This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] [Resolved] Unable to open Computer Properties

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there WTT.

I don't know how long this has been 'lurking' but i tried opening Computer Properties by Right Clicking "My Computer" then "Properties". Then i got

Title: Run a DLL as an App
Info: Run a DLL as an App has encountered a problem and needs to close. We are sorry for the inconvenience.
Then The usual: If you were in the middle of something… blah blah blah… For more information about this error, click here

App Name: rundll32.exe
AppVer: 5.1.2600.5512
ModName: user32.dll
ModVer: 5.1.2600.5512
Offset: 00009de9

THIS IS THE "The Following Files Will Be Included In This Error Report:" FILE
   
   
   
	   
	   
	   
	   
	   
	   
	   
	   
	   
	   
   
   
	   
   
   

. i tried getting round that by trying Windows Key & Pause/Break which gave me the error

An exception occurred while trying to run "C:\WINDOWS\system32\shell32.dll,Control_RunDLLSYSDM.CPL,System"


Also, i cannot reply in Firefox (i have the latest version). it will let me enter a topic title and description but not type into the message composing box

Also, i'm trying to pair my phone with my laptop via bluetooth (Which works ok) then trying to add an outgoing port. (Bluetooth Devices > COM Ports > Add > Outgoing (Computer Initiates Connection) i then select my newly paired phone and the "Serial Port (SSP)" service click ok and then it says "Access is Denied." I've tried this on my Admin account and the root admin account and both are exactly the same.

I run MBAM weekly along with a virus scan Daily and both are clean and use C Cleaner regularly.

Please help


Thanks

Duey

N.B. The OS is XP SP3 x86
Hi,

Please do the following:


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi CatByte, thanks for helping me with this fix.

Attach.txt

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 04/02/2010 01:15:13
System Uptime: 26/04/2010 12:24:50 (15 hours ago)

Motherboard: PACKARD BELL BV | | EasyNote SW51
Processor: AMD Turion™ 64 X2 Mobile Technology TL-50 | S1 | 1603/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 112 GiB total, 79.645 GiB free.
D: is Removable
E: is Removable
F: is Removable
G: is CDROM (UDF)
H: is Removable
I: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP37: 13/02/2010 20:44:16 - Software Distribution Service 3.0
RP38: 13/02/2010 22:08:27 - Installed Windows XP WgaNotify.
RP39: 13/02/2010 22:09:32 - Revo Uninstaller Pro's restore point - Driver Checker v2.7.4
RP40: 14/02/2010 03:01:58 - Software Distribution Service 3.0
RP41: 14/02/2010 05:55:14 - Software Distribution Service 3.0
RP42: 14/02/2010 17:47:56 - Software Distribution Service 3.0
RP43: 14/02/2010 17:59:10 - Software Distribution Service 3.0
RP44: 14/02/2010 18:43:52 - Printer Driver Microsoft XPS Document Writer Installed
RP45: 15/02/2010 01:42:04 - Installed BOINC
RP46: 15/02/2010 02:19:30 - Revo Uninstaller Pro's restore point - Thoosje Vista Sidebar
RP47: 15/02/2010 13:26:45 - Software Distribution Service 3.0
RP48: 16/02/2010 13:27:40 - System Checkpoint
RP49: 16/02/2010 17:03:00 - Software Distribution Service 3.0
RP50: 17/02/2010 20:52:48 - Installed Maxtor Manager
RP51: 18/02/2010 00:18:27 - Installed Windows Defender
RP52: 18/02/2010 00:20:49 - Software Distribution Service 3.0
RP53: 18/02/2010 00:25:14 - Revo Uninstaller Pro's restore point - LCD-Test
RP54: 18/02/2010 01:48:46 - Software Distribution Service 3.0
RP55: 18/02/2010 02:11:33 - Installed Java™ 6 Update 18
RP56: 18/02/2010 02:21:30 - Installed Java™ 6 Update 16
RP57: 19/02/2010 00:34:03 - Software Distribution Service 3.0
RP58: 20/02/2010 18:12:09 - System Checkpoint
RP59: 21/02/2010 18:16:02 - System Checkpoint
RP60: 22/02/2010 01:22:07 - Software Distribution Service 3.0
RP61: 22/02/2010 13:31:41 - Software Distribution Service 3.0
RP62: 23/02/2010 01:57:03 - Software Distribution Service 3.0
RP63: 24/02/2010 02:05:42 - Software Distribution Service 3.0
RP64: 24/02/2010 02:11:37 - Installed VistaMizer
RP65: 24/02/2010 02:52:14 - Software Distribution Service 3.0
RP66: 24/02/2010 18:15:36 - Installed Belkin N Wireless USB Adapter Setup
RP67: 24/02/2010 18:17:19 - Removed Belkin N Wireless USB Adapter Setup
RP68: 25/02/2010 01:34:24 - Software Distribution Service 3.0
RP69: 25/02/2010 17:39:27 - Software Distribution Service 3.0
RP70: 25/02/2010 23:18:46 - Software Distribution Service 3.0
RP71: 27/02/2010 00:14:38 - System Checkpoint
RP72: 28/02/2010 00:16:11 - System Checkpoint
RP73: 28/02/2010 19:03:21 - Revo Uninstaller Pro's restore point - Desintaller
RP74: 28/02/2010 19:04:37 - Revo Uninstaller Pro's restore point - Windows Search 4.0
RP75: 28/02/2010 19:06:05 - Revo Uninstaller Pro's restore point - Windows Search 4.0
RP76: 02/03/2010 03:34:25 - System Checkpoint
RP77: 03/03/2010 03:40:58 - System Checkpoint
RP78: 04/03/2010 11:31:26 - Restore Operation
RP79: 05/03/2010 02:29:24 - Software Distribution Service 3.0
RP80: 06/03/2010 02:47:10 - System Checkpoint
RP81: 07/03/2010 02:52:40 - System Checkpoint
RP82: 08/03/2010 03:48:30 - System Checkpoint
RP83: 09/03/2010 00:13:05 - Software Distribution Service 3.0
RP84: 09/03/2010 19:56:49 - Software Distribution Service 3.0
RP85: 09/03/2010 20:19:55 - Unsigned printer driver Brother MFC-410CN Printer installed.
RP86: 10/03/2010 20:53:54 - System Checkpoint
RP87: 11/03/2010 00:23:50 - Revo Uninstaller's restore point - Revo Uninstaller Pro 2.1.1
RP88: 11/03/2010 00:24:02 - Revo Uninstaller's restore point - Revo Uninstaller Pro 2.1.1
RP89: 11/03/2010 00:25:18 - Revo Uninstaller's restore point - Sandboxie 3.44
RP90: 11/03/2010 00:27:18 - Revo Uninstaller's restore point - Space Plasma 3D Screensaver 1.5
RP91: 11/03/2010 00:28:44 - Revo Uninstaller's restore point - Java™ 6 Update 16
RP92: 11/03/2010 00:29:00 - Removed Java™ 6 Update 16
RP93: 11/03/2010 00:30:36 - Revo Uninstaller's restore point - Halloween Haunts 1.0.0
RP94: 11/03/2010 00:31:58 - Revo Uninstaller's restore point - BOINC
RP95: 11/03/2010 00:35:31 - Revo Uninstaller's restore point - GNU Aspell 0.50-3
RP96: 11/03/2010 00:35:45 - Revo Uninstaller's restore point - GNU Aspell 0.50-3
RP97: 11/03/2010 12:28:53 - Software Distribution Service 3.0
RP98: 12/03/2010 02:07:15 - Software Distribution Service 3.0
RP99: 13/03/2010 02:43:09 - System Checkpoint
RP100: 14/03/2010 12:53:43 - System Checkpoint
RP101: 15/03/2010 12:56:43 - System Checkpoint
RP102: 15/03/2010 18:43:08 - Software Distribution Service 3.0
RP103: 16/03/2010 19:55:37 - System Checkpoint
RP104: 18/03/2010 08:32:39 - System Checkpoint
RP105: 19/03/2010 01:38:50 - Software Distribution Service 3.0
RP106: 19/03/2010 01:41:19 - Avira AntiVir Personal - 19/03/2010 01:41
RP107: 20/03/2010 03:04:48 - System Checkpoint
RP108: 21/03/2010 06:21:40 - System Checkpoint
RP109: 22/03/2010 15:23:36 - System Checkpoint
RP110: 22/03/2010 23:59:23 - Software Distribution Service 3.0
RP111: 24/03/2010 14:20:41 - Avira AntiVir Personal - 24/03/2010 14:20
RP112: 24/03/2010 14:26:52 - Installed AVG Free 9.0
RP113: 24/03/2010 14:35:56 - Installed AVG Free 9.0
RP114: 25/03/2010 08:10:11 - Avg Update
RP115: 25/03/2010 11:51:31 - Installed iTunes
RP116: 27/03/2010 16:50:00 - System Checkpoint
RP117: 29/03/2010 04:54:09 - Installed Next Generation Visualisations
RP118: 29/03/2010 04:55:07 - Installed Windows Media Player 9 Series Winter Fun Pack
RP119: 31/03/2010 18:37:00 -
RP120: 31/03/2010 18:46:25 - Software Distribution Service 3.0
RP121: 01/04/2010 22:11:46 -
RP122: 02/04/2010 08:04:30 - Avg Update
RP123: 02/04/2010 08:06:43 - Avg Update
RP124: 03/04/2010 16:09:46 -
RP125: 04/04/2010 18:12:45 -
RP126: 06/04/2010 05:27:39 -
RP127: 08/04/2010 13:01:57 - Avg Update
RP128: 11/04/2010 04:46:25 -
RP129: 12/04/2010 04:51:49 -
RP130: 18/04/2010 16:21:37 -
RP131: 19/04/2010 17:49:11 -
RP132: 20/04/2010 18:35:19 -
RP133: 21/04/2010 02:03:35 - Software Distribution Service 3.0
RP134: 21/04/2010 02:49:18 - Software Distribution Service 3.0
RP135: 21/04/2010 03:01:11 - Software Distribution Service 3.0
RP136: 21/04/2010 12:56:39 - Software Distribution Service 3.0
RP137: 22/04/2010 08:43:07 - Avg Update
RP138: 22/04/2010 08:44:21 - Avg Update
RP139: 23/04/2010 08:55:02 -
RP140: 24/04/2010 10:01:44 -
RP141: 25/04/2010 10:51:28 -
RP142: 26/04/2010 13:47:25 -
RP143: 26/04/2010 23:45:24 - Revo Uninstaller's restore point - Autoglym High Definition Wax 2009 Screensaver Screensaver
RP144: 26/04/2010 23:46:17 - Revo Uninstaller's restore point - HijackThis 2.0.2
RP145: 26/04/2010 23:50:44 - Revo Uninstaller's restore point - Windows Search 4.0

==== Installed Programs ======================

Acrobat.com
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.2
Adobe Shockwave Player 11.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AusLogics Disk Defrag
AVG Free 9.0
Bandwidth Monitor
Bonjour
Breakaway for Windows
CCleaner
Faster Downloader
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB945282)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946040)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946308)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946344)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947540)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947789)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB948127)
Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB951708)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
iTunes
Java Auto Updater
Java™ 6 Update 18
Junk Mail filter update
Malwarebytes' Anti-Malware
Maxtor Manager
Media Player Codec Pack 3.9.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Live Add-in 1.4
Microsoft Office Professional Edition 2003
Microsoft Primary Interoperability Assemblies 2005
Microsoft Silverlight
Microsoft SQL Server 2008 Management Objects
Microsoft SQL Server Compact 3.5 SP1 Design Tools English
Microsoft SQL Server Compact 3.5 SP1 English
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
Mozilla Firefox (3.6.3)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MyPhoneExplorer
Next Generation Visualisations
NT Registry Analyzer
NVIDIA Drivers
QuickTime
Realtek High Definition Audio Driver
Revo Uninstaller 1.85
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981349)
Segoe UI
SereneScreen Marine Aquarium 3
SpywareBlaster 4.2
SQL Server System CLR Types
Synaptics Pointing Device Driver
System Requirements Lab
Tweak N' Tune 1.1.0
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows Internet Explorer 8 (KB980302)
VideoLAN VLC media player 0.8.6d
VistaMizer [removed]
WebFldrs XP
Windows Defender
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Mail
Windows Live Messenger
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 9 Series Winter Fun Pack
Windows XP Service Pack 3
WinRAR archiver
YouTube Downloader 2.5.3
ZyDAS IEEE 802.11 b+g Wireless LAN - USB

==== Event Viewer Messages From Past Week ========

27/04/2010 03:11:28, error: Service Control Manager [7016] - The BrSplService service has reported an invalid current state 0.
26/04/2010 23:51:12, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
26/04/2010 13:06:41, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

==== End Of File ===========================


DDS.txt


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 3:11:24.84 on 27/04/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1919.854 [GMT 1:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\AVG\AVG9\avgemc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\MPK\MPK.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Breakaway\breakaway.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Breakaway\breakaway.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Rokario\Bandwidth Monitor\bandmon.exe
C:\WINDOWS\system32\osk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\MSSWCHX.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Mum\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uInternet Connection Wizard,ShellNext = hxxp://www.belkin.com/support/networkingsupport.asp
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\mpk\MPK.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: IEDownloadCatcher.DownloadManager: {aecb3c96-189c-35f9-9c0b-a3832b3c1839} - mscoree.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uRun: [bandmon] c:\program files\rokario\bandwidth monitor\bandmon.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [nwiz] nwiz.exe /installquiet
mRun: [Breakaway] "c:\program files\breakaway\breakaway.exe" force
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: Download with Faster Downloader - c:\program files\psykonikcorp\faster downloader\dl.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1266036412781
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {5952FBA8-3A7E-4D84-AD2A-86D1E9102708} = 156.154.70.22,156.154.71.22
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\mum\applic~1\mozilla\firefox\profiles\c1qwdl02.default\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\mum\application data\mozilla\firefox\profiles\c1qwdl02.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\windows\system32\c2mp\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-3-24 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-3-24 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-3-24 242896]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-24 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-24 308064]
R3 EuMusDesignVirtualAudioCableWdm_lcs;Breakaway Pipeline (WDM);c:\windows\system32\drivers\vaclcskd.sys [2008-8-27 48872]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [2004-4-19 6656]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [2010-2-24 598400]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-3-24 369920]
S3 cpuz131;cpuz131;\??\c:\docume~1\mum\locals~1\temp\cpuz131\cpuz_x32.sys –> c:\docume~1\mum\locals~1\temp\cpuz131\cpuz_x32.sys [?]
S3 cpuz132;cpuz132;\??\c:\docume~1\mum\locals~1\temp\cpuz132\cpuz132_x32.sys –> c:\docume~1\mum\locals~1\temp\cpuz132\cpuz132_x32.sys [?]

=============== Created Last 30 ================

2010-04-25 01:14:10 587 —-a-w- c:\windows\system32\runrefog.lnk
2010-04-25 01:14:10 587 —-a-w- c:\windows\system32\runkgb.lnk
2010-04-25 01:14:06 0 d-sh–w- c:\windows\system32\MPK
2010-04-25 01:14:06 0 d-sh–w- c:\docume~1\alluse~1\applic~1\MPK
2010-04-25 00:08:39 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-04-21 13:02:02 0 d-sh–w- c:\documents and settings\mum\IECompatCache
2010-04-21 13:00:57 0 d-sh–w- c:\documents and settings\mum\PrivacIE
2010-04-21 11:31:35 0 d-sh–w- c:\documents and settings\mum\IETldCache
2010-04-21 02:07:09 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-21 02:07:09 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-04-21 02:07:01 0 d—–w- c:\windows\ie8updates
2010-04-21 02:06:50 64000 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-04-21 02:05:59 0 dc-h–w- c:\windows\ie8
2010-04-21 01:50:04 0 d—–w- c:\program files\Windows Desktop Search
2010-04-13 02:39:27 0 d—–w- c:\windows\system32\Adobe
2010-04-08 19:15:44 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-04-08 19:15:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-04-08 19:15:36 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-04-08 19:15:36 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-04-06 03:09:53 0 d—–w- c:\program files\iPod
2010-04-06 03:09:47 0 d—–w- c:\program files\iTunes
2010-04-06 03:09:47 0 d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-06 03:02:34 0 d—–w- c:\program files\Bonjour
2010-04-01 11:53:54 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-04-01 11:53:52 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-03-29 03:55:09 0 d—–w- c:\program files\Windows XP Fun Pack

==================== Find3M ====================

2010-04-22 07:44:14 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-29 14:24:58 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 14:24:46 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-24 14:38:24 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-24 14:38:13 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-24 00:56:37 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-03-20 01:43:33 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-03-19 10:12:44 1474832 —-a-w- c:\windows\system32\drivers\sfi.dat
2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-01 02:59:17 38428 —ha-w- c:\windows\system32\mlfcache.dat
2010-02-25 06:24:37 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 10:16:06 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-24 02:17:56 218624 —-a-w- c:\windows\system32\uxtheme.dll
2010-02-18 02:11:45 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-16 14:08:49 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25:04 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-14 03:09:17 16384 —-a-w- c:\windows\system32\wbem\mofcomp.exe
2010-02-12 10:46:14 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 10:46:14 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-12 10:03:03 293376 ——w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33:11 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-04 01:07:30 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2008-04-14 05:42:30 60416 –sha-w- c:\windows\vistamizer\old\msimn.exe

============= FINISH: 3:12:04.62 ===============

Also, Please note, GMER will NOT run correctly. i have tried it 3 seperate times with restarts inbetween for good measure. The first 2 times the computer just ground to a halt and wouldn't do anything and the last time i tried running the scan was on my root admin account and that just made the screen go to the default "Windows Blue" (NOT BSOD) i also had no desktop icons or taskbar and no matter what i pressed it ust wouldn't respond, all i could do was move the mouse around on a blank blue screen

Thanks for taking the time to help me out

Regards

Duey
Please try running GMER in safe mode Check only the boxes beside "sections" and the "C:\' drive, see if that helps leave everything else blank.
it's running fine in Windows XP Safe Mode with only the above options selected.

Here is the Log…

GMER.TXT

GMER Did not find any system modification
hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi,
Thanks for your reply.

Below is my log but i just need to say something regarding this log…

As you will see, there was a keylogger (ReFog or something like that) I installed that along with the Vistamizer which you will also see on the log under the (((((((((((((((((OTHER DELETIONS)))))))))))))))))))))) bit.

ComboFix Log
ComboFix 10-04-26.05 - Me 28/04/2010 0:19.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1919.963 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
c:\documents and settings\All Users\Application Data\MPK
c:\documents and settings\All Users\Application Data\MPK\1\D0000
c:\documents and settings\All Users\Application Data\MPK\1\S0000
c:\documents and settings\All Users\Application Data\MPK\2\D0000
c:\documents and settings\All Users\Application Data\MPK\2\S0000
c:\documents and settings\All Users\Application Data\MPK\3\D0000
c:\documents and settings\All Users\Application Data\MPK\3\S0000
c:\documents and settings\All Users\Application Data\MPK\CPDM\cpfm.bin
c:\documents and settings\All Users\Application Data\MPK\M0000
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\Get discount!.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\Order now!.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\REFOG Free Keylogger on the Web.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\REFOG Free Keylogger.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\Uninstall REFOG Free Keylogger.lnk
c:\documents and settings\All Users\Application Data\MPK\S0000
c:\windows\system32\drivers\etc\lmhosts

Infected copy of c:\windows\system32\midimap.dll was found and disinfected
Restored copy from - c:\windows\VistaMizer\old\midimap.dll

.
((((((((((((((((((((((((( Files Created from 2010-03-27 to 2010-04-27 )))))))))))))))))))))))))))))))
.

2010-04-27 05:13 . 2010-04-27 05:13 ——– d—–w- c:\documents and settings\LocalService\Application Data\PeerNetworking
2010-04-25 01:14 . 2010-04-25 02:46 ——– d-sh–w- c:\windows\system32\MPK
2010-04-25 00:11 . 2010-04-25 00:11 ——– d—–w- c:\documents and settings\Admin Account\Application Data\MyPhoneExplorer
2010-04-25 00:08 . 2010-04-25 00:08 ——– d—–w- c:\documents and settings\Admin Account\Local Settings\Application Data\Microsoft
2010-04-21 13:02 . 2010-04-21 13:02 ——– d-sh–w- c:\documents and settings\Me\IECompatCache
2010-04-21 13:00 . 2010-04-21 13:00 ——– d-sh–w- c:\documents and settings\Me\PrivacIE
2010-04-21 11:31 . 2010-04-21 11:31 ——– d-sh–w- c:\documents and settings\Me\IETldCache
2010-04-21 02:18 . 2010-04-21 02:18 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-04-21 02:07 . 2010-02-25 06:24 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-04-21 02:07 . 2010-02-25 06:24 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-21 02:07 . 2010-04-21 02:07 ——– d—–w- c:\windows\ie8updates
2010-04-21 02:06 . 2010-02-16 04:50 64000 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-04-21 02:05 . 2010-04-21 02:06 ——– dc-h–w- c:\windows\ie8
2010-04-21 01:50 . 2010-04-27 02:30 ——– d—–w- c:\program files\Windows Desktop Search
2010-04-13 02:39 . 2010-04-13 02:39 ——– d—–w- c:\windows\system32\Adobe
2010-04-09 01:09 . 2010-04-19 01:40 ——– d—–w- c:\documents and settings\Me\Local Settings\Application Data\Axialis
2010-04-08 19:15 . 2001-08-17 21:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-04-08 19:15 . 2008-04-14 04:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-04-08 19:15 . 2008-04-13 23:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-04-08 19:15 . 2008-04-13 23:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-04-06 03:09 . 2010-04-06 03:09 ——– d—–w- c:\program files\iPod
2010-04-06 03:09 . 2010-04-06 03:10 ——– d—–w- c:\program files\iTunes
2010-04-06 03:09 . 2010-04-06 03:10 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-06 03:06 . 2010-04-06 03:06 ——– d—–w- c:\program files\QuickTime
2010-04-06 03:02 . 2010-04-06 03:02 ——– d—–w- c:\program files\Bonjour
2010-04-06 02:57 . 2010-04-06 02:57 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-01 11:53 . 2010-04-01 11:53 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-04-01 11:53 . 2010-04-01 11:53 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-03-30 01:29 . 2010-03-30 01:29 ——– d—–w- C:\rsit
2010-03-30 00:57 . 2010-03-30 00:57 5918720 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-03-29 03:55 . 2010-03-29 03:55 29184 —-a-r- c:\documents and settings\Me\Application Data\Microsoft\Installer\{52C8FAA0-68CA-4AF9-8A7A-92CF3174CC77}\IconTmpl5.26D6FF13_F77C_402E_8E96_9E49DFBBAF31.exe
2010-03-29 03:55 . 2010-03-29 03:55 ——– d—–w- c:\program files\Windows XP Fun Pack
2010-03-29 03:53 . 2010-02-23 14:04 1664256 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-27 17:11 . 2010-03-25 03:05 0 —-a-w- c:\documents and settings\Me\Local Settings\Application Data\prvlcl.dat
2010-04-26 22:42 . 2010-02-04 01:40 ——– d—–w- c:\program files\CCleaner
2010-04-25 00:09 . 2010-04-25 00:09 ——– d—–w- c:\documents and settings\Admin Account\Application Data\Windows Desktop Search
2010-04-25 00:09 . 2010-04-25 00:09 ——– d—–w- c:\documents and settings\Admin Account\Application Data\Apple Computer
2010-04-25 00:09 . 2010-04-25 00:09 45024 —-a-w- c:\documents and settings\Admin Account\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-24 03:02 . 2010-02-05 01:05 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-22 07:44 . 2010-03-24 14:38 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-21 13:00 . 2010-03-24 14:38 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-04-14 21:49 . 2010-02-07 03:37 ——– d—–w- c:\documents and settings\Me\Application Data\dvdcss
2010-04-12 03:15 . 2010-02-06 02:52 ——– d—–w- c:\documents and settings\Me\Application Data\Marine Aquarium 3
2010-04-08 11:56 . 2010-03-24 14:26 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-04-08 04:25 . 2010-02-05 01:04 ——– d—–w- c:\program files\SpywareBlaster
2010-04-06 03:09 . 2010-02-04 21:36 ——– d—–w- c:\program files\Common Files\Apple
2010-03-31 17:00 . 2010-02-13 01:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-29 14:24 . 2010-02-13 01:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 14:24 . 2010-02-13 01:55 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-29 10:54 . 2010-02-04 21:38 ——– d—–w- c:\documents and settings\Me\Application Data\Apple Computer
2010-03-29 10:53 . 2010-02-04 21:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-03-27 02:37 . 2010-03-24 22:52 ——– d—–w- c:\documents and settings\Me\Application Data\Rokario
2010-03-26 16:50 . 2010-02-04 02:56 ——– d—–w- c:\documents and settings\Me\Application Data\NT Registry Analyzer
2010-03-26 02:20 . 2010-03-26 02:20 ——– d—–w- c:\documents and settings\Me\Application Data\AVG9
2010-03-24 22:52 . 2010-03-24 22:52 ——– d—–w- c:\program files\Rokario
2010-03-24 14:38 . 2010-03-24 14:38 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-24 14:38 . 2010-03-24 14:38 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-24 14:38 . 2010-03-24 14:38 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-24 14:29 . 2010-03-24 00:56 ——– d—–w- c:\program files\CheckPoint
2010-03-24 14:27 . 2010-03-24 14:27 ——– d—–w- c:\program files\AVG
2010-03-24 14:05 . 2010-02-05 00:54 ——– d—–w- c:\program files\COMODO
2010-03-24 00:57 . 2010-03-24 00:57 ——– d—–w- c:\documents and settings\Me\Application Data\CheckPoint
2010-03-24 00:56 . 2010-03-24 00:56 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-03-20 01:43 . 2010-03-19 01:42 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-03-19 10:12 . 2010-02-05 01:15 1474832 —-a-w- c:\windows\system32\drivers\sfi.dat
2010-03-11 00:33 . 2010-02-15 01:42 ——– d—–w- c:\documents and settings\All Users\Application Data\BOINC
2010-03-11 00:29 . 2010-02-18 02:11 ——– d—–w- c:\program files\Java
2010-03-11 00:24 . 2010-02-06 17:15 ——– d—–w- c:\program files\VS Revo Group
2010-03-10 06:15 . 2004-08-04 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-09 20:20 . 2010-03-09 20:20 ——– d—–r- c:\documents and settings\Me\Application Data\Brother
2010-03-01 02:59 . 2010-03-01 02:59 38428 —ha-w- c:\windows\system32\mlfcache.dat
2010-02-28 16:28 . 2010-02-04 01:53 45024 —-a-w- c:\documents and settings\Me\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-25 06:24 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-25 02:40 . 2010-02-24 22:43 598400 —-a-w- c:\windows\system32\drivers\RTL8192su.sys
2010-02-24 13:11 . 2004-08-04 12:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-24 10:16 . 2010-02-18 00:21 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-24 02:17 . 2004-12-16 04:43 218624 —-a-w- c:\windows\system32\uxtheme.dll
2010-02-18 02:12 . 2010-02-18 02:12 503808 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7fd050e2-n\msvcp71.dll
2010-02-18 02:12 . 2010-02-18 02:12 499712 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7fd050e2-n\jmc.dll
2010-02-18 02:12 . 2010-02-18 02:12 348160 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7fd050e2-n\msvcr71.dll
2010-02-18 02:12 . 2010-02-18 02:12 61440 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4699ef4f-n\decora-sse.dll
2010-02-18 02:12 . 2010-02-18 02:12 12800 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4699ef4f-n\decora-d3d.dll
2010-02-18 02:11 . 2010-02-18 02:12 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-18 02:11 . 2010-02-18 02:11 79488 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\jre1.6.0_18\gtapi.dll
2010-02-18 02:10 . 2010-02-18 02:10 152576 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\jre1.6.0_18\lzma.dll
2010-02-16 14:08 . 2004-08-04 12:00 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-15 01:58 . 2010-02-15 01:58 193824 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\VBExpress\9.0\1033\ResourceCache.dll
2010-02-15 01:57 . 2010-02-15 01:57 416 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2010-02-14 03:09 . 2010-02-04 01:05 16384 —-a-w- c:\windows\system32\wbem\mofcomp.exe
2010-02-13 19:30 . 2010-02-04 01:10 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-12 10:46 . 2010-02-12 10:46 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 10:46 . 2010-02-12 10:46 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-12 10:03 . 2010-02-24 18:14 293376 ——w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2004-08-04 12:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 12:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-08 19:45 . 2010-02-08 19:45 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-02-04 01:41 . 2010-02-04 01:41 0 —-a-w- c:\windows\nsreg.dat
2010-02-04 01:34 . 2010-02-04 01:34 21035 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-02-04 01:07 . 2010-02-04 01:07 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2008-04-14 05:42 . 2010-02-04 21:56 60416 –sha-w- c:\windows\VistaMizer\old\msimn.exe
.

——- Sigcheck ——-

[-] 2008-04-14 . A55B8899D2EA2E800061BCFD456E34DC . 547328 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 . A55B8899D2EA2E800061BCFD456E34DC . 547328 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[7] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\winlogon.exe
[-] 2004-08-04 . 55ACA85EB80E2155E20211AAADDD711A . 541696 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe

[-] 2008-04-14 . C280F24E855FBC107E8B95C42DC0EB3C . 724992 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2008-04-14 . C280F24E855FBC107E8B95C42DC0EB3C . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
[7] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\VistaMizer\old\comctl32.dll
[-] 2004-08-04 . 5F25281C9DC595E269735EABC9F64485 . 718848 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll

[-] 2008-04-14 . 1F796B640B01A277B463E51CF0D79E10 . 587264 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-14 . 1F796B640B01A277B463E51CF0D79E10 . 587264 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[7] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\user32.dll
[7] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\user32.dll
[7] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\ERDNT\cache\user32.dll

[-] 2008-04-14 . DCDEAA7B5698587F82C0F6CD7FB71967 . 1551872 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . DCDEAA7B5698587F82C0F6CD7FB71967 . 1551872 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\explorer.exe
[-] 2004-08-04 . 49290030CE8BB6A2C5AF4339B122261F . 1550336 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\explorer.exe

[-] 2008-04-14 . B5E8782D4AF1B3756F38E11E7C157BBE . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 . B5E8782D4AF1B3756F38E11E7C157BBE . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ctfmon.exe
[-] 2004-08-04 . 5F1724D0E11EB88C95A3B73A6DD72779 . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 14:04 1664256 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-01 16208384]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"nwiz"="nwiz.exe" [2006-04-27 1519616]
"Breakaway"="c:\program files\Breakaway\breakaway.exe" [2008-12-14 8994816]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-03-10 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-03-10 688218]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-27 7561216]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 25088]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-24 14:38 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless Networking Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Belkin Wireless Networking Utility.lnk
backup=c:\windows\pss\Belkin Wireless Networking Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ZDWLan Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ZDWLan Utility.lnk
backup=c:\windows\pss\ZDWLan Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bandmon]
2008-06-01 17:05 1529856 —-a-w- c:\program files\Rokario\Bandwidth Monitor\bandmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-03-26 00:10 142120 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
2008-04-17 03:31 169256 —-a-w- c:\program files\Maxtor\OneTouch Status\MaxMenuMgr.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [24/03/2010 15:38 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [24/03/2010 15:38 242896]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [24/03/2010 15:36 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [24/03/2010 15:36 308064]
R3 EuMusDesignVirtualAudioCableWdm_lcs;Breakaway Pipeline (WDM);c:\windows\system32\drivers\vaclcskd.sys [27/08/2008 04:01 48872]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [19/04/2004 16:01 6656]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [24/02/2010 23:43 598400]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 20:19 13592]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [24/03/2010 15:38 369920]
S3 cpuz131;cpuz131;\??\c:\docume~1\Me\LOCALS~1\Temp\cpuz131\cpuz_x32.sys –> c:\docume~1\Me\LOCALS~1\Temp\cpuz131\cpuz_x32.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2010-04-27 c:\windows\Tasks\Auslogics Console Defragmentation.job
- c:\program files\Auslogics\AusLogics Disk Defrag\cdefrag.exe [2010-02-04 00:42]

2010-04-27 c:\windows\Tasks\User_Feed_Synchronization-{AC472B14-94B8-4C03-BFA0-802CE98B3952}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.belkin.com/support/networkingsupport.asp
uInternet Settings,ProxyOverride = *.local
IE: Download with Faster Downloader - c:\program files\PsykonikCorp\Faster Downloader\dl.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: {5952FBA8-3A7E-4D84-AD2A-86D1E9102708} = 156.154.70.22,156.154.71.22
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\documents and settings\Me\Application Data\Mozilla\Firefox\Profiles\c1qwdl02.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Me\Application Data\Mozilla\Firefox\Profiles\c1qwdl02.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-boincmgr - c:\program files\BOINC\boincmgr.exe
MSConfigStartUp-boinctray - c:\program files\BOINC\boinctray.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-28 00:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1144)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll

- - - - - - - > 'lsass.exe'(1200)
c:\windows\system32\setupapi.dll
c:\windows\system32\psbase.dll

- - - - - - - > 'explorer.exe'(1112)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSENG.DLL
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\brss01a.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Maxtor\Sync\SyncServices.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\mqsvc.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\mqtgsvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\OSK.exe
c:\windows\system32\MSSWCHX.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-04-28 00:34:20 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-27 23:34
ComboFix2.txt 2010-02-13 01:41
ComboFix3.txt 2010-02-08 02:03

Pre-Run: 85,320,896,512 bytes free
Post-Run: 85,313,699,840 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 1409057E823B01621A833CD14BD78DA3
What can you tell me about the VistaMizer program.

there are certain core files on your system that appear to have been altered by this program, I take it this was done intentionally?

these are the files
c:\windows\VistaMizer\old\winlogon.exe
c:\windows\VistaMizer\old\comctl32.dll
c:\windows\VistaMizer\old\user32.dll
c:\windows\VistaMizer\old\explorer.exe
c:\windows\VistaMizer\old\ctfmon.exe

the files that are now in place eg; c:\windows\system32\winlogon.exe are failing signature verification, which I assume is because they have been altered by VistaMizer - can you please confirm this.


Please do the following:


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT



Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
the vistamizer program emulates the look of vista on XP. it changes all the default icons to the vista style .

there are certain core files on your system that appear to have been altered by this program, I take it this was done intentionally?

these are the files
c:\windows\VistaMizer\old\winlogon.exe
c:\windows\VistaMizer\old\comctl32.dll
c:\windows\VistaMizer\old\user32.dll
c:\windows\VistaMizer\old\explorer.exe
c:\windows\VistaMizer\old\ctfmon.exe

the files that are now in place eg; c:\windows\system32\winlogon.exe are failing signature verification, which I assume is because they have been altered by VistaMizer - can you please confirm this.

as the files are not from microsoft and are altered versions, they will fail this verification. this was intentional as was the modification of the files listed above.

I will run your recommended scans now…
Here are the requested logs…

MBAM
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 4043

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

28/04/2010 02:02:29
mbam-log-2010-04-28 (02-02-29).txt

Scan type: Quick scan
Objects scanned: 112742
Time elapsed: 8 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 76

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Refog Software (Refog.Keylogger) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\MPK (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Images (Refog.Keylogger) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\MPK\Brazilian.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\French.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\German.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\icon.ico (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\icon_1.ico (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Italian.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Japanese.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\lnkmst.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Mpk.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\MPK.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Mpk64.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\MPK64.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\MPKView.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Portuguese.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Romanian.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Spanish.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\sqlite3.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\unins000.dat (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\unins000.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\file.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\imhelp.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\need_update_net.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\update.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\English\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\file.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\imhelp.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\need_update_net.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\German\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Help\Spanish\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Images\english.gif (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Images\german.gif (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Images\russian.gif (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Images\vista_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK\Images\xp_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully.




Kaspersky Online Scan

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, April 28, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, April 28, 2010 00:57:47
Records in database: 3991680
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan statistics:
Objects scanned: 50301
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 01:42:39


File name / Threat / Threats count
C:\Documents and Settings\Mum\My Documents\Downloads\FreeFireplaceSS.exe Infected: Trojan-Banker.Win32.Banker.auma 1

Selected area has been scanned.


n.b. i have deleted the above file (C:\Documents and Settings\Mum\My Documents\Downloads\FreeFireplaceSS.exe)

the symptoms described in my first post still exist
Please do the following:

  • Click Start, click Run, type cmd.exe, and then click OK.
  • At the command prompt, type sfc /purgecache, and then press ENTER.
    Note You may be prompted to provide Windows installation source files when you run the sfc /purgecache command. If the command is completed successfully, you will receive the following message:
  • Windows File Protection successfully made the requested change.
  • At the command prompt, type sfc /scannow, and then press ENTER.
    Note This command may take several minutes to finish. You may also be prompted to provide Windows installation source files when you run the sfc /scannow command.
  • At the command prompt, type exit, and then press ENTER to close the command prompt.


Let me know how that goes
hi, i've not got my genuine install discs. my mate has got a cd that has all the different versions on it. could i try doing a repair through the CD and not through windows itself? the sfc /purgecache worked fine the sfc /scannow needs my XP disc
Hi, Thats worked but now it says "You May Be a Victim of Software Counterfeiting". I have a valid product key but microsoft are saying that it's invalid??

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI