This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Solved] (RESOLVED) Heavy Spikes Sluggish Computer

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Computer was running slow so I ran a Kaspersky scan. Here is the result of the scan: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Tuesday, June 8, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, June 08, 2010 02:47:17 Records in database: 4209933 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ E:\ F:\ G:\ H:\ Scan statistics: Objects scanned: 185714 Threats found: 2 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 18:15:50 File name / Threat / Threats count C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\3\12a49b83-49d8927d Infected: Exploit.Java.Agent.f 1 C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\3\12a49b83-49d8927d Infected: Trojan-Downloader.Java.OpenStream.ad 1 I would be very grateful for help getting rid of these thanks
DDS Log: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 22:10:52.95 on Wed 06/09/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3063.2171 [GMT -4:00] AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\CTHELPER.EXE C:\WINDOWS\system32\CTXFIHLP.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe C:\WINDOWS\SYSTEM32\CTXFISPI.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AWS\WeatherBug\Weather.exe C:\Program Files\RAMRush\RAMRush.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe svchost.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Softland\FBackup 4\fbaSched.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\RocketDock\RocketDock.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Softland\FBackup 4\VscSrv.exe C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://astrocomputers.net/ uInternet Connection Wizard,ShellNext = iexplore BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1 uRun: [ftweak_RAMRush] c:\program files\ramrush\RAMRush.exe uRun: [ccleaner] "c:\program files\ccleaner\CCleaner.exe" /AUTO uRun: [DriverMax_RESTART] uRun: [Cookienator] "c:\program files\cookienator\cookienator.exe" /auto uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe" uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [FBackup Scheduler] "c:\program files\softland\fbackup 4\fbaSched.exe" mRun: [CTHelper] CTHELPER.EXE mRun: [CTxfiHlp] CTXFIHLP.EXE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1256927863234 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\4s87tle8.default\ FF - prefs.js: browser.startup.homepage - hxxp://astrocomputers.net/ FF - plugin: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\4s87tle8.default\extensions\[removed]\plugins\npTVUAx.dll FF - plugin: c:\documents and settings\administrator\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\opera\program\plugins\NPQNXWrap.dll FF - plugin: c:\program files\opera\program\plugins\npsnpy.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-4-29 164048] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2009-12-11 123280] R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2009-12-11 41616] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-4-29 19024] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-29 40384] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-29 40384] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-29 40384] R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-11-30 100048] R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2009-11-30 110992] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-29 135664] S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2010\RpcAgentSrv.exe [2009-11-27 93336] =============== Created Last 30 ================ 2010-06-09 18:28 –d—– c:\program files\ESET 2010-06-09 15:36 –d—– c:\docume~1\admini~1\applic~1\Malwarebytes 2010-06-09 15:36 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-09 15:36 20,952 a——- c:\windows\system32\drivers\mbam.sys 2010-06-09 15:36 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-06-09 15:36 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-06-09 09:28 –d—– c:\docume~1\admini~1\applic~1\Canneverbe_Limited 2010-06-09 09:27 –d—– c:\docume~1\alluse~1\applic~1\Canneverbe Limited 2010-06-09 01:12 743,424 -c—— c:\windows\system32\dllcache\iedvtool.dll 2010-06-08 22:48 –d—– c:\program files\Trend Micro 2010-06-07 21:48 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2010-06-07 21:48 –d—– c:\program files\SUPERAntiSpyware 2010-06-06 21:28 –d-h— c:\windows\system32\GroupPolicy 2010-06-06 18:35 –d—– c:\docume~1\admini~1\applic~1\IObit 2010-06-06 18:35 –d—– c:\program files\IObit 2010-06-06 16:16 –d—– c:\program files\Netscape 2010-06-03 21:09 –d—– C:\xpadder_gamepad_profiler 2010-06-03 16:43 218,624 a——- c:\windows\system32\uxtheme.uxtender 2010-06-03 11:47 –d—– c:\program files\Cookienator 2010-06-02 17:42 –d—– c:\program files\common files\Gibinsoft Shared 2010-06-02 17:42 –d—– c:\program files\GiPo@Utilities 2010-06-02 14:06 –d—– c:\program files\RocketDock 2010-06-02 13:11 –d—– c:\windows\pss 2010-06-02 11:15 –d—– c:\docume~1\admini~1\applic~1\Dexpot 2010-06-02 10:32 –d—– c:\docume~1\admini~1\applic~1\maComfort 2010-06-02 10:32 –d—– c:\program files\maComfort 2010-06-02 00:27 –d—– c:\docume~1\admini~1\applic~1\Auslogics 2010-06-01 23:15 –d—– C:\shman 2010-06-01 22:15 –d—– c:\program files\Auslogics 2010-06-01 11:28 –d—– c:\program files\Motherboard Monitor 5 2010-05-30 10:26 –d—– c:\windows\Downloaded Installations 2010-05-29 20:32 –d—– c:\docume~1\admini~1\applic~1\EstSoft 2010-05-29 20:32 –d—– c:\program files\ESTsoft 2010-05-29 18:03 –d—– c:\program files\Folder View 2010-05-29 16:29 –d—– c:\docume~1\alluse~1\applic~1\Innovative Solutions 2010-05-29 16:29 –d—– c:\program files\Innovative Solutions 2010-05-29 10:10 –d—– c:\docume~1\admini~1\applic~1\NCH Software 2010-05-29 10:10 –d—– c:\program files\NCH Software 2010-05-29 09:29 –d—– c:\program files\VLMC 2010-05-29 07:44 44,189 a——- C:\WaxCrash.dmp 2010-05-29 07:40 –d—– c:\program files\Pure Motion 2010-05-29 07:40 –d—– c:\program files\Sonic Foundry 2010-05-29 07:39 –d—– c:\program files\DebugMode 2010-05-29 06:33 719,872 a——- c:\windows\system32\devil.dll 2010-05-29 06:33 369,152 a——- c:\windows\system32\avisynth.dll 2010-05-29 06:33 70,656 a——- c:\windows\system32\yv12vfw.dll 2010-05-29 06:33 70,656 a——- c:\windows\system32\i420vfw.dll 2010-05-29 06:33 27,648 a——- c:\windows\system32\AVSredirect.dll 2010-05-29 06:33 –d—– c:\program files\AviSynth 2.5 2010-05-29 06:32 –d—– c:\program files\eRightSoft 2010-05-17 22:33 –d—– c:\program files\MPC HomeCinema 2010-05-17 20:47 819,200 a——- c:\windows\system32\xvidcore.dll 2010-05-17 20:47 180,224 a——- c:\windows\system32\xvidvfw.dll 2010-05-17 20:47 77,824 a——- c:\windows\system32\xvid.ax 2010-05-17 20:47 –d—– c:\program files\Xvid 2010-05-17 20:36 421,888 a——- c:\windows\system32\ac3filter.acm 2010-05-17 20:36 –d—– c:\program files\XP Codec Pack 2010-05-17 20:12 –d—– c:\program files\Haali ==================== Find3M ==================== 2010-06-04 05:09 1,033,728 a——- c:\windows\explorer.exe 2010-06-03 16:44 218,624 a——- c:\windows\system32\uxtheme.dll 2010-05-06 06:41 916,480 a——- c:\windows\system32\wininet.dll 2010-05-02 01:22 1,851,264 a——- c:\windows\system32\win32k.sys 2010-04-20 01:30 285,696 a——- c:\windows\system32\atmfd.dll 2010-04-12 17:29 411,368 a——- c:\windows\system32\deployJava1.dll 2006-05-03 05:06 163,328 —shr– c:\windows\system32\flvDX.dll 2007-02-21 06:47 31,232 —shr– c:\windows\system32\msfDX.dll 2008-03-16 08:30 216,064 —shr– c:\windows\system32\nbDX.dll 2009-10-30 12:16 16,384 a–sh— c:\windows\system32\config\systemprofile\cookies\index.dat 2009-10-30 12:16 245,760 a–sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat 2009-10-30 12:16 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat 2009-10-30 12:16 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009103020091031\index.dat 2009-10-30 12:16 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat ============= FINISH: 22:11:30.15 ===============
Hi,

you just need to empty your Java cache to delete those,

Clear Sun Jave cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.

run the following utility as well

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.


run the following scanner;

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



Any other symptoms besides slowness?
Thanks for helping. Yes, mostly the computer has just been running a little slow. It seems a little better already, though. Must have been alot of stuff from the internet

I have a few questions. Is there any way to empty the things from the internet without losing passwords and without having to log into everything all the time? I use CCleaner on boot. Would it be best to set it to leave cookies for this purpose? It seems to wipe out everything. Put another way, is there anything that just gets rid of the bad sruff?

Also, will I be removing these softwares when I am done?

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-10 19:09:25
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pwqiafoc.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xACB32C7A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xACB32B36]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xACB330EA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xACB33014]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xACB3270C]
SSDT spkv.sys ZwEnumerateKey [0xF74F4DA4]
SSDT spkv.sys ZwEnumerateValueKey [0xF74F5132]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xACB32C10]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xACB3264C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xACB326B0]
SSDT spkv.sys ZwQueryKey [0xF74F520A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xACB32D30]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xACB331B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xACB32CF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xACB32E70]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xACC1E620]

INT 0x62 ? 8AB51BF8
INT 0x63 ? 8ABBDBF8
INT 0x63 ? 8ABBDBF8
INT 0x83 ? 8ABBDBF8
INT 0xA4 ? 8ABBDBF8
INT 0xB4 ? 8ABBDBF8

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xACB3FAC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xACB3F8EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xACB3FA24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!_abnormal_termination + 148 804E27B4 4 Bytes JMP 27ACB330
PAGE ntoskrnl.exe!ObInsertObject 8056503A 5 Bytes JMP ACB3CEC2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!NtCreateSection 805652B3 7 Bytes JMP ACB3F8EE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FE4C 7 Bytes JMP ACB3FACA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ObMakeTemporaryObject 8059F8CA 5 Bytes JMP ACB3B536 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ZwLoadDriver 805A3B73 7 Bytes JMP ACB3FA28 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
? spkv.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B97AE8AC 3 Bytes JMP 8ABBD1D8
.text USBPORT.SYS!DllUnload + 4 B97AE8B0 1 Byte [D1]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AC9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD0ED C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB1C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E25467C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E480F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4741 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E47AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4612 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4674 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4872 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E46D6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1252] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4B77 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB1C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E480F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4741 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E47AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4612 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4674 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4872 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E46D6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
Device \FileSystem\Ntfs \Ntfs 8ABBC1F8

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\usbuhci \Device\USBPDO-0 8A9B91F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8ABBE1F8
Device \Driver\dmio \Device\DmControl\DmConfig 8ABBE1F8
Device \Driver\dmio \Device\DmControl\DmPnP 8ABBE1F8
Device \Driver\dmio \Device\DmControl\DmInfo 8ABBE1F8
Device \Driver\usbuhci \Device\USBPDO-1 8A9B91F8
Device \Driver\usbuhci \Device\USBPDO-2 8A9B91F8
Device \Driver\usbuhci \Device\USBPDO-3 8A9B91F8
Device \Driver\usbehci \Device\USBPDO-4 8A990500

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Ftdisk \Device\HarddiskVolume1 8AB521F8
Device \Driver\USBSTOR \Device\00000071 88B671F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8AB521F8
Device \Driver\Cdrom \Device\CdRom0 8A97B500
Device \Driver\USBSTOR \Device\00000072 88B671F8
Device \Driver\Cdrom \Device\CdRom1 8A97B500
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom2 8A97B500
Device \Driver\NetBT \Device\NetBT_Tcpip_{E83A5D2A-7A79-4FE8-98F7-41DCA48A7D95} 88BE71F8
Device \Driver\USBSTOR \Device\00000077 88B671F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 88BE71F8
Device \Driver\USBSTOR \Device\00000078 88B671F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{38065BB0-A094-4D4E-8677-FD93673B8A63} 88BE71F8
Device \Driver\NetBT \Device\NetbiosSmb 88BE71F8

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\usbuhci \Device\USBFDO-0 8A9B91F8
Device \Driver\usbuhci \Device\USBFDO-1 8A9B91F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 88BE51F8
Device \Driver\usbuhci \Device\USBFDO-2 8A9B91F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 88BE51F8
Device \Driver\usbuhci \Device\USBFDO-3 8A9B91F8
Device \Driver\usbehci \Device\USBFDO-4 8A990500
Device \Driver\Ftdisk \Device\FtControl 8AB521F8
Device \FileSystem\Cdfs \Cdfs 88B681F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Thanks for all the help so far. Computer seems to be running very smoothly now. Here is ComboFix log:

ComboFix 10-06-10.03 - Administrator 06/11/2010 0:24.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3063.2723 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
ADS - explorer.exe: deleted 88 bytes in 2 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\AVSredirect.dll

.
((((((((((((((((((((((((( Files Created from 2010-05-11 to 2010-06-11 )))))))))))))))))))))))))))))))
.

2010-06-10 05:21 . 2010-06-10 05:21 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-06-10 05:20 . 2009-03-02 18:00 95592 —-a-w- c:\windows\system32\drivers\StarPortLite.sys
2010-06-10 05:08 . 2010-06-10 05:08 158192 ——w- c:\windows\system32\pxwma.dll
2010-06-10 03:36 . 2010-06-10 03:36 ——– d—–w- c:\documents and settings\Administrator\Application Data\ElevatedDiagnostics
2010-06-09 22:28 . 2010-06-09 22:28 ——– d—–w- c:\program files\ESET
2010-06-09 19:36 . 2010-06-09 19:36 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-06-09 19:36 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-09 19:36 . 2010-06-09 19:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-09 19:36 . 2010-06-09 19:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-09 19:36 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-09 05:12 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 02:48 . 2010-06-09 02:48 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-09 02:48 . 2010-06-09 02:48 ——– d—–w- c:\program files\Trend Micro
2010-06-08 01:49 . 2010-06-08 01:49 63488 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-06-08 01:49 . 2010-06-08 01:49 52224 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-06-08 01:49 . 2010-06-08 01:49 117760 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-06-08 01:48 . 2010-06-08 01:48 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-06-08 01:48 . 2010-06-08 01:48 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-06-07 01:28 . 2010-06-07 01:28 ——– d–h–w- c:\windows\system32\GroupPolicy
2010-06-06 22:35 . 2010-06-06 22:35 ——– d—–w- c:\documents and settings\Administrator\Application Data\IObit
2010-06-06 22:35 . 2010-06-06 22:35 ——– d—–w- c:\program files\IObit
2010-06-06 20:16 . 2010-06-06 20:16 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Netscape
2010-06-06 20:16 . 2010-06-06 20:16 ——– d—–w- c:\documents and settings\Administrator\Application Data\Netscape
2010-06-06 20:16 . 2010-06-06 20:16 ——– d—–w- c:\program files\Netscape
2010-06-04 01:09 . 2008-10-15 09:09 ——– d—–w- C:\xpadder_gamepad_profiler
2010-06-02 21:42 . 2010-06-02 21:42 ——– d—–w- c:\program files\Common Files\Gibinsoft Shared
2010-06-02 21:42 . 2010-06-02 21:42 ——– d—–w- c:\program files\GiPo@Utilities
2010-06-02 18:06 . 2010-06-02 18:06 ——– d—–w- c:\program files\RocketDock
2010-06-02 15:15 . 2010-06-02 16:30 ——– d—–w- c:\documents and settings\Administrator\Application Data\Dexpot
2010-06-02 14:32 . 2010-06-02 14:32 ——– d—–w- c:\documents and settings\Administrator\Application Data\maComfort
2010-06-02 14:32 . 2010-06-02 17:15 ——– d—–w- c:\program files\maComfort
2010-06-02 04:27 . 2010-06-02 04:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\Auslogics
2010-06-02 03:15 . 2010-06-02 04:33 ——– d—–w- C:\shman
2010-06-02 02:15 . 2010-06-10 05:49 ——– d—–w- c:\program files\Auslogics
2010-05-30 14:26 . 2010-05-30 14:26 ——– d—–w- c:\windows\Downloaded Installations
2010-05-30 00:32 . 2010-05-30 00:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\EstSoft
2010-05-30 00:32 . 2010-05-30 00:42 ——– d—–w- c:\program files\ESTsoft
2010-05-29 20:29 . 2010-05-29 20:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Innovative Solutions
2010-05-29 20:29 . 2010-05-29 20:29 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Innovative Solutions
2010-05-29 20:29 . 2010-05-29 20:29 ——– d—–w- c:\program files\Innovative Solutions
2010-05-29 14:10 . 2010-05-29 14:10 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Software
2010-05-29 14:10 . 2010-05-29 14:10 ——– d—–w- c:\documents and settings\Administrator\Application Data\NCH Software
2010-05-29 14:10 . 2010-05-29 14:10 ——– d—–w- c:\program files\NCH Software
2010-05-29 13:29 . 2010-05-29 13:55 ——– d—–w- c:\program files\VLMC
2010-05-29 11:40 . 2010-05-29 11:40 ——– d—–w- c:\program files\Sonic Foundry
2010-05-29 11:39 . 2010-05-29 11:51 ——– d—–w- c:\program files\DebugMode
2010-05-29 10:33 . 2004-02-22 14:11 719872 —-a-w- c:\windows\system32\devil.dll
2010-05-29 10:33 . 2009-09-27 13:39 369152 —-a-w- c:\windows\system32\avisynth.dll
2010-05-29 10:33 . 2004-01-25 04:00 70656 —-a-w- c:\windows\system32\yv12vfw.dll
2010-05-29 10:33 . 2004-01-25 04:00 70656 —-a-w- c:\windows\system32\i420vfw.dll
2010-05-29 10:33 . 2010-05-29 10:33 ——– d—–w- c:\program files\AviSynth 2.5
2010-05-29 10:32 . 2008-03-16 12:30 216064 –sh–r- c:\windows\system32\nbDX.dll
2010-05-29 10:32 . 2007-02-21 10:47 31232 –sh–r- c:\windows\system32\msfDX.dll
2010-05-29 10:32 . 2006-05-03 09:06 163328 –sh–r- c:\windows\system32\flvDX.dll
2010-05-29 10:32 . 2010-05-29 10:32 ——– d—–w- c:\program files\eRightSoft
2010-05-23 07:30 . 2010-05-23 07:30 503808 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2fbeba8c-n\msvcp71.dll
2010-05-23 07:29 . 2010-05-23 07:29 499712 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2fbeba8c-n\jmc.dll
2010-05-23 07:29 . 2010-05-23 07:29 12800 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4094cbbe-n\decora-d3d.dll
2010-05-23 07:29 . 2010-05-23 07:29 61440 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4094cbbe-n\decora-sse.dll
2010-05-23 07:29 . 2010-05-23 07:29 348160 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2fbeba8c-n\msvcr71.dll
2010-05-18 02:33 . 2010-05-18 02:34 ——– d—–w- c:\program files\MPC HomeCinema
2010-05-18 00:47 . 2010-05-18 00:47 ——– d—–w- c:\program files\Xvid
2010-05-18 00:47 . 2009-06-07 20:24 180224 —-a-w- c:\windows\system32\xvidvfw.dll
2010-05-18 00:47 . 2009-06-07 20:16 819200 —-a-w- c:\windows\system32\xvidcore.dll
2010-05-18 00:36 . 2010-05-18 00:36 ——– d—–w- c:\program files\XP Codec Pack
2010-05-18 00:22 . 2010-05-18 00:22 ——– d—–w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2010-05-18 00:12 . 2010-05-18 00:12 ——– d—–w- c:\program files\Haali

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-11 03:09 . 2009-11-20 16:08 1 —-a-w- c:\documents and settings\Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-10 23:41 . 2009-11-19 08:40 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-10 07:57 . 2009-12-17 08:06 ——– d—–w- c:\program files\Oldgames
2010-06-09 13:56 . 2009-11-19 16:45 ——– d—–w- c:\documents and settings\Administrator\Application Data\BitTorrent
2010-06-08 01:48 . 2009-12-20 21:06 ——– d—–w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2010-06-05 17:57 . 2009-11-18 22:41 ——– d—–w- c:\program files\IrfanView
2010-06-04 09:09 . 2004-08-04 10:00 1033728 —-a-w- c:\windows\explorer.exe
2010-06-03 20:44 . 2004-08-04 10:00 218624 —-a-w- c:\windows\system32\uxtheme.dll
2010-06-03 14:10 . 2009-11-27 22:06 2316 —-a-w- c:\documents and settings\All Users\Application Data\xml9F.tmp
2010-06-03 14:10 . 2010-05-25 23:03 13757 —-a-w- c:\documents and settings\All Users\Application Data\xml31.tmp
2010-06-03 14:10 . 2009-11-27 22:06 9521 —-a-w- c:\documents and settings\All Users\Application Data\xml9D.tmp
2010-05-31 07:39 . 2010-03-01 06:32 ——– d—–w- c:\program files\Bible Explorer 4
2010-05-29 22:18 . 2010-01-09 02:48 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverScanner
2010-05-29 22:18 . 2010-01-09 02:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\Uniblue
2010-05-29 15:04 . 2010-03-18 12:46 439816 —-a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\setup.exe
2010-05-26 04:50 . 2009-11-19 09:18 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-09 01:33 . 2009-11-18 22:41 ——– d—–w- c:\program files\Google
2010-05-06 23:50 . 2009-11-19 09:48 ——– d—–w- c:\program files\Java
2010-05-06 20:59 . 2010-04-29 04:10 165032 —-a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2010-04-29 04:10 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2010-04-29 04:10 164048 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2010-04-29 04:10 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2010-04-29 04:10 100432 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2010-04-29 04:10 94800 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2010-04-29 04:10 19024 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2010-04-29 04:10 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 10:41 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 16:21 . 2010-05-04 16:21 ——– d—–w- c:\documents and settings\Administrator\Application Data\Unity
2010-05-02 05:22 . 2004-08-04 10:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 04:10 . 2010-04-29 04:10 ——– d—–w- c:\program files\Alwil Software
2010-04-29 04:10 . 2010-04-29 04:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-04-25 19:36 . 2010-04-25 09:35 ——– d—–w- c:\program files\EA SPORTS
2010-04-25 09:38 . 2010-04-25 09:37 ——– d—–w- c:\program files\EACOM
2010-04-25 09:38 . 2008-08-14 19:27 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-25 09:38 . 2010-04-25 09:38 474 —-a-w- c:\windows\eReg.dat
2010-04-25 09:11 . 2010-04-24 23:46 ——– d—–w- c:\program files\DOSBox-0.72
2010-04-20 05:30 . 2004-08-04 10:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-14 16:47 . 2010-04-29 04:10 38848 —-a-w- c:\windows\system32\avastSS.scr
2010-04-12 21:29 . 2010-05-06 23:50 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-03-15 03:17 . 2006-06-26 06:05 72864 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-05-03 09:06 . 2010-05-29 10:32 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2010-05-29 10:32 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2010-05-29 10:32 216064 –sh–r- c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-18 39408]
"Weather"="c:\program files\AWS\WeatherBug\Weather.exe" [2009-10-20 1693184]
"ftweak_RAMRush"="c:\program files\RAMRush\RAMRush.exe" [2009-09-17 670720]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-12-21 1803064]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-05-18 2397424]
"FBackup Scheduler"="c:\program files\Softland\FBackup 4\fbaSched.exe" [2010-05-18 2015056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-12-12 20480]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-18 198160]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2010\\RpcAgentSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2010\\WNt500x86\\sandra.mui"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2010\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/29/2010 12:10 AM 164048]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 2:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 2:41 PM 67656]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [6/10/2010 1:20 AM 95592]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [12/11/2009 8:56 PM 123280]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [12/11/2009 8:49 PM 41616]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/29/2010 12:10 AM 19024]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [11/30/2009 1:27 PM 100048]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [11/30/2009 1:27 PM 110992]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/10/2010 1:21 AM 721904]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/29/2010 3:17 AM 135664]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2010\RpcAgentSrv.exe [11/27/2009 6:02 PM 93336]
.
Contents of the 'Scheduled Tasks' folder

2010-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-06-08 c:\windows\Tasks\Defraggler Volume C Task.job
- c:\program files\Defraggler\df.exe [2009-12-02 17:37]

2010-06-09 c:\windows\Tasks\Defraggler Volume E Task.job
- c:\program files\Defraggler\df.exe [2009-12-02 17:37]

2010-06-10 c:\windows\Tasks\fba_Productivity Files.job
- c:\program files\Softland\FBackup 4\fbaSchedStarter.exe [2009-11-19 13:01]

2010-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 07:17]

2010-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 07:17]

2010-06-11 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-06-06 16:57]

2010-06-11 c:\windows\Tasks\User_Feed_Synchronization-{E0311074-F1C8-40DA-AE5A-33A049AF1E74}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://astrocomputers.net/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4s87tle8.default\
FF - prefs.js: browser.startup.homepage - hxxp://astrocomputers.net/
FF - prefs.js: browser.search.selectedEngine - GoogleFeed.net
FF - prefs.js: browser.startup.homepage - hxxp://www.google-feed.net/?CID=1&PID=StarBurn
FF - plugin: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4s87tle8.default\extensions\[removed]\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Opera\program\plugins\NPQNXWrap.dll
FF - plugin: c:\program files\Opera\program\plugins\npsnpy.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-DriverMax_RESTART - (no file)
HKCU-Run-Cookienator - c:\program files\Cookienator\cookienator.exe
AddRemove-UnityWebPlayer - c:\documents and settings\Administrator\Local Settings\Application Data\Unity\WebPlayer\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-11 00:30
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1715567821-2146905285-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ca,b7,4f,25,be,03,af,4c,91,2f,6e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d9,cb,c2,14,57,e0,84,4f,80,4d,15,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1012)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2010-06-11 00:33:37
ComboFix-quarantined-files.txt 2010-06-11 04:33

Pre-Run: 123,977,760,768 bytes free
Post-Run: 123,956,060,160 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 286B02AC49187458193459CACC784B50
Hi

Unless you use it regularly, I recommend removing the IOBIT software from your machine as that is now considered rogue software.

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
OK, I did not know about the IOBit software. I would like to keep it, because it is the best defragementer I have been able to find to date. What are the dangers of keeping it? Have people been having problems with updates? I'ver never heard the expression rogue software before. Here are the logs from MBAM and the Kaspersky: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4189 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 6/11/2010 8:21:31 AM mbam-log-2010-06-11 (08-21-31).txt Scan type: Quick scan Objects scanned: 119818 Time elapsed: 7 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\SkyMedia (Adware.SkyMedia) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Kaspersky: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Friday, June 11, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, June 11, 2010 05:14:58 Records in database: 4255519 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ E:\ F:\ G:\ H:\ Scan statistics: Objects scanned: 185413 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 07:08:26 File name / Threat / Threats count Selected area has been scanned. Malwarebytes found 1 infection which I removed on instruction, but the scan shows no action taken. I ran another quick scan just to see, and no threats showed up, so I guess it's gone
please post a fresh DDS Log as well as an Attach.txt and advise how your computer is running now and if there are any outstanding issues.
Computer seems to me to be running better. The hard drive was loud before, but it is much quieter. I think it was the temporary files. DDS followed by Attach: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 22:44:42.14 on Fri 06/11/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3063.2399 [GMT -4:00] AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\explorer.exe C:\Program Files\internet explorer\iexplore.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files\RAMRush\RAMRush.exe C:\Program Files\RocketDock\RocketDock.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Documents and Settings\Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://astrocomputers.net/ uInternet Connection Wizard,ShellNext = iexplore BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1 uRun: [ftweak_RAMRush] c:\program files\ramrush\RAMRush.exe uRun: [ccleaner] "c:\program files\ccleaner\CCleaner.exe" /AUTO uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe" uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [FBackup Scheduler] "c:\program files\softland\fbackup 4\fbaSched.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [CTHelper] CTHELPER.EXE mRun: [CTxfiHlp] CTXFIHLP.EXE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1256927863234 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\4s87tle8.default\ FF - prefs.js: browser.startup.homepage - hxxp://astrocomputers.net/ FF - prefs.js: browser.search.selectedEngine - GoogleFeed.net FF - prefs.js: browser.startup.homepage - hxxp://www.google-feed.net/?CID=1&PID=StarBurn FF - plugin: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\4s87tle8.default\extensions\[removed]\plugins\npTVUAx.dll FF - plugin: c:\documents and settings\administrator\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\opera\program\plugins\NPQNXWrap.dll FF - plugin: c:\program files\opera\program\plugins\npsnpy.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-4-29 164048] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [2010-6-10 95592] R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2009-12-11 123280] R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2009-12-11 41616] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-4-29 19024] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-29 40384] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-29 40384] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-29 40384] R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-11-30 100048] R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2009-11-30 110992] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-29 135664] S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2010\RpcAgentSrv.exe [2009-11-27 93336] =============== Created Last 30 ================ 2010-06-11 09:35 260,880 a——- c:\windows\system32\MSFLXGRD.ocx 2010-06-11 09:35 152,848 a——- c:\windows\system32\Comdlg32.ocx 2010-06-11 09:35 101,888 a——- c:\windows\system32\VB6STKIT.DLL 2010-06-11 00:23 a-dshr– C:\cmdcons 2010-06-11 00:19 256,512 a——- c:\windows\PEV.exe 2010-06-11 00:19 161,792 a——- c:\windows\SWREG.exe 2010-06-11 00:19 98,816 a——- c:\windows\sed.exe 2010-06-11 00:19 77,312 a——- c:\windows\MBR.exe 2010-06-10 01:21 721,904 a——- c:\windows\system32\drivers\sptd.sys 2010-06-10 01:20 95,592 a——- c:\windows\system32\drivers\StarPortLite.sys 2010-06-10 01:08 158,192 ——– c:\windows\system32\pxwma.dll 2010-06-09 23:36 –d—– c:\docume~1\admini~1\applic~1\ElevatedDiagnostics 2010-06-09 18:28 –d—– c:\program files\ESET 2010-06-09 15:36 –d—– c:\docume~1\admini~1\applic~1\Malwarebytes 2010-06-09 15:36 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-09 15:36 20,952 a——- c:\windows\system32\drivers\mbam.sys 2010-06-09 15:36 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-06-09 15:36 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-06-09 01:12 743,424 -c—— c:\windows\system32\dllcache\iedvtool.dll 2010-06-08 22:48 –d—– c:\program files\Trend Micro 2010-06-07 21:48 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2010-06-07 21:48 –d—– c:\program files\SUPERAntiSpyware 2010-06-06 21:28 –d-h— c:\windows\system32\GroupPolicy 2010-06-06 18:35 –d—– c:\docume~1\admini~1\applic~1\IObit 2010-06-06 18:35 –d—– c:\program files\IObit 2010-06-06 16:16 –d—– c:\program files\Netscape 2010-06-03 21:09 –d—– C:\xpadder_gamepad_profiler 2010-06-03 16:43 218,624 a——- c:\windows\system32\uxtheme.uxtender 2010-06-02 17:42 –d—– c:\program files\common files\Gibinsoft Shared 2010-06-02 17:42 –d—– c:\program files\GiPo@Utilities 2010-06-02 14:06 –d—– c:\program files\RocketDock 2010-06-02 13:11 –d—– c:\windows\pss 2010-06-02 11:15 –d—– c:\docume~1\admini~1\applic~1\Dexpot 2010-06-02 10:32 –d—– c:\docume~1\admini~1\applic~1\maComfort 2010-06-02 10:32 –d—– c:\program files\maComfort 2010-06-02 00:27 –d—– c:\docume~1\admini~1\applic~1\Auslogics 2010-06-01 23:15 –d—– C:\shman 2010-06-01 22:15 –d—– c:\program files\Auslogics 2010-05-30 10:26 –d—– c:\windows\Downloaded Installations 2010-05-29 20:32 –d—– c:\docume~1\admini~1\applic~1\EstSoft 2010-05-29 20:32 –d—– c:\program files\ESTsoft 2010-05-29 16:29 –d—– c:\docume~1\alluse~1\applic~1\Innovative Solutions 2010-05-29 16:29 –d—– c:\program files\Innovative Solutions 2010-05-29 10:10 –d—– c:\docume~1\admini~1\applic~1\NCH Software 2010-05-29 10:10 –d—– c:\program files\NCH Software 2010-05-29 09:29 –d—– c:\program files\VLMC 2010-05-29 07:44 44,189 a——- C:\WaxCrash.dmp 2010-05-29 07:40 –d—– c:\program files\Sonic Foundry 2010-05-29 07:39 –d—– c:\program files\DebugMode 2010-05-29 06:33 719,872 a——- c:\windows\system32\devil.dll 2010-05-29 06:33 369,152 a——- c:\windows\system32\avisynth.dll 2010-05-29 06:33 70,656 a——- c:\windows\system32\yv12vfw.dll 2010-05-29 06:33 70,656 a——- c:\windows\system32\i420vfw.dll 2010-05-29 06:33 –d—– c:\program files\AviSynth 2.5 2010-05-29 06:32 –d—– c:\program files\eRightSoft 2010-05-17 22:33 –d—– c:\program files\MPC HomeCinema 2010-05-17 20:47 819,200 a——- c:\windows\system32\xvidcore.dll 2010-05-17 20:47 180,224 a——- c:\windows\system32\xvidvfw.dll 2010-05-17 20:47 77,824 a——- c:\windows\system32\xvid.ax 2010-05-17 20:47 –d—– c:\program files\Xvid 2010-05-17 20:36 421,888 a——- c:\windows\system32\ac3filter.acm 2010-05-17 20:36 –d—– c:\program files\XP Codec Pack 2010-05-17 20:12 –d—– c:\program files\Haali ==================== Find3M ==================== 2010-06-04 05:09 1,033,728 a——- c:\windows\explorer.exe 2010-06-03 16:44 218,624 a——- c:\windows\system32\uxtheme.dll 2010-05-06 06:41 916,480 a——- c:\windows\system32\wininet.dll 2010-05-02 01:22 1,851,264 a——- c:\windows\system32\win32k.sys 2010-04-20 01:30 285,696 a——- c:\windows\system32\atmfd.dll 2010-04-12 17:29 411,368 a——- c:\windows\system32\deployJava1.dll 2006-05-03 05:06 163,328 —shr– c:\windows\system32\flvDX.dll 2007-02-21 06:47 31,232 —shr– c:\windows\system32\msfDX.dll 2008-03-16 08:30 216,064 —shr– c:\windows\system32\nbDX.dll 2009-10-30 12:16 245,760 a–sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat 2009-10-30 12:16 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat 2009-10-30 12:16 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009103020091031\index.dat ============= FINISH: 22:45:30.07 =============== Attach: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 8/14/2008 3:06:11 PM System Uptime: 6/11/2010 8:38:06 AM (14 hours ago) Motherboard: Dell Computer Corp. | | 0U1324 Processor: Intel® Celeron® CPU 2.40GHz | Microprocessor | 2394/400mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 149 GiB total, 115.221 GiB free. E: is FIXED (NTFS) - 112 GiB total, 83.103 GiB free. F: is CDROM (CDFS) G: is CDROM () H: is CDROM (CDFS) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP197: 5/6/2010 7:49:44 PM - Installed Java™ 6 Update 20 RP198: 5/9/2010 5:32:11 AM - System Checkpoint RP199: 5/13/2010 12:53:09 AM - Software Distribution Service 3.0 RP200: 5/17/2010 10:09:46 AM - System Checkpoint RP201: 5/19/2010 9:31:04 AM - System Checkpoint RP202: 5/20/2010 10:17:27 AM - System Checkpoint RP203: 5/21/2010 11:07:23 PM - System Checkpoint RP204: 5/24/2010 1:06:02 PM - Software Distribution Service 3.0 RP205: 5/26/2010 3:10:57 AM - Software Distribution Service 3.0 RP206: 5/29/2010 6:03:24 PM - Before Folder View Install RP207: 5/29/2010 10:33:01 PM - Installed Photo Story 3 for Windows RP208: 5/29/2010 10:40:22 PM - Removed Photo Story 3 for Windows RP209: 5/30/2010 10:27:14 AM - Installed Calculator Powertoy for Windows XP RP210: 5/31/2010 10:02:18 PM - System Checkpoint RP211: 6/2/2010 10:32:47 AM - Installed maComfort RP212: 6/2/2010 5:42:19 PM - Installed GiPo@MoveOnBoot 1.9.5 RP213: 6/3/2010 11:47:57 AM - Installed Cookienator RP214: 6/7/2010 12:20:47 AM - Control Panel\Administrative Tools\Local Security Policy\Security Settings\Local Policies\Security Options\Account Limit local account use of blank passwords to console logon only RP215: 6/8/2010 10:48:09 PM - Installed HiJackThis RP216: 6/9/2010 1:13:36 AM - Software Distribution Service 3.0 RP217: 6/9/2010 1:45:06 AM - Software Distribution Service 3.0 RP218: 6/9/2010 11:26:46 PM - Installed %1 %2. RP219: 6/10/2010 1:21:21 AM - SPTD setup V1.59 RP220: 6/10/2010 1:49:36 AM - Removed Cookienator ==== Installed Programs ====================== 7-Zip 4.57 AAC Decoder Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3.2 Adobe Shockwave Player 11.5 ALTools Update Apple Application Support Apple Software Update Auslogics Registry Defrag AutoUpdate avast! Free Antivirus BE Downloadable Edition BF Battleship World War 2 BitTorrent Calculator Powertoy for Windows XP CCleaner Conexant SmartHSFi V.9x 56K DF PCI Modem CPUID CPU-Z 1.52.2 Defraggler Dell ResourceCD DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Plus Web Player DivX Version Checker DriverMax 5 EA.com Matchup EA.com Update ESET Online Scanner v3 FBackup 4 GiPo@MoveOnBoot 1.9.5 Google Earth Plug-in Google Toolbar for Internet Explorer Google Update Helper H.264 Decoder Haali Media Splitter HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) InfraRecorder Intel® Extreme Graphics 2 Driver Intel® PRO Network Adapters and Drivers IrfanView (remove only) Java Auto Updater Java™ 6 Update 20 maComfort Magic ISO Maker v5.4 (build 0239) MagicDisc 2.7.106 Malwarebytes' Anti-Malware Media Player Classic - Home Cinema v. 1.3.1249.0 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works 7.0 MKV Splitter Mozilla Firefox (3.5.6) Mozilla Thunderbird (3.0) Netscape Navigator ([removed]) NHL 2002 NVIDIA Drivers OpenOffice.org 3.2 Opera 10.10 PC Wizard 2009.1.9111 Quake QuickTime RAMRush 1.0.6.917 RealPlayer Recuva Risk II RocketDock 1.3.5 RSS Advantage Newsticker V1.1.0.57 Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) SiSoftware Sandra Lite 2010 Smart Defrag SopCast 3.2.4 SoundMAX Sun VirtualBox SUPER © Version 2010.bld.38 (May 2, 2010) SUPERAntiSpyware System Requirements Lab Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB971930) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VC80CRTRedist - 8.0.50727.4053 VideoPad Video Editor WeatherBug WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Live OneCare safety scanner Windows Media Format 11 runtime Windows Media Player 11 Windows PowerShell™ 1.0 Windows XP Service Pack 3 XP Codec Pack Xvid 1.2.2 final uninstall ==== Event Viewer Messages From Past Week ======== 6/9/2010 11:37:21 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service. 6/6/2010 5:56:24 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSP aswTdi Fips intelppm OMCI VBoxDrv VBoxUSBMon 6/6/2010 5:51:37 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT OMCI RasAcd Rdbss Tcpip VBoxDrv VBoxUSBMon 6/6/2010 5:51:37 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 6/6/2010 5:51:37 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 6/6/2010 5:51:37 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 6/6/2010 5:51:37 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 6/6/2010 5:50:57 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 6/6/2010 5:50:47 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 6/6/2010 12:30:35 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the WZCSVC service. ==== End Of File ===========================
Your logs appear to be clean

If you just use IOBIT for the defragmenter, that's fine, i don't think there is any concern about that at all,

but try this one, let me know how it compares:

Download and run Auslogics Disc Defragmenter


Just some housekeeping to do now,

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT


  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Thankyou so much for your help. I made all the downloads, and I am going to install them all now. My IE settings were already correct, so that was good already. After reading so many accounts of so many problems, I am really going to be careful. Thanks again for everything you guys do. I will now mark the thread as resolved…RESOLVED! :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI