles\fc61f7j2.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}\components\FFAlert.dll FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2010-02-27 15:54 –d—– c:\program files\ESET 2010-02-25 19:07 –d—– C:\_OTM 2010-02-24 18:54 a-dshr– C:\cmdcons 2010-02-24 18:40 77,312 a——- c:\windows\MBR.exe 2010-02-24 18:40 261,632 a——- c:\windows\PEV.exe 2010-02-24 17:42 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat 2010-02-23 18:56 –d—– c:\windows\system32\XPSViewer 2010-02-23 18:53 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2010-02-23 18:53 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2010-02-23 18:53 117,760 ——– c:\windows\system32\prntvpt.dll 2010-02-23 18:53 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2010-02-23 18:53 575,488 ——– c:\windows\system32\xpsshhdr.dll 2010-02-23 18:53 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2010-02-23 18:53 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2010-02-23 18:53 –d—– C:\593ae7cdbd7768f57473 2010-02-20 11:03 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-20 11:03 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-02-20 11:03 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-02-11 18:36 –d—– C:\$AVG 2010-02-11 18:35 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar 2010-02-11 18:34 –d—– c:\docume~1\alluse~1\applic~1\avg9 2010-02-09 19:47 921 a——- c:\windows\QSFVExit.bat 2010-02-09 19:43 –d—– c:\docume~1\alluse~1\applic~1\FileCure 2010-02-09 19:43 –d—– c:\program files\ParetoLogic 2010-02-09 19:29 –d—– c:\program files\QuickSFV 2010-02-08 17:45 –d—– c:\docume~1\alluse~1\applic~1\Trymedia 2010-02-08 17:09 –d—– c:\program files\Windows Installer Clean Up 2010-02-08 17:08 –d—– c:\program files\MSECACHE 2010-02-08 15:44 –d—– c:\program files\Conduit 2010-02-08 15:44 –d—– c:\program files\TorrentMan 2010-02-02 16:33 –d-h— c:\windows\PIF ==================== Find3M ==================== 2010-02-11 18:35 360,584 a——- c:\windows\system32\drivers\avgtdix.sys 2010-02-11 18:35 333,192 a——- c:\windows\system32\drivers\avgldx86.sys 2010-02-11 18:35 12,464 a——- c:\windows\system32\avgrsstx.dll 2010-02-09 19:32 185,320 a——- c:\windows\pchealth\helpctr\config\cache\Personal_32_1033.dat 2009-12-31 16:50 353,792 a——- c:\windows\system32\drivers\srv.sys 2009-12-21 19:14 916,480 ——– c:\windows\system32\wininet.dll 2009-12-16 18:43 343,040 a——- c:\windows\system32\mspaint.exe 2009-12-14 07:08 33,280 a——- c:\windows\system32\csrsrv.dll 2009-12-08 19:27 2,189,184 ——– c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43 2,066,048 ——– c:\windows\system32\ntkrnlpa.exe 2008-07-18 13:49 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008071820080719\index.dat ============= FINISH: 11:14:01.56 =============== Attach, Sorry not sure how to attach zipped file, so here is the log, UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 03/12/2004 16:57:47 System Uptime: 28/02/2010 10:46:18 (1 hours ago) Motherboard: ASUSTeK Computer INC. | | Grouper Processor: Intel® Pentium® 4 CPU 2.66GHz | CPU 1 | 2665/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 53 GiB total, 25.573 GiB free. D: is FIXED (FAT32) - 4 GiB total, 1.181 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP581: 30/11/2009 10:54:49 - System Checkpoint RP582: 04/12/2009 16:26:32 - System Checkpoint RP583: 05/12/2009 16:28:36 - System Checkpoint RP584: 06/12/2009 17:21:30 - System Checkpoint RP585: 09/12/2009 11:07:30 - System Checkpoint RP586: 09/12/2009 19:38:54 - Software Distribution Service 3.0 RP587: 10/12/2009 20:20:41 - System Checkpoint RP588: 12/12/2009 15:33:36 - System Checkpoint RP589: 13/12/2009 15:45:24 - System Checkpoint RP590: 14/12/2009 19:39:56 - System Checkpoint RP591: 15/12/2009 20:49:52 - System Checkpoint RP592: 16/12/2009 21:35:24 - System Checkpoint RP593: 17/12/2009 21:38:31 - System Checkpoint RP594: 19/12/2009 16:24:55 - System Checkpoint RP595: 20/12/2009 16:39:03 - System Checkpoint RP596: 21/12/2009 16:43:11 - System Checkpoint RP597: 22/12/2009 17:54:22 - System Checkpoint RP598: 23/12/2009 18:44:24 - System Checkpoint RP599: 26/12/2009 10:26:49 - System Checkpoint RP600: 27/12/2009 10:40:34 - System Checkpoint RP601: 28/12/2009 11:40:38 - System Checkpoint RP602: 29/12/2009 11:41:42 - System Checkpoint RP603: 30/12/2009 16:57:19 - System Checkpoint RP604: 31/12/2009 17:39:07 - System Checkpoint RP605: 01/01/2010 18:39:11 - System Checkpoint RP606: 03/01/2010 15:29:00 - System Checkpoint RP607: 05/01/2010 09:36:28 - System Checkpoint RP608: 06/01/2010 10:12:36 - System Checkpoint RP609: 07/01/2010 10:34:40 - System Checkpoint RP610: 08/01/2010 11:01:06 - System Checkpoint RP611: 09/01/2010 11:48:24 - System Checkpoint RP612: 10/01/2010 15:39:14 - System Checkpoint RP613: 12/01/2010 20:25:48 - Software Distribution Service 3.0 RP614: 13/01/2010 20:28:02 - System Checkpoint RP615: 14/01/2010 03:00:25 - Software Distribution Service 3.0 RP616: 17/01/2010 13:47:59 - System Checkpoint RP617: 18/01/2010 14:05:25 - System Checkpoint RP618: 18/01/2010 17:12:45 - Installed Windows XP KB954708. RP619: 18/01/2010 17:14:23 - Installed DirectX RP620: 19/01/2010 20:20:15 - System Checkpoint RP621: 20/01/2010 21:02:36 - System Checkpoint RP622: 21/01/2010 03:00:26 - Software Distribution Service 3.0 RP623: 22/01/2010 03:02:35 - System Checkpoint RP624: 23/01/2010 03:00:20 - Software Distribution Service 3.0 RP625: 24/01/2010 03:34:06 - System Checkpoint RP626: 25/01/2010 04:34:06 - System Checkpoint RP627: 26/01/2010 05:34:04 - System Checkpoint RP628: 27/01/2010 06:23:10 - System Checkpoint RP629: 29/01/2010 10:13:10 - System Checkpoint RP630: 30/01/2010 10:51:24 - System Checkpoint RP631: 31/01/2010 11:33:18 - System Checkpoint RP632: 02/02/2010 16:14:13 - System Checkpoint RP633: 05/02/2010 10:25:47 - System Checkpoint RP634: 06/02/2010 12:52:07 - System Checkpoint RP635: 07/02/2010 13:34:49 - System Checkpoint RP636: 08/02/2010 17:09:32 - Installed Windows Installer Clean Up RP637: 09/02/2010 18:16:52 - System Checkpoint RP638: 09/02/2010 19:52:28 - Software Distribution Service 3.0 RP639: 10/02/2010 19:57:49 - System Checkpoint RP640: 11/02/2010 18:05:01 - Installed Windows Installer Clean Up RP641: 11/02/2010 18:34:03 - Installed AVG Free 9.0 RP642: 11/02/2010 23:19:51 - Avg8 Update RP643: 16/02/2010 18:39:01 - Removed Digimax Master RP644: 19/02/2010 19:12:11 - Removed QUAD RegistryCleaner RP645: 22/02/2010 17:56:55 - Restore Operation RP646: 22/02/2010 18:16:21 - Restore Operation RP647: 22/02/2010 20:23:56 - Automatic Restore Point RP648: 23/02/2010 18:31:56 - Software Distribution Service 3.0 RP649: 24/02/2010 17:16:30 - Printer Driver Microsoft XPS Document Writer Installed RP650: 24/02/2010 20:09:25 - Software Distribution Service 3.0 RP651: 25/02/2010 19:09:07 - OTM Restore Point ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Agere Systems PCI Soft Modem ArcSoft Software Suite AVG Free 9.0 Disney's Princess Royal Horse Show Enhanced Multimedia Keyboard Solution ERUNT 1.1j ESET Online Scanner v3 FinePixViewer Ver.4.2 FUJIFILM USB Driver Google Toolbar for Internet Explorer Help and Support Additions High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB954708) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) HP Image Zone 4.2 HP PSC & OfficeJet 4.2 IBM ViaVoice Command and Control Runtime 5.3 - UK English IBM ViaVoice Outloud Runtime - UK English ImageMixer VCD2 for FinePix Indeo® Software Intel® Graphics Media Accelerator Driver iTunes Let's Ride 3 Day Eventing - Championship Season Madagascar Paint And Create Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MicroStaff WINASPI Mozilla Firefox (3.5.8) MSN NetTurboPro [removed] On2 VP3 Video for Windows Codec Pippa Funnell ProductContext PS2 QuickTime Riding Star Samsung USB Driver Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978706) SmartDraw 2010 SpeedTouch USB Software SpywareBlaster 4.2 SpywareGuard v2.2 TorrentMan Toolbar Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB971180) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Installer Clean Up Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Essentials Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 Yahoo! Toolbar ==== Event Viewer Messages From Past Week ======== 26/02/2010 19:47:50, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect. 26/02/2010 19:47:50, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 25/02/2010 19:08:40, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 25/02/2010 19:08:39, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s). 25/02/2010 19:08:39, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 25/02/2010 19:08:39, error: Service Control Manager [7034] - The AVG Free E-mail Scanner service terminated unexpectedly. It has done this 1 time(s). 25/02/2010 19:08:39, error: Service Control Manager [7031] - The AVG Free WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 22/02/2010 21:03:51, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Pml Driver HPZ12 service to connect. 22/02/2010 21:03:51, error: Service Control Manager [7000] - The Pml Driver HPZ12 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 22/02/2010 21:03:00, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCLEPCI SISAGP viaagp1 22/02/2010 17:35:16, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCLEPCI ==== End Of File =========================== A couple of other errors I recive are, no firewall and virtual memory is running low
Hello again.

Logs looking good.

Follow instructions here on enabling your Windows Firewall: http://support.microsoft.com/kb/283673
Regarding Virtual Memory error, that's due to you have very little memory available and too many applications/programs using the resources. That's not something I can physically due since you would need to purchase more RAM as I can see from the log you only have about 200 MB of ram which isn't a lot -perhaps it's due to how old this computer might be.

Other than that logs look clean. Let's wrap up.

Please follow/read the steps below to remove the tools we used and for some more information. :)


Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run… command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
    🖼Click to load external image (Posted Image)
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything assoicated with it.

Download and Run OTC

We will now remove the tools we used during this fix using OTC.


System A bit Slow? Try StartupLight

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.

If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.

Congratulations! You now appear clean! :D

Now that you are clean, please follow and read some of the prevention tips below.

Preventing Infections in the Future


Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:


Some of the main things you should consider to perform/read are:

  • Disabling Autorun/Play on Flash-Drive/Removable Drives
  • Avoid gaming sites, underground web pages, pirated software sites, and Peer to Peer Programs
  • Keep Windows Updated through going to Windows Updates
  • Updating Non-Microsoft Programs
  • Keeping Security softwares updated

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Update all programs regularly - Make sure you update all the programs you have installed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

If you have no more questions, comments or problems please tell us, so we can close off the topic.

Thanks :)

With Regards,
Extremeboy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI