This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

my computer folders start everytime i boot up

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

it did not create log first time ,don't reckon it even did everything correct but now after rerunning i have a log file .



ComboFix 10-06-28.01 - Administrator 29/06/2010 16:49:22.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1048 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\ADMINI~1\LOCALS~1\Temp\install_flash_player.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Packet.dll
c:\windows\system32\Process.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-29 )))))))))))))))))))))))))))))))
.

2010-06-23 14:26 . 2010-06-23 14:26 ——– d—–w- C:\_OTL
2010-06-20 09:03 . 2010-06-20 09:03 ——– d—–w- c:\program files\Common Files\HP
2010-06-20 09:01 . 2009-02-11 11:03 589824 —-a-w- c:\windows\system32\hpost_d02c.dll
2010-06-20 09:01 . 2009-02-11 11:03 712704 —-a-w- c:\windows\system32\hposwia_d02c.dll
2010-06-20 09:01 . 2009-02-11 11:03 315392 —-a-w- c:\windows\system32\hposc_d02a.dll
2010-06-20 08:57 . 2010-06-20 09:05 137724 —-a-w- c:\windows\hpoins44.dat
2010-06-20 08:57 . 2010-01-30 13:02 512 ——w- c:\windows\hpomdl44.dat
2010-06-20 08:51 . 2008-10-28 10:27 372736 —-a-r- c:\windows\system32\hppldcoi.dll
2010-06-20 08:51 . 2008-10-28 10:27 309760 —-a-r- c:\windows\system32\difxapi.dll
2010-06-18 17:27 . 2010-06-18 17:27 50968 —-a-w- c:\windows\system32\avgfwdx.dll
2010-06-18 17:27 . 2010-06-18 17:27 30104 —-a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-06-18 17:24 . 2010-06-18 17:30 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-06-16 18:39 . 2010-06-16 18:39 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-15 16:00 . 2010-06-15 16:00 133648 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-15 16:00 . 2010-06-15 16:00 133720 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-14 18:59 . 2010-06-14 18:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\Google Chrome Backup
2010-06-13 11:11 . 2010-06-13 11:11 ——– d—–w- c:\program files\Trend Micro
2010-06-09 15:31 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-30 21:28 . 2010-05-30 21:28 ——– d—–w- c:\windows\XSxS
2010-05-30 21:28 . 2010-05-30 21:28 ——– d—–w- c:\program files\Xenocode

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-29 16:14 . 2010-01-12 20:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-06-29 15:39 . 2009-06-15 07:38 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-27 21:57 . 2009-06-27 01:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\uTorrent
2010-06-27 21:18 . 2010-01-17 00:08 ——– d—–w- c:\documents and settings\Administrator\Application Data\vlc
2010-06-27 20:29 . 2009-06-17 23:47 ——– d—–w- c:\program files\Opera
2010-06-20 09:00 . 2009-01-25 11:55 ——– d—–w- c:\program files\HP
2010-06-18 17:25 . 2009-08-16 22:18 ——– d—–w- c:\program files\AVG
2010-06-14 18:58 . 2009-06-15 07:18 70400 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-12 22:55 . 2010-01-21 21:24 ——– d—–w- c:\program files\UltraISO
2010-06-12 22:33 . 2009-01-25 11:57 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-06-12 12:20 . 2009-06-18 01:16 ——– d—–w- c:\program files\Aspell
2010-06-12 12:19 . 2009-12-31 18:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-12 12:18 . 2009-06-27 01:51 ——– d—–w- c:\program files\LimeWire
2010-06-12 12:15 . 2009-06-13 00:33 ——– d—–w- c:\program files\GemMaster
2010-06-09 22:12 . 2010-02-27 23:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-05 12:55 . 2009-06-20 14:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-01 15:31 . 2009-06-27 01:34 ——– d—–w- c:\program files\uTorrent
2010-05-24 21:39 . 2009-10-01 18:26 ——– d—–w- c:\program files\CCleaner
2010-05-24 19:18 . 2009-01-25 23:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\HPAppData
2010-05-23 12:40 . 2009-12-01 23:14 ——– d—–w- c:\program files\QuickTime
2010-05-23 12:38 . 2010-05-23 12:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-05-23 12:33 . 2010-05-23 11:03 ——– d—–w- c:\program files\CodeStuff
2010-05-16 10:40 . 2010-05-01 11:31 57344 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-16 10:40 . 2010-05-01 11:18 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-05-16 10:39 . 2010-05-01 11:25 ——– d—–w- c:\program files\DivX
2010-05-16 10:37 . 2010-05-16 10:37 144696 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-08 21:52 . 2010-01-17 16:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-06 10:41 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-05 19:36 . 2010-01-12 20:32 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-05-05 19:36 . 2010-01-12 20:32 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-05-03 14:59 . 2010-05-03 14:59 ——– d—–w- c:\program files\Common Files\AOLSHARE
2010-05-03 14:59 . 2010-05-03 14:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\AOL
2010-05-02 05:22 . 2004-08-10 11:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-05-01 11:29 . 2010-05-01 11:29 ——– d—–w- c:\documents and settings\Administrator\Application Data\DivX
2010-05-01 11:18 . 2010-05-01 11:31 1180952 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-29 14:39 . 2010-01-17 16:49 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2010-01-17 16:49 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:30 . 2004-08-10 11:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-07 21:31 . 2010-04-07 21:31 5607 —-a-w- c:\windows\~GLH0001.TMP
2010-04-07 21:31 . 2010-04-07 21:31 27136 —-a-w- c:\windows\~GLH0000.TMP
2010-04-07 21:31 . 2010-04-07 21:31 140288 —-a-w- c:\windows\~GLC0000.TMP
2010-03-31 16:33 . 2009-06-20 00:38 335 —-a-w- c:\windows\nsreg.dat
.

——- Sigcheck ——-

[-] 2009-12-30 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2009-12-30 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys

[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe

c:\windows\System32\ctfmon.exe … is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-20 340456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^WWU.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\WWU.lnk
backup=c:\windows\pss\WWU.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Launchy.lnk
backup=c:\windows\pss\Launchy.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-06-16 11:55 133104 —-atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ThreatFire"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\Administrator\\Desktop\\Charon.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1270674119\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1270674119\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24884:TCP"= 24884:TCP:BitComet 24884 TCP
"24884:UDP"= 24884:UDP:BitComet 24884 UDP
"20482:TCP"= 20482:TCP:BitComet 20482 TCP
"20482:UDP"= 20482:UDP:BitComet 20482 UDP
"9067:TCP"= 9067:TCP:BitComet 9067 TCP(ED2K)
"9067:UDP"= 9067:UDP:BitComet 9067 UDP(ED2K)
"9751:TCP"= 9751:TCP:BitComet 9751 TCP(ED2K)
"9751:UDP"= 9751:UDP:BitComet 9751 UDP(ED2K)
"7043:TCP"= 7043:TCP:BitComet 7043 TCP
"7043:UDP"= 7043:UDP:BitComet 7043 UDP
"10255:TCP"= 10255:TCP:BitComet 10255 TCP
"10255:UDP"= 10255:UDP:BitComet 10255 UDP
"8343:TCP"= 8343:TCP:BitComet 8343 TCP
"8343:UDP"= 8343:UDP:BitComet 8343 UDP
"7175:TCP"= 7175:TCP:BitComet 7175 TCP
"7175:UDP"= 7175:UDP:BitComet 7175 UDP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [14/10/2009 21:18 36880]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [14/01/2010 23:45 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [14/01/2010 23:46 59664]
R1 wbsecdrv;wbsecdrv Protocol Driver;c:\windows\system32\drivers\wbsecdrv.sys [08/04/2010 17:15 17952]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R2 wbsecsvc;wbsecsvc;c:\windows\system32\wbsecsvc.exe [08/04/2010 17:15 274432]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 14:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/10/2009 19:39 19472]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [14/01/2010 23:46 33552]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [18/06/2010 18:27 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [18/06/2010 18:27 30104]
S3 W35UND;IS89C35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\drivers\W35UND.SYS [08/04/2010 17:15 117632]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [24/10/2009 16:55 717296]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 16:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2010-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1326574676-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 11:55]

2010-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1326574676-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 11:55]

2010-06-29 c:\windows\Tasks\User_Feed_Synchronization-{FFFA57F7-E474-4C3A-9B66-7535F0F662CF}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.co.uk/aolbroadband
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.myaolbroadband.co.uk
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
IE: &D&ownload &with BitComet
IE: &D&ownload all video with BitComet
IE: &D&ownload all with BitComet
IE: &Download by Orbit
IE: &Grab video by Orbit
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Do&wnload selected by Orbit
IE: Down&load all by Orbit
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL -
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}\platform\WINNT_x86-msvc\components\enbar3.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\KavLinkFilter.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\NPMetaStream3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
user_pref('capability.policy.policynames', 'localfilelinks');user_pref('capability.policy.localfilelinks.sites', 'hxxp://www.webmynd.com http://www.google.com');user_pref('…ri.enabled', 'allAccess');.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-avgrsstarter - (no file)
MSConfigStartUp-Advanced SystemCare 3 - c:\program files\IObit\Advanced SystemCare 3\AWC.exe
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-DU Meter - c:\program files\DU Meter\DUMeter.exe
MSConfigStartUp-ISW - c:\program files\CheckPoint\ZAForceField\ForceField.exe
MSConfigStartUp-MSSE - c:\program files\Microsoft Security Essentials\msseces.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
MSConfigStartUp-ZoneAlarm Client - c:\program files\Zone Labs\ZoneAlarm\zlclient.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-29 17:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ThreatFire]
"AlternateImagePath"=""
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-789336058-1326574676-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,43,8e,9a,c0,2d,a6,4c,43,85,76,45,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,da,72,39,5d,4b,78,90,4a,99,93,8e,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,43,8e,9a,c0,2d,a6,4c,43,85,76,45,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1372)
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'lsass.exe'(1428)
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'explorer.exe'(1128)
c:\windows\system32\WININET.dll
c:\program files\ThreatFire\TfWah.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\program files\ThreatFire\TFNI.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\ThreatFire\TFService.exe
c:\windows\wanmpsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2010-06-29 17:28:49 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-29 16:28

Pre-Run: 56,320,016,384 bytes free
Post-Run: 56,529,436,672 bytes free

- - End Of File - - 1E6E78B3ECEC92B98A729DD24D824CFD

Thanks. :thumbup:

How is your computer running now?

edruss



so far so good seems to be running okay, thank you very much for all your help .
I need you to do the following steps.
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

Fcopy::
c:\windows\ServicePackFiles\i386\tcpip.sys | c:\windows\system32\dllcache\tcpip.sys
c:\windows\ServicePackFiles\i386\tcpip.sys | c:\windows\system32\drivers\tcpip.sys

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt .
Please post this log in your next reply.

edruss
this took two attempt as it said somthing about shooting down emulating drives and then shut computer down ,restarted and nothing happened so i redid it and it worked just dropped the text fill into combo fix and let it do it's work,here is the log file below .

ComboFix 10-06-29.04 - Administrator 30/06/2010 20:59:22.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1037 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.tx
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
————— FCopy —————

c:\windows\ServicePackFiles\i386\tcpip.sys –> c:\windows\system32\dllcache\tcpip.sys
c:\windows\ServicePackFiles\i386\tcpip.sys –> c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-30 )))))))))))))))))))))))))))))))
.

2010-06-30 19:50 . 2010-06-30 19:52 ——– d—–w- C:\32788R22FWJFW
2010-06-23 14:26 . 2010-06-23 14:26 ——– d—–w- C:\_OTL
2010-06-20 09:03 . 2010-06-20 09:03 ——– d—–w- c:\program files\Common Files\HP
2010-06-20 09:01 . 2009-02-11 11:03 589824 —-a-w- c:\windows\system32\hpost_d02c.dll
2010-06-20 09:01 . 2009-02-11 11:03 712704 —-a-w- c:\windows\system32\hposwia_d02c.dll
2010-06-20 09:01 . 2009-02-11 11:03 315392 —-a-w- c:\windows\system32\hposc_d02a.dll
2010-06-20 08:57 . 2010-06-20 09:05 137724 —-a-w- c:\windows\hpoins44.dat
2010-06-20 08:57 . 2010-01-30 13:02 512 ——w- c:\windows\hpomdl44.dat
2010-06-20 08:51 . 2008-10-28 10:27 372736 —-a-r- c:\windows\system32\hppldcoi.dll
2010-06-20 08:51 . 2008-10-28 10:27 309760 —-a-r- c:\windows\system32\difxapi.dll
2010-06-18 17:27 . 2010-06-18 17:27 50968 —-a-w- c:\windows\system32\avgfwdx.dll
2010-06-18 17:27 . 2010-06-18 17:27 30104 —-a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-06-18 17:24 . 2010-06-18 17:30 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-06-16 18:39 . 2010-06-16 18:39 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-15 16:00 . 2010-06-15 16:00 133648 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-15 16:00 . 2010-06-15 16:00 133720 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-14 18:59 . 2010-06-14 18:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\Google Chrome Backup
2010-06-13 11:11 . 2010-06-13 11:11 ——– d—–w- c:\program files\Trend Micro
2010-06-09 15:31 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-30 19:49 . 2010-01-12 20:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-06-30 19:37 . 2009-06-27 01:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\uTorrent
2010-06-30 19:28 . 2009-06-15 07:38 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-27 21:18 . 2010-01-17 00:08 ——– d—–w- c:\documents and settings\Administrator\Application Data\vlc
2010-06-27 20:29 . 2009-06-17 23:47 ——– d—–w- c:\program files\Opera
2010-06-20 09:00 . 2009-01-25 11:55 ——– d—–w- c:\program files\HP
2010-06-18 17:25 . 2009-08-16 22:18 ——– d—–w- c:\program files\AVG
2010-06-14 18:58 . 2009-06-15 07:18 70400 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-12 22:55 . 2010-01-21 21:24 ——– d—–w- c:\program files\UltraISO
2010-06-12 22:33 . 2009-01-25 11:57 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-06-12 12:20 . 2009-06-18 01:16 ——– d—–w- c:\program files\Aspell
2010-06-12 12:19 . 2009-12-31 18:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-12 12:18 . 2009-06-27 01:51 ——– d—–w- c:\program files\LimeWire
2010-06-12 12:15 . 2009-06-13 00:33 ——– d—–w- c:\program files\GemMaster
2010-06-09 22:12 . 2010-02-27 23:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-05 12:55 . 2009-06-20 14:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-01 15:31 . 2009-06-27 01:34 ——– d—–w- c:\program files\uTorrent
2010-05-30 21:28 . 2010-05-30 21:28 ——– d—–w- c:\program files\Xenocode
2010-05-24 21:39 . 2009-10-01 18:26 ——– d—–w- c:\program files\CCleaner
2010-05-24 19:18 . 2009-01-25 23:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\HPAppData
2010-05-23 12:40 . 2009-12-01 23:14 ——– d—–w- c:\program files\QuickTime
2010-05-23 12:38 . 2010-05-23 12:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-05-23 12:33 . 2010-05-23 11:03 ——– d—–w- c:\program files\CodeStuff
2010-05-16 10:40 . 2010-05-01 11:31 57344 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-16 10:40 . 2010-05-01 11:18 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-05-16 10:39 . 2010-05-01 11:25 ——– d—–w- c:\program files\DivX
2010-05-16 10:37 . 2010-05-16 10:37 144696 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-08 21:52 . 2010-01-17 16:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-06 10:41 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-05 19:36 . 2010-01-12 20:32 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-05-05 19:36 . 2010-01-12 20:32 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-05-03 14:59 . 2010-05-03 14:59 ——– d—–w- c:\program files\Common Files\AOLSHARE
2010-05-03 14:59 . 2010-05-03 14:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\AOL
2010-05-02 05:22 . 2004-08-10 11:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-05-01 11:18 . 2010-05-01 11:31 1180952 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-29 14:39 . 2010-01-17 16:49 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2010-01-17 16:49 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:30 . 2004-08-10 11:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-07 21:31 . 2010-04-07 21:31 5607 —-a-w- c:\windows\~GLH0001.TMP
2010-04-07 21:31 . 2010-04-07 21:31 27136 —-a-w- c:\windows\~GLH0000.TMP
2010-04-07 21:31 . 2010-04-07 21:31 140288 —-a-w- c:\windows\~GLC0000.TMP
.

——- Sigcheck ——-

[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe

c:\windows\System32\ctfmon.exe … is missing !!
.
((((((((((((((((((((((((((((( SnapShot@2010-06-29_16.14.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-30 19:45 . 2010-06-30 19:45 16384 c:\windows\Temp\Perflib_Perfdata_248.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-20 340456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^WWU.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\WWU.lnk
backup=c:\windows\pss\WWU.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Launchy.lnk
backup=c:\windows\pss\Launchy.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-06-16 11:55 133104 —-atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ThreatFire"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\Administrator\\Desktop\\Charon.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1270674119\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1270674119\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24884:TCP"= 24884:TCP:BitComet 24884 TCP
"24884:UDP"= 24884:UDP:BitComet 24884 UDP
"20482:TCP"= 20482:TCP:BitComet 20482 TCP
"20482:UDP"= 20482:UDP:BitComet 20482 UDP
"9067:TCP"= 9067:TCP:BitComet 9067 TCP(ED2K)
"9067:UDP"= 9067:UDP:BitComet 9067 UDP(ED2K)
"9751:TCP"= 9751:TCP:BitComet 9751 TCP(ED2K)
"9751:UDP"= 9751:UDP:BitComet 9751 UDP(ED2K)
"7043:TCP"= 7043:TCP:BitComet 7043 TCP
"7043:UDP"= 7043:UDP:BitComet 7043 UDP
"10255:TCP"= 10255:TCP:BitComet 10255 TCP
"10255:UDP"= 10255:UDP:BitComet 10255 UDP
"8343:TCP"= 8343:TCP:BitComet 8343 TCP
"8343:UDP"= 8343:UDP:BitComet 8343 UDP
"7175:TCP"= 7175:TCP:BitComet 7175 TCP
"7175:UDP"= 7175:UDP:BitComet 7175 UDP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [14/10/2009 21:18 36880]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [14/01/2010 23:45 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [14/01/2010 23:46 59664]
R1 wbsecdrv;wbsecdrv Protocol Driver;c:\windows\system32\drivers\wbsecdrv.sys [08/04/2010 17:15 17952]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R2 wbsecsvc;wbsecsvc;c:\windows\system32\wbsecsvc.exe [08/04/2010 17:15 274432]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 14:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/10/2009 19:39 19472]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [14/01/2010 23:46 33552]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [18/06/2010 18:27 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [18/06/2010 18:27 30104]
S3 W35UND;IS89C35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\drivers\W35UND.SYS [08/04/2010 17:15 117632]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [24/10/2009 16:55 717296]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 16:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-06-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2010-06-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1326574676-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 11:55]

2010-06-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1326574676-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 11:55]

2010-06-30 c:\windows\Tasks\User_Feed_Synchronization-{FFFA57F7-E474-4C3A-9B66-7535F0F662CF}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.co.uk/aolbroadband
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.myaolbroadband.co.uk
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
IE: &D&ownload &with BitComet
IE: &D&ownload all video with BitComet
IE: &D&ownload all with BitComet
IE: &Download by Orbit
IE: &Grab video by Orbit
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Do&wnload selected by Orbit
IE: Down&load all by Orbit
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
user_pref('capability.policy.policynames', 'localfilelinks');user_pref('capability.policy.localfilelinks.sites', 'hxxp://www.webmynd.com http://www.google.com');user_pref('…ri.enabled', 'allAccess');.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-30 21:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ThreatFire]
"AlternateImagePath"=""
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-789336058-1326574676-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,43,8e,9a,c0,2d,a6,4c,43,85,76,45,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,da,72,39,5d,4b,78,90,4a,99,93,8e,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,43,8e,9a,c0,2d,a6,4c,43,85,76,45,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1368)
c:\program files\ThreatFire\TFWAH.dll
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll

- - - - - - - > 'lsass.exe'(1424)
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'explorer.exe'(1220)
c:\windows\system32\WININET.dll
c:\program files\ThreatFire\TfWah.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\program files\ThreatFire\TFNI.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
Completion time: 2010-06-30 21:28:39
ComboFix-quarantined-files.txt 2010-06-30 20:28
ComboFix2.txt 2010-06-29 16:29

Pre-Run: 54,941,888,512 bytes free
Post-Run: 54,925,094,912 bytes free

- - End Of File - - 0154C9E6561DE969694EFC806C5233D6
Your log looks pretty good. Let's just do these to verify.

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.


Please run Kapersky Online AV Scanner using the steps below.
Using Internet Explore Go to Kaspersky Online Scanner
  • Read the Requirements and limitations before you click Accept.
  • After you click Accept please click Run in the box if one appears .
  • Under the Scan section click My Computer This may take a few hours so be prepared to let it run until it finishes.
  • After it finishes Click Scan Report
  • Click Save Report As…
  • In the Save in: box choose Desktop
  • In the Files of type: box choose Text file(.txt)
  • In the File name: box give it a name such as Kas Report or something you will recognize.
  • Click Save
.
Copy and paste the report into your next reply along with a description of how your PC is behaving.

edruss
Thanks you, I will get that done and the results posted by tomorrow . this is coming up when I try to open java ra ,so i will try and goggle it and open it . Error 403 - Forbidden You tried to access a document for which you don't have privileges.

Ok. If you can't get JavaRa to run, try to get the Kaspersky scan.

edruss


it's okay got it to run through google ,will now go for the kasperskey scan .
I will be taking this now :)

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
:wavey: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=47c67f652f7e1544b859101cae72d093 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-07-03 06:41:32 # local_time=2010-07-03 07:41:32 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 1749056 1749056 0 0 # compatibility_mode=768 16777215 100 0 33127001 33127001 0 0 # compatibility_mode=1024 16777215 100 0 1294649 1294649 0 0 # compatibility_mode=1280 16777175 100 0 14851915 14851915 0 0 # compatibility_mode=2560 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 175 175 0 0 # scanned=77582 # found=4 # cleaned=4 # scan_time=5959 C:\Documents and Settings\Administrator\Desktop\Downloads 50gig\Toolbar Uninstaller 1.0.0.1.34.exe probably a variant of Win32/Agent trojan (deleted - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\Administrator\My Documents\Downloads\WindowsCannotFindFixWizard.exe a variant of Win32/SecurityStronghold application (deleted - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{6AE494CD-CBFD-4C1B-BDD7-BC2E38A15565}\RP2\A0001238.exe a variant of Win32/SecurityStronghold application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{6AE494CD-CBFD-4C1B-BDD7-BC2E38A15565}\RP21\A0009759.exe probably a variant of Win32/Agent trojan (deleted - quarantined) 00000000000000000000000000000000 C

:wavey: Ok that looks like a cool result - what problems do you have at the moment ?



the machine seems to be running okay now ,the only problem i do have which is not related is the fact that a little while ago I installed abunto dual boot which i would love to get rid of and restore my partition ,but seems to complicated . ^_^
OK lets clear my tools and I will then see if I can come up with a simple guide to removing that. But, to clarify - Ubunto is removed but the loader is still showing as a valid operating system when you start ?

I will remove my tools now and give some recommendations, but I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Files
    c:\windows\System32\ctfmon.exe|c:\windows\ServicePackFiles\i386\ctfmon.exe /replace
    
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS] 
    [Reboot]

[*]Then click the Run Fix button at the top

[*]Let the program run unhindered, reboot the PC when it is done


Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.



SPRING CLEAN

Download and run Puran Disc Defragmenter

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
    [external image: Posted Image] Malwarebytes. Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
  • Microsoft Windows Update


To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI