This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

sysinternal virus

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:20:01 PM, on 7/14/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\IObit\IObit Security 360\IS360tray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common

Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common

Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Maxthon2\Maxthon.exe
C:\PROGRA~1\Maxthon2\Modules\MXDOWN~1\MXDOWN~1.EXE
C:\MxDownload\HiJackThis.exe
C:\Program Files\Microsoft Works\wkswp.exe
C:\Program Files\Microsoft Works\wkgdcach.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

Page = http://www.slingo.com/
R1 -

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn2\yt.dll
F2 - REG:system.ini:

UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
O2 - BHO: YSPManager -

{25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program

Files\Yahoo!\Search Protection\ysp.dll
O2 - BHO: Yahoo! IE Services Button -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class -

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) -

{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program

Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [avast!]

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IObit Security 360] "C:\Program

Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O4 - HKLM\..\Run: [MSConfig]

C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program

Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program

Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\RunOnce: [Shockwave Updater]

C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update

-1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT

5.1; FunWebProducts; Mozilla/4.0 (compatible; MSIE 6.0;

Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR

2.0.50727; .NET CLR 3.0.04506.30; yie8; yie8)"

-"http://www.gameland.com/games/multiplayer/newmultiuser/i

ngamechat.asp?sessid=7075633458504A60AA5CA0378532FFE9&tabl

ename=1~@7026A26D-BBB2-4BC3-A622-E735FBA8DF7F&gamename=Chr

istmas%20In%20A%20Box"
O4 - HKUS\S-1-5-18\..\Run: [pbuilder] \pb32.exe (User

'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [pbuilder] \pb32.exe (User

'Default user')
O8 - Extra context menu item: &Yahoo! Search -

file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Google Photos

Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Customize Menu -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Yahoo! &Dictionary -

file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -

file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS -

file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Fill Forms -

{320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program

Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

(file missing)
O9 - Extra 'Tools' menuitem: Fill Forms -

{320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program

Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

(file missing)
O9 - Extra button: Save -

{320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program

Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

(file missing)
O9 - Extra 'Tools' menuitem: Save Forms -

{320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program

Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

(file missing)
O9 - Extra button: AOL Toolbar -

{4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar -

{4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Yahoo! Services -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ICQ -

{6224f700-cba3-4071-b251-47cb894244cd} - C:\Program

Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ -

{6224f700-cba3-4071-b251-47cb894244cd} - C:\Program

Files\ICQ\ICQ.exe
O9 - Extra button: ComcastHSI -

{669B269B-0D4E-41FB-A3D8-FD67CA94F646} -

http://www.comcast.net/ (file missing)
O9 - Extra button: RoboForm -

{724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program

Files\Siber Systems\AI

RoboForm\RoboFormComShowToolbar.html (file missing)
O9 - Extra 'Tools' menuitem: RoboForm Toolbar -

{724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program

Files\Siber Systems\AI

RoboForm\RoboFormComShowToolbar.html (file missing)
O9 - Extra button: Bonjour -

{7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program

Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Support -

{8828075D-D097-4055-AA02-2DBFA9D85E8A} -

http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help -

{97809617-3937-4F84-B335-9BB05EF1A8D4} -

http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) -

{BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program

Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra 'Tools' menuitem: Yahoo! Search Protection -

{BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program

Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra button: Real.com -

{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide -

{E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program

Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {0E718CF0-047B-6345-87FE-28541D87FEA9} -

http://85.255.115.229/1/gdnUS1388.exe
O16 - DPF: {1A781DED-4153-C22D-3213-A3211E29DF13}

(GameDesire Card Games) -

http://cached.gamedesire.com/g_bin/eng/cards_2_0_0_81.cab
O16 - DPF: {288A7509-9648-418B-393A-100729FE469C} -

http://85.255.115.229/1/gdnUS1388.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -

http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,

0,0,83/mcinsctl.cab
O16 - DPF: {51045741-8C4E-4EAC-8F03-08E43A6FBB29} -

http://c.ancestry.com/cab/aft/AncestryFamilyTree.cab
O16 - DPF: {5B152E7C-33E9-7BE2-D344-34BB4101EF05} -

http://85.255.115.229/1/gdnUS1388.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows

Live Safety Center Base Module) -

http://cdn.scan.onecare.live.com/resource/download/scanner

/wlscbase6087.cab
O16 - DPF: {66BA8BD7-424C-0985-B580-022B6C681F45} -

http://85.255.115.229/1/gdnUS1388.exe
O16 - DPF: {688CBDA7-A68B-5D0C-99E3-5A4004156E31} -

http://85.255.115.229/1/gdnUS1388.exe
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -

http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0

,0,20/mcgdmgr.cab
O17 -

HKLM\System\CCS\Services\Tcpip\..\{EF991938-2C33-4C8E-97BD

-DC2BDBEC386F}: NameServer = 85.255.112.174;85.255.112.109
O18 - Protocol: skype4com -

{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader -

{438755C2-A8BA-11D1-B96B-00A0C90312E1} -

C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache

daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} -

C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) -

Lavasoft - C:\Program Files\Lavasoft\Ad-Aware

2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL

LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor)

- America Online, Inc - C:\Program Files\Common

Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple Inc. -

C:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) -

ALWIL Software - C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software -

C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software -

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software -

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program

Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google -

C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: IS360service - IObit - C:\Program

Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark

International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Pml Driver HPZ12 - HP -

C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2)

(sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program

Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint

Corporation - C:\Program

Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service

(WANMiniportService) - America Online, Inc. -

C:\WINDOWS\wanmpsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo!

Inc. - C:\Program

Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 12203 bytes


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:12:51.31 on Wed 07/14/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.87 [GMT -4:00]

AV: avast! antivirus 4.8.1368 [VPS 100714-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\IObit\IObit Security 360\IS360tray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Maxthon2\Maxthon.exe
C:\PROGRA~1\Maxthon2\Modules\MXDOWN~1\MXDOWN~1.EXE
C:\MxDownload\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.slingo.com/
mStart Page = hxxp://www.msn.com
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
mWinlogon: System=lsass.exe
mWinlogon: Userinit=c:\windows\system32\userinit.exe,userinit.exe
BHO: Yahooo Search Protection: {25bc7718-0bfa-40ea-b381-4b2d9732d686} - c:\program files\yahoo!\search protection\ysp.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~3.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; FunWebProducts; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; yie8; yie8)" -"http://www.gameland.com/games/multiplayer/newmultiuser/ingamechat.asp?sessid=7075633458504A60AA5CA0378532FFE9&tablename=1~@7026A26D-BBB2-4BC3-A622-E735FBA8DF7F&gamename=Christmas%20In%20A%20Box"
mRun: [S3TRAY2] S3tray2.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [IObit Security 360] "c:\program files\iobit\iobit security 360\IS360tray.exe" /autostart
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
dRun: [pbuilder] \pb32.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {6224f700-cba3-4071-b251-47cb894244cd} - c:\program files\icq\ICQ.exe
IE: {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/
IE: {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - {4982D40A-C53B-4615-B15B-B5B5E98D167C}
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll
IE: {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - c:\program files\yahoo!\search protection\ysp.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0E718CF0-047B-6345-87FE-28541D87FEA9} - hxxp://85.255.115.229/1/gdnUS1388.exe
DPF: {1A781DED-4153-C22D-3213-A3211E29DF13} - hxxp://cached.gamedesire.com/g_bin/eng/cards_2_0_0_81.cab
DPF: {288A7509-9648-418B-393A-100729FE469C} - hxxp://85.255.115.229/1/gdnUS1388.exe
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
DPF: {51045741-8C4E-4EAC-8F03-08E43A6FBB29} - hxxp://c.ancestry.com/cab/aft/AncestryFamilyTree.cab
DPF: {5B152E7C-33E9-7BE2-D344-34BB4101EF05} - hxxp://85.255.115.229/1/gdnUS1388.exe
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {66BA8BD7-424C-0985-B580-022B6C681F45} - hxxp://85.255.115.229/1/gdnUS1388.exe
DPF: {688CBDA7-A68B-5D0C-99E3-5A4004156E31} - hxxp://85.255.115.229/1/gdnUS1388.exe
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
TCP: {EF991938-2C33-4C8E-97BD-DC2BDBEC386F} = 85.255.112.174;85.255.112.109
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\mom\applic~1\mozilla\firefox\profiles\la2lruc1.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-20 114768]
R2 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2007-6-5 607576]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-20 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-5-20 138680]
R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2010-7-7 312152]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-20 24652]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-5-20 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-5-20 352920]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [2008-12-2 27904]

=============== Created Last 30 ================

2010-07-07 12:35 –d—– c:\docume~1\alluse~1\applic~1\SpeedyPC
2010-07-07 12:35 –d—– c:\program files\SpeedyPC
2010-07-06 17:25 –d—– C:\MxDownload
2010-07-05 19:23 0 a——- c:\program files\extra1.dat
2010-06-18 00:33 24,576 ac—— c:\windows\system32\dllcache\agcgauge.ax

==================== Find3M ====================

2008-04-13 20:11 1,889,615 ac—— c:\docume~1\mom\applic~1\XQIsbxot.dll
2008-04-13 20:11 1,889,615 ac—— c:\docume~1\mom\applic~1\uosRv.dll
2008-04-13 20:11 1,889,615 ac—— c:\docume~1\mom\applic~1\mBgmPxJ.exe
2008-04-13 20:11 871,407 ac—— c:\docume~1\mom\applic~1\bKiPaJNNx.dll
2008-04-13 20:11 378,607 ac—— c:\docume~1\mom\applic~1\uypoh.dll
2008-04-13 20:11 378,607 ac—— c:\docume~1\mom\applic~1\kuCdpJL.dll
2008-04-13 20:11 229,999 ac—— c:\docume~1\mom\applic~1\QaDRFRlal.exe
2008-04-13 20:11 229,999 ac—— c:\docume~1\mom\applic~1\cjxkt.dll
2006-11-16 12:44 104,607 ac—— c:\docume~1\mom\applic~1\fWyjb.dll
2006-11-16 12:44 104,607 ac—— c:\docume~1\mom\applic~1\EcJmc.dll
2006-11-16 12:44 104,607 ac—— c:\docume~1\mom\applic~1\bDRRp.exe
2006-10-18 21:47 7,791 ac—— c:\docume~1\mom\applic~1\pVXoFT.exe
2006-10-18 21:47 7,791 ac—— c:\docume~1\mom\applic~1\efJjA.dll
2006-10-18 21:47 7,791 ac—— c:\docume~1\mom\applic~1\BfHsgf.exe
2006-08-19 13:51 284 ac—— c:\docume~1\mom\applic~1\ViewerApp.dat
2006-03-30 21:38 774,144 ac—— c:\program files\RngInterstitial.dll
2005-01-14 15:48 1,107,968 ac—— c:\program files\My Money.mny
2004-08-04 08:00 70,207 ac—— c:\docume~1\mom\applic~1\lGxgUIgkT.exe
2004-08-04 08:00 13,935 ac—— c:\docume~1\mom\applic~1\VKJdX.exe
2004-08-04 08:00 13,935 ac—— c:\docume~1\mom\applic~1\ucjGuGW.exe
2004-08-04 08:00 13,935 ac—— c:\docume~1\mom\applic~1\pNcpGtOY.exe
2004-08-04 08:00 13,935 ac—— c:\docume~1\mom\applic~1\OMaVwWkan.exe
2004-08-04 08:00 13,935 ac—— c:\docume~1\mom\applic~1\iyDjmc.dll
2004-08-04 08:00 13,935 ac—— c:\docume~1\mom\applic~1\CtytIR.dll
2002-11-06 16:49 25,268 ac—— c:\docume~1\mom\applic~1\dkyYAEdYs.exe
2002-08-29 08:00 65,135 ac—— c:\docume~1\mom\applic~1\swmjjPNp.dll
1996-08-02 03:51 162,175 ac—— c:\docume~1\mom\applic~1\VaaHHdSWx.dll
1996-08-02 03:51 162,175 ac—— c:\docume~1\mom\applic~1\nHiYLIe.exe
1996-08-02 03:51 162,175 ac—— c:\docume~1\mom\applic~1\GPoob.dll
1996-08-02 03:51 162,175 ac—— c:\docume~1\mom\applic~1\FEXEHxrVd.dll
1996-08-02 03:51 162,175 ac—— c:\docume~1\mom\applic~1\BncgdjAeJ.dll
2008-08-20 12:54 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082020080821\index.dat

============= FINISH: 19:13:50.06 ===============
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Thank you mowman. I am not home between 7am and 4:30pm weekdays on monday, tuesday, thursday and friday. I will check back for your help tonight.
Hello mattsgrandma please do the following

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.
had a problem when rebooted computer yesterday. The windows installer attempted to load microsoft money 2002. It kept trying and trying and would finally say couldnt load. Then it would attempt to try again. I dont use it so I did delete it from the hard drive.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-15 19:04:38
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Mom\LOCALS~1\Temp\pxtdapob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF1C6F6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF1C6F574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF1C6FA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF1C6F14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF1C6F64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF1C6F08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF1C6F0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF1C6F76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF1C6F72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF1C6F8AE]
SSDT \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys ZwUnloadKey [0xF0F026D0]

—- Kernel code sections - GMER 1.0.15 —-

? C:\WINDOWS\system32\Drivers\uphcleanhlp.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Microsoft Works\wkswp.exe[728] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Works\wkswp.exe[728] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Works\wkswp.exe[728] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Works\wkswp.exe[728] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Works\wkswp.exe[728] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AF0001
.text C:\Program Files\Microsoft Works\wkswp.exe[728] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Microsoft Works\wkswp.exe[728] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Microsoft Works\wkswp.exe[728] ADVAPI32.dll!CreateProcessAsUserW 77DEA889 6 Bytes JMP 5F100F5A
.text C:\Program Files\Microsoft Works\wkswp.exe[728] ADVAPI32.dll!CreateProcessWithLogonW 77E15FD5 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Works\wkswp.exe[728] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E15FD9 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Works\wkswp.exe[728] ADVAPI32.dll!CreateServiceA 77E371E9 6 Bytes JMP 5F190F5A
.text C:\Program Files\Microsoft Works\wkswp.exe[728] ADVAPI32.dll!CreateServiceW 77E37381 6 Bytes JMP 5F1C0F5A
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003D0001
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] ADVAPI32.dll!CreateProcessAsUserW 77DEA889 6 Bytes JMP 5F100F5A
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] ADVAPI32.dll!CreateProcessWithLogonW 77E15FD5 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E15FD9 2 Bytes [05, 5F]
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] ADVAPI32.dll!CreateServiceA 77E371E9 6 Bytes JMP 5F190F5A
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[836] ADVAPI32.dll!CreateServiceW 77E37381 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\Explorer.EXE[1444] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02720001
.text C:\WINDOWS\Explorer.EXE[1444] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\Explorer.EXE[1444] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\Explorer.EXE[1444] ADVAPI32.dll!CreateProcessAsUserW 77DEA889 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\Explorer.EXE[1444] ADVAPI32.dll!CreateProcessWithLogonW 77E15FD5 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1444] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E15FD9 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\ctfmon.exe[1516] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[1516] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\WINDOWS\system32\ctfmon.exe[1516] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[1516] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\WINDOWS\system32\ctfmon.exe[1516] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BB0001
.text C:\WINDOWS\system32\ctfmon.exe[1516] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\ctfmon.exe[1516] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[1516] ADVAPI32.dll!CreateProcessAsUserW 77DEA889 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\ctfmon.exe[1516] ADVAPI32.dll!CreateProcessWithLogonW 77E15FD5 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[1516] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E15FD9 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\ctfmon.exe[1516] ADVAPI32.dll!CreateServiceA 77E371E9 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\ctfmon.exe[1516] ADVAPI32.dll!CreateServiceW 77E37381 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 032A1A00 C:\Program Files\Maxthon2\Modules\MxSandBox\MxSec.dll (MxSec/Maxthon International ltd.)
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 02002D9F C:\Program Files\Maxthon2\MxCrashCatch.dll (MxCrashCatch/Maxthon International ltd.)
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01980001
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] kernel32.dll!ExitThread 7C80C0E8 7 Bytes JMP 061B12A0 C:\Program Files\Maxthon2\Modules\MxMute\MxMute.dll (MxMute/Maxthon International ltd.)
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 032A5FE0 C:\Program Files\Maxthon2\Modules\MxSandBox\MxSec.dll (MxSec/Maxthon International ltd.)
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] WININET.dll!HttpOpenRequestA 78064341 5 Bytes JMP 032A18C0 C:\Program Files\Maxthon2\Modules\MxSandBox\MxSec.dll (MxSec/Maxthon International ltd.)
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] WININET.dll!CommitUrlCacheEntryA 7807FC0A 5 Bytes JMP 032A1940 C:\Program Files\Maxthon2\Modules\MxSandBox\MxSec.dll (MxSec/Maxthon International ltd.)
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ADVAPI32.dll!RegCloseKey 77DD6C17 5 Bytes JMP 004E8DFD C:\Program Files\Maxthon2\Maxthon.exe (Maxthon Browser/Maxthon International ltd.)
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 004E8E36 C:\Program Files\Maxthon2\Maxthon.exe (Maxthon Browser/Maxthon International ltd.)
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ADVAPI32.dll!CreateProcessAsUserW 77DEA889 6 Bytes JMP 5F100F5A
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ADVAPI32.dll!RegEnumValueA 77DF9B8F 5 Bytes JMP 004E8F0E C:\Program Files\Maxthon2\Maxthon.exe (Maxthon Browser/Maxthon International ltd.)
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ADVAPI32.dll!CreateProcessWithLogonW 77E15FD5 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E15FD9 2 Bytes [05, 5F]
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ADVAPI32.dll!CreateServiceA 77E371E9 6 Bytes JMP 5F190F5A
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] ADVAPI32.dll!CreateServiceW 77E37381 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Maxthon2\Maxthon.exe[3216] USER32.dll!MessageBoxA 7E45058A 5 Bytes JMP 032A4D40 C:\Program Files\Maxthon2\Modules\MxSandBox\MxSec.dll (MxSec/Maxthon International ltd.)
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AF0001
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] ADVAPI32.dll!CreateProcessAsUserW 77DEA889 6 Bytes JMP 5F100F5A
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] ADVAPI32.dll!CreateProcessWithLogonW 77E15FD5 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E15FD9 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] ADVAPI32.dll!CreateServiceA 77E371E9 6 Bytes JMP 5F190F5A
.text C:\Program Files\Microsoft Works\WksWP.exe[3280] ADVAPI32.dll!CreateServiceW 77E37381 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Microsoft Works\wksss.exe[3328] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Works\wksss.exe[3328] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Works\wksss.exe[3328] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Works\wksss.exe[3328] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Works\wksss.exe[3328] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00DF0001
.text C:\Program Files\Microsoft Works\wksss.exe[3328] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Microsoft Works\wksss.exe[3328] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Microsoft Works\wksss.exe[3328] ADVAPI32.dll!CreateProcessAsUserW 77DEA889 6 Bytes JMP 5F100F5A
.text C:\Program Files\Microsoft Works\wksss.exe[3328] ADVAPI32.dll!CreateProcessWithLogonW 77E15FD5 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Works\wksss.exe[3328] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E15FD9 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Works\wksss.exe[3328] ADVAPI32.dll!CreateServiceA 77E371E9 6 Bytes JMP 5F190F5A
.text C:\Program Files\Microsoft Works\wksss.exe[3328] ADVAPI32.dll!CreateServiceW 77E37381 6 Bytes JMP 5F1C0F5A
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [FF, 25, 1E]
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [FF, 25, 1E]
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] ADVAPI32.dll!CreateProcessAsUserW 77DEA889 6 Bytes JMP 5F100F5A
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] ADVAPI32.dll!CreateProcessWithLogonW 77E15FD5 3 Bytes [FF, 25, 1E]
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E15FD9 2 Bytes [05, 5F]
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] ADVAPI32.dll!CreateServiceA 77E371E9 6 Bytes JMP 5F190F5A
.text C:\DOCUME~1\Mom\LOCALS~1\Temp\Temporary Directory 2 for gmer.zip\gmer.exe[20508] ADVAPI32.dll!CreateServiceW 77E37381 6 Bytes JMP 5F1C0F5A

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (SISIDEX Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 60: copy of MBR

—- EOF - GMER 1.0.15 —-

Attachments:

Hello mattsgrandma please do the following

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Wow computer running great all ready mowman. Thanks for all your help so far.


ComboFix 10-07-15.05 - Mom 07/16/2010 18:26:52.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.126 [GMT -4:00]
Running from: c:\mxdownload\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100716-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Mom\Application Data\bDRRp.exe
c:\documents and settings\Mom\Application Data\BfHsgf.exe
c:\documents and settings\Mom\Application Data\bKiPaJNNx.dll
c:\documents and settings\Mom\Application Data\BncgdjAeJ.dll
c:\documents and settings\Mom\Application Data\cjxkt.dll
c:\documents and settings\Mom\Application Data\CtytIR.dll
c:\documents and settings\Mom\Application Data\EcJmc.dll
c:\documents and settings\Mom\Application Data\efJjA.dll
c:\documents and settings\Mom\Application Data\FEXEHxrVd.dll
c:\documents and settings\Mom\Application Data\fWyjb.dll
c:\documents and settings\Mom\Application Data\GPoob.dll
c:\documents and settings\Mom\Application Data\iyDjmc.dll
c:\documents and settings\Mom\Application Data\kuCdpJL.dll
c:\documents and settings\Mom\Application Data\mBgmPxJ.exe
c:\documents and settings\Mom\Application Data\nHiYLIe.exe
c:\documents and settings\Mom\Application Data\OMaVwWkan.exe
c:\documents and settings\Mom\Application Data\pNcpGtOY.exe
c:\documents and settings\Mom\Application Data\pVXoFT.exe
c:\documents and settings\Mom\Application Data\QaDRFRlal.exe
c:\documents and settings\Mom\Application Data\swmjjPNp.dll
c:\documents and settings\Mom\Application Data\ucjGuGW.exe
c:\documents and settings\Mom\Application Data\uosRv.dll
c:\documents and settings\Mom\Application Data\uypoh.dll
c:\documents and settings\Mom\Application Data\VaaHHdSWx.dll
c:\documents and settings\Mom\Application Data\VKJdX.exe
c:\documents and settings\Mom\Application Data\XQIsbxot.dll
c:\program files\Freeze.com Toolbar
c:\program files\Internet Explorer\msimg32.dll
C:\resycled
c:\windows\AKCRSnd.exe
c:\windows\Brkwfr.dll
c:\windows\DENKk.dll
c:\windows\dNajmxa.dll
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.inf
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.0.inf
c:\windows\dSTKe.exe
c:\windows\dYkpu.exe
c:\windows\ePUioK.dll
c:\windows\eUnkYAN.exe
c:\windows\gfyplkM.exe
c:\windows\GgRMrOLut.dll
c:\windows\GkfUOvy.exe
c:\windows\JnPygE.exe
c:\windows\kqOcc.dll
c:\windows\kYFKxfGMJ.dll
c:\windows\LGlhVCVJ.exe
c:\windows\mqUedQwJp.dll
c:\windows\nMdcX.exe
c:\windows\PGndruby.dll
c:\windows\QPkIUax.dll
c:\windows\RXNqhtHu.exe
c:\windows\svEIvnxAr.dll
c:\windows\system32\_005146_.tmp.dll
c:\windows\system32\_005147_.tmp.dll
c:\windows\system32\_005148_.tmp.dll
c:\windows\system32\_005149_.tmp.dll
c:\windows\system32\_005156_.tmp.dll
c:\windows\system32\_005157_.tmp.dll
c:\windows\system32\_005158_.tmp.dll
c:\windows\system32\_005159_.tmp.dll
c:\windows\system32\_005161_.tmp.dll
c:\windows\system32\_005162_.tmp.dll
c:\windows\system32\_005165_.tmp.dll
c:\windows\system32\_005166_.tmp.dll
c:\windows\system32\_005168_.tmp.dll
c:\windows\system32\_005169_.tmp.dll
c:\windows\system32\_005170_.tmp.dll
c:\windows\system32\_005172_.tmp.dll
c:\windows\system32\_005175_.tmp.dll
c:\windows\system32\_005176_.tmp.dll
c:\windows\system32\_005180_.tmp.dll
c:\windows\system32\_005181_.tmp.dll
c:\windows\system32\_005183_.tmp.dll
c:\windows\system32\_005186_.tmp.dll
c:\windows\system32\_005188_.tmp.dll
c:\windows\system32\_005189_.tmp.dll
c:\windows\system32\_005190_.tmp.dll
c:\windows\system32\_005191_.tmp.dll
c:\windows\system32\_005192_.tmp.dll
c:\windows\system32\_005195_.tmp.dll
c:\windows\system32\_005196_.tmp.dll
c:\windows\system32\_005197_.tmp.dll
c:\windows\system32\_005198_.tmp.dll
c:\windows\system32\_005199_.tmp.dll
c:\windows\system32\_005204_.tmp.dll
c:\windows\system32\_005206_.tmp.dll
c:\windows\system32\_005207_.tmp.dll
c:\windows\system32\aNcBICdy.exe
c:\windows\system32\cCFeuUeB.dll
c:\windows\system32\dfVmKGpk.dll
c:\windows\system32\drivers\cKnMoYIOo.exe
c:\windows\system32\drivers\dshDX.exe
c:\windows\system32\drivers\EbOvFImFu.exe
c:\windows\system32\drivers\eKSTkwvvo.exe
c:\windows\system32\drivers\EUaAOEsHj.exe
c:\windows\system32\drivers\HcYRc.dll
c:\windows\system32\drivers\hgVFgX.dll
c:\windows\system32\drivers\HjTxW.dll
c:\windows\system32\drivers\kiDYO.exe
c:\windows\system32\drivers\loUCCt.exe
c:\windows\system32\drivers\NbinrjNhi.exe
c:\windows\system32\drivers\oBejeAmnL.exe
c:\windows\system32\drivers\pISmdLQvv.exe
c:\windows\system32\drivers\QoHlyiLEu.exe
c:\windows\system32\drivers\SfwPc.dll
c:\windows\system32\drivers\sKehlNIsJ.exe
c:\windows\system32\drivers\TEBIQJxno.exe
c:\windows\system32\drivers\THnFBJ.dll
c:\windows\system32\drivers\xwxgvYMJ.exe
c:\windows\system32\drivers\YdHbj.dll
c:\windows\system32\drivers\yqbOgOgLL.dll
c:\windows\system32\drivers\YRAvTIFga.exe
c:\windows\system32\elYrhaG.dll
c:\windows\system32\eYMJjAIA.dll
c:\windows\system32\FaanTcw.dll
c:\windows\system32\FhiEtG.exe
c:\windows\system32\hELAEokJ.exe
c:\windows\system32\hQfDfbp.dll
c:\windows\system32\jHJglL.exe
c:\windows\system32\lyGifO.dll
c:\windows\system32\mHgEcc.dll
c:\windows\system32\MqvLkba.exe
c:\windows\system32\nxiMkP.exe
c:\windows\system32\oBClFu.dll
c:\windows\system32\qVurMiMR.exe
c:\windows\system32\tkEdhyj.dll
c:\windows\system32\vGohDwrBT.dll
c:\windows\system32\VkTYf.exe
c:\windows\system32\xCnfexQJX.dll
c:\windows\system32\XPaUN.dll
c:\windows\system32\yjamXAy.dll
c:\windows\VOjHm.dll
c:\windows\WLqkoOJt.dll
c:\windows\wwDCpCQb.dll
c:\windows\xDFbul.dll
c:\windows\XviJBbrk.exe
c:\windows\YhTfXAY.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ADBUPD
——-\Legacy_MYWEBSEARCHSERVICE


((((((((((((((((((((((((( Files Created from 2010-06-16 to 2010-07-16 )))))))))))))))))))))))))))))))
.

2010-07-07 17:22 . 2010-07-07 17:24 ——– d—–w- c:\program files\Windows Live Safety Center
2010-07-07 16:35 . 2010-07-08 11:54 ——– d—–w- c:\documents and settings\All Users\Application Data\SpeedyPC
2010-07-07 16:35 . 2010-07-07 16:42 ——– d—–w- c:\program files\SpeedyPC
2010-07-06 21:25 . 2010-07-16 22:09 ——– d—–w- C:\MxDownload
2010-07-05 23:23 . 2010-07-05 23:23 0 —-a-w- c:\program files\extra1.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-16 22:43 . 2007-09-13 22:52 ——– d—–w- c:\documents and settings\Mom\Application Data\MxBoost
2010-07-15 01:20 . 2008-08-06 18:27 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-14 19:51 . 2007-09-13 22:51 ——– d—–w- c:\program files\Maxthon2
2010-07-12 21:48 . 2007-07-10 13:04 ——– d—–w- c:\program files\HP
2010-07-06 21:21 . 2007-10-12 22:58 ——– d—–w- c:\program files\Glary Utilities
2010-06-27 23:09 . 2005-08-23 20:56 ——– d—–w- c:\program files\PCStitch 6
2010-06-18 04:26 . 2007-12-17 15:30 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-28 04:26 . 2009-06-22 20:04 ——– d—–w- c:\program files\CCleaner
2010-04-30 20:29 . 2010-04-30 20:29 862872 ——w- c:\documents and settings\Mom\Application Data\yahoo!\SearchProtection\fudogs_2.0.1.13_msgr_bts_setup.2010.04.01.01.exe
2006-03-31 01:38 . 2006-03-31 01:39 774144 -c–a-w- c:\program files\RngInterstitial.dll
2005-01-14 19:48 . 2005-01-14 19:47 1107968 -c–a-w- c:\program files\My Money.mny
.

——- Sigcheck ——-

[7] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\$NtServicePackUninstall$\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\system32\netman.dll
[-] 2005-08-22 . 3516D8A18B36784B1005B950B84232E1 . 197632 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
[7] 2004-08-04 . DAB9E6C7105D2EF49876FE92C524F565 . 198144 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB905414$\netman.dll

[7] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\system32\rpcss.dll
[-] 2005-07-26 . C369DF215D352B6F3A0B8C3469AA34F8 . 398336 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll
[-] 2005-04-28 . DA383FB39A6F1C445F3AFC94B3EB1248 . 396288 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
[-] 2005-04-28 . C8061F289E000703E7672916B7FE1571 . 395776 . . [5.1.2600.2665] . . c:\windows\$NtUninstallKB902400$\rpcss.dll
[-] 2005-01-14 . 94456045BEB4545B5EBE1DCC85951AFA . 395776 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2QFE\rpcss.dll
[7] 2004-08-04 . 5C83A4408604F737717AB96371201680 . 395776 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB894391$\rpcss.dll
[-] 2003-08-25 . 7A6F20EEAC4B2168451878AF9054396F . 260608 . . [5.1.2600.1263] . . c:\windows\$NtUninstallKB828741$\rpcss.dll
[-] 2002-08-29 . 493FCBED180DCACF0B5D4C8C29949CA9 . 260608 . . [5.1.2600.1106] . . c:\windows\$NtUninstallKB826939$\rpcss.dll

[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe
[7] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896423$\spoolsv.exe

[7] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
[7] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll
[7] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[7] 2008-07-07 20:06 . A4AB3DCA4A383F0DF4988ABDEB84F9A4 . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
[7] 2008-04-14 00:11 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtServicePackUninstall$\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtUninstallKB950974$\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtUninstallKB950974_0$\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\system32\es.dll
[-] 2005-07-26 04:20 . 95F5FEA4C6DE2C3F28784D0DCC8F0DD3 . 243200 . . [2001.12.4414.308] . . c:\windows\$hf_mig$\KB902400\SP2QFE\es.dll
[7] 2004-08-04 12:00 . ACD36A2DD7D1E9D8A060AA651DC07E63 . 243200 . . [2001.12.4414.258] . . c:\windows\$NtUninstallKB902400$\es.dll
[-] 2002-08-29 12:00 . C9702DDD814C39DC1254CF757C31C6E4 . 225280 . . [2001.12.4414.46] . . c:\windows\$NtUninstallKB828741$\es.dll

[7] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
[-] 2005-09-01 . 648BF0B4DDE4F7A1156DAE7174D36EFA . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\system32\linkinfo.dll
[7] 2004-08-04 . C2BBD044C741EA4292016C36F718D2E4 . 18944 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB900725$\linkinfo.dll
[-] 2002-08-29 . 7D8C58C0CBB7331E9296A7357827CA8E . 15360 . . [5.1.2600.0] . . c:\windows\$NtUninstallKB841356$\linkinfo.dll

[7] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[-] 2005-07-08 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\system32\tapisrv.dll
[7] 2004-08-04 . EB4A4187D74A8EFDCBEA3EA2CB1BDFBD . 246272 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB893756$\tapisrv.dll

[7] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2007-03-08 . 7AA4F6C00405DFC4B70ED4214E7D687B . 578048 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\system32\user32.dll
[-] 2005-03-02 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2005-03-02 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\$NtUninstallKB925902$\user32.dll
[7] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB890859$\user32.dll
[-] 2002-11-01 . 68E1F4EF02DF52CA9C5E157045D23582 . 528896 . . [5.1.2600.1134] . . c:\windows\$NtUninstallKB891711$\user32.dll
[-] 2002-08-29 . DD9269230C21EE8FB7FD3FCCC3B1CFCB . 560128 . . [5.1.2600.1106] . . c:\windows\$NtUninstallKB826939$\user32.dll

[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe

[7] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\system32\shsvcs.dll
[-] 2006-12-19 . 53D9184A21C5CBF600D918E51EF3A7E5 . 135168 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll
[7] 2004-08-04 . E7518DC542D3EBDCB80EDD98462C7821 . 134656 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB928255$\shsvcs.dll
[-] 2002-08-29 . 61684089A54936E40F65DA02D47A28AE . 116224 . . [6.00.2800.1106] . . c:\windows\$NtUninstallKB885835_0$\shsvcs.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-07-02 2347216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3tray2.exe" [2003-02-25 69632]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^Mom^Start Menu^Programs^Startup^CNET TechTracker.lnk]
backup=c:\windows\pss\CNET TechTracker.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-09 16:09 63712 -c–a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"HostManager"=c:\program files\Common Files\AOL\1105230214\ee\AOLSoftware.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\aim6.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Maxthon\\Maxthon.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Maxthon2\\Maxthon.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Maxthon2\\Modules\\MxDownloader\\MxDownloadServer.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/20/2009 6:02 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/20/2009 6:02 PM 20560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/20/2007 10:57 PM 24652]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [7/7/2010 11:45 AM 312152]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [12/2/2008 4:25 PM 27904]

— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2008-04-23 04:16 124928 -c—-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]

2010-07-16 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-12-31 17:03]

2010-07-16 c:\windows\Tasks\SpeedyPC Program Check.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]

2010-07-15 c:\windows\Tasks\SpeedyPC.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.slingo.com/
mStart Page = hxxp://www.msn.com
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Settings,ProxyOverride = *.local
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {0E718CF0-047B-6345-87FE-28541D87FEA9} - hxxp://85.255.115.229/1/gdnUS1388.exe
DPF: {1A781DED-4153-C22D-3213-A3211E29DF13} - hxxp://cached.gamedesire.com/g_bin/eng/cards_2_0_0_81.cab
DPF: {288A7509-9648-418B-393A-100729FE469C} - hxxp://85.255.115.229/1/gdnUS1388.exe
DPF: {5B152E7C-33E9-7BE2-D344-34BB4101EF05} - hxxp://85.255.115.229/1/gdnUS1388.exe
DPF: {66BA8BD7-424C-0985-B580-022B6C681F45} - hxxp://85.255.115.229/1/gdnUS1388.exe
DPF: {688CBDA7-A68B-5D0C-99E3-5A4004156E31} - hxxp://85.255.115.229/1/gdnUS1388.exe
FF - ProfilePath - c:\documents and settings\Mom\Application Data\Mozilla\Firefox\Profiles\la2lruc1.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-pbuilder - \pb32.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-16 18:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-4198444561-2043493450-2835451435-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2680)
c:\program files\AOL Deskbar\deskbar.dll
c:\program files\Common Files\AOL\AOL Toolbar\smartbox.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\aolshare\aolshcpy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\HPZipm12.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\wanmpsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2010-07-16 19:02:32 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-16 23:02

Pre-Run: 56,858,935,296 bytes free
Post-Run: 56,773,128,192 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /noexecute=optin

- - End Of File - - AB58BA3189346351C1DAACCD68B902CA

Attachments:

Hello mattsgrandma please do the following

Delete the copy of Combofix you have and download a fresh one from one of the links below.Make sure you save it to your desktop

Link 1
Link 2


COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/index.php?showtopic=113203
    
    Collect:: 
    c:\program files\extra1.dat
    
    DDS::
    DPF: {0E718CF0-047B-6345-87FE-28541D87FEA9} - hxxp://85.255.115.229/1/gdnUS1388.exe
    DPF: {288A7509-9648-418B-393A-100729FE469C} - hxxp://85.255.115.229/1/gdnUS1388.exe
    DPF: {5B152E7C-33E9-7BE2-D344-34BB4101EF05} - hxxp://85.255.115.229/1/gdnUS1388.exe
    DPF: {66BA8BD7-424C-0985-B580-022B6C681F45} - hxxp://85.255.115.229/1/gdnUS1388.exe
    DPF: {688CBDA7-A68B-5D0C-99E3-5A4004156E31} - hxxp://85.255.115.229/1/gdnUS1388.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please
ComboFix 10-07-16.01 - Mom 07/17/2010 19:52:10.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.153 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\COMBOFIX2.EXE
Command switches used :: c:\documents and settings\Mom\Desktop\CFSCRIPT.TXT
AV: avast! antivirus 4.8.1368 [VPS 100717-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

file zipped: c:\program files\extra1.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\extra1.dat

.
((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
.

2010-07-17 03:23 . 2010-07-17 03:24 ——– d—–w- c:\windows\LastGood
2010-07-07 17:22 . 2010-07-07 17:24 ——– d—–w- c:\program files\Windows Live Safety Center
2010-07-07 16:35 . 2010-07-08 11:54 ——– d—–w- c:\documents and settings\All Users\Application Data\SpeedyPC
2010-07-07 16:35 . 2010-07-07 16:42 ——– d—–w- c:\program files\SpeedyPC
2010-07-06 21:25 . 2010-07-16 22:09 ——– d—–w- C:\MxDownload

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-16 23:03 . 2007-09-13 22:52 ——– d—–w- c:\documents and settings\Mom\Application Data\MxBoost
2010-07-15 01:20 . 2008-08-06 18:27 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-14 19:51 . 2007-09-13 22:51 ——– d—–w- c:\program files\Maxthon2
2010-07-12 21:48 . 2007-07-10 13:04 ——– d—–w- c:\program files\HP
2010-07-06 21:21 . 2007-10-12 22:58 ——– d—–w- c:\program files\Glary Utilities
2010-06-27 23:09 . 2005-08-23 20:56 ——– d—–w- c:\program files\PCStitch 6
2010-06-18 04:26 . 2007-12-17 15:30 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-28 04:26 . 2009-06-22 20:04 ——– d—–w- c:\program files\CCleaner
2006-03-31 01:38 . 2006-03-31 01:39 774144 -c–a-w- c:\program files\RngInterstitial.dll
2005-01-14 19:48 . 2005-01-14 19:47 1107968 -c–a-w- c:\program files\My Money.mny
.

——- Sigcheck ——-

[7] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\$NtServicePackUninstall$\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\system32\netman.dll
[-] 2005-08-22 . 3516D8A18B36784B1005B950B84232E1 . 197632 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
[7] 2004-08-04 . DAB9E6C7105D2EF49876FE92C524F565 . 198144 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB905414$\netman.dll

[7] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\system32\rpcss.dll
[-] 2005-07-26 . C369DF215D352B6F3A0B8C3469AA34F8 . 398336 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll
[-] 2005-04-28 . DA383FB39A6F1C445F3AFC94B3EB1248 . 396288 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
[-] 2005-04-28 . C8061F289E000703E7672916B7FE1571 . 395776 . . [5.1.2600.2665] . . c:\windows\$NtUninstallKB902400$\rpcss.dll
[-] 2005-01-14 . 94456045BEB4545B5EBE1DCC85951AFA . 395776 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2QFE\rpcss.dll
[7] 2004-08-04 . 5C83A4408604F737717AB96371201680 . 395776 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB894391$\rpcss.dll
[-] 2003-08-25 . 7A6F20EEAC4B2168451878AF9054396F . 260608 . . [5.1.2600.1263] . . c:\windows\$NtUninstallKB828741$\rpcss.dll
[-] 2002-08-29 . 493FCBED180DCACF0B5D4C8C29949CA9 . 260608 . . [5.1.2600.1106] . . c:\windows\$NtUninstallKB826939$\rpcss.dll

[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe
[7] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896423$\spoolsv.exe

[7] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
[7] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll
[7] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[7] 2008-07-07 20:06 . A4AB3DCA4A383F0DF4988ABDEB84F9A4 . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
[7] 2008-04-14 00:11 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtServicePackUninstall$\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtUninstallKB950974$\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtUninstallKB950974_0$\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\system32\es.dll
[-] 2005-07-26 04:20 . 95F5FEA4C6DE2C3F28784D0DCC8F0DD3 . 243200 . . [2001.12.4414.308] . . c:\windows\$hf_mig$\KB902400\SP2QFE\es.dll
[7] 2004-08-04 12:00 . ACD36A2DD7D1E9D8A060AA651DC07E63 . 243200 . . [2001.12.4414.258] . . c:\windows\$NtUninstallKB902400$\es.dll
[-] 2002-08-29 12:00 . C9702DDD814C39DC1254CF757C31C6E4 . 225280 . . [2001.12.4414.46] . . c:\windows\$NtUninstallKB828741$\es.dll

[7] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
[-] 2005-09-01 . 648BF0B4DDE4F7A1156DAE7174D36EFA . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\system32\linkinfo.dll
[7] 2004-08-04 . C2BBD044C741EA4292016C36F718D2E4 . 18944 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB900725$\linkinfo.dll
[-] 2002-08-29 . 7D8C58C0CBB7331E9296A7357827CA8E . 15360 . . [5.1.2600.0] . . c:\windows\$NtUninstallKB841356$\linkinfo.dll

[7] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[-] 2005-07-08 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\system32\tapisrv.dll
[7] 2004-08-04 . EB4A4187D74A8EFDCBEA3EA2CB1BDFBD . 246272 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB893756$\tapisrv.dll

[7] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2007-03-08 . 7AA4F6C00405DFC4B70ED4214E7D687B . 578048 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\system32\user32.dll
[-] 2005-03-02 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2005-03-02 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\$NtUninstallKB925902$\user32.dll
[7] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB890859$\user32.dll
[-] 2002-11-01 . 68E1F4EF02DF52CA9C5E157045D23582 . 528896 . . [5.1.2600.1134] . . c:\windows\$NtUninstallKB891711$\user32.dll
[-] 2002-08-29 . DD9269230C21EE8FB7FD3FCCC3B1CFCB . 560128 . . [5.1.2600.1106] . . c:\windows\$NtUninstallKB826939$\user32.dll

[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe

[7] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\system32\shsvcs.dll
[-] 2006-12-19 . 53D9184A21C5CBF600D918E51EF3A7E5 . 135168 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll
[7] 2004-08-04 . E7518DC542D3EBDCB80EDD98462C7821 . 134656 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB928255$\shsvcs.dll
[-] 2002-08-29 . 61684089A54936E40F65DA02D47A28AE . 116224 . . [6.00.2800.1106] . . c:\windows\$NtUninstallKB885835_0$\shsvcs.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-07-02 2347216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3tray2.exe" [2003-02-25 69632]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^Mom^Start Menu^Programs^Startup^CNET TechTracker.lnk]
backup=c:\windows\pss\CNET TechTracker.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-09 16:09 63712 -c–a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"HostManager"=c:\program files\Common Files\AOL\1105230214\ee\AOLSoftware.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\aim6.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Maxthon\\Maxthon.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Maxthon2\\Maxthon.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Maxthon2\\Modules\\MxDownloader\\MxDownloadServer.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/20/2009 6:02 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/20/2009 6:02 PM 20560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/20/2007 10:57 PM 24652]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [7/7/2010 11:45 AM 312152]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [12/2/2008 4:25 PM 27904]

— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2008-04-23 04:16 124928 -c—-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]

2010-07-16 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-12-31 17:03]

2010-07-17 c:\windows\Tasks\SpeedyPC Program Check.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]

2010-07-15 c:\windows\Tasks\SpeedyPC.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.slingo.com/
mStart Page = hxxp://www.msn.com
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Settings,ProxyOverride = *.local
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1A781DED-4153-C22D-3213-A3211E29DF13} - hxxp://cached.gamedesire.com/g_bin/eng/cards_2_0_0_81.cab
FF - ProfilePath - c:\documents and settings\Mom\Application Data\Mozilla\Firefox\Profiles\la2lruc1.default\
FF - prefs.js: browser.search.selectedEngine - Ask

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-17 20:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-4198444561-2043493450-2835451435-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2010-07-17 20:15:46
ComboFix-quarantined-files.txt 2010-07-18 00:15
ComboFix2.txt 2010-07-16 23:02

Pre-Run: 56,406,704,128 bytes free
Post-Run: 56,467,214,336 bytes free

- - End Of File - - 6F9E533E070E58AE9B52B969CE196D2B
Upload was successful



Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4322

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

7/17/2010 8:51:22 PM
mbam-log-2010-07-17 (20-51-22).txt

Scan type: Quick scan
Objects scanned: 167080
Time elapsed: 14 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)
Hello mattsgrandma please do the following

Please post the full Malwarebytes log as half of the one you posted is missing
Malwarebytes' Anti-Malware

  • Open Malwarebytes' Anti-Malware
  • Select the Logs tab
  • Click on the latest log. The bottom most log is the latest
  • Click Open
  • Notepad will open. Please post this log in your next reply.



COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    FCopy::
    c:\windows\ServicePackFiles\i386\netman.dll | c:\windows\system32\netman.dll
    c:\windows\ServicePackFiles\i386\rpcss.dll | c:\windows\system32\rpcss.dll
    c:\windows\ServicePackFiles\i386\spoolsv.exe | c:\windows\system32\spoolsv.exe
    c:\windows\ServicePackFiles\i386\es.dll | c:\windows\system32\es.dll
    c:\windows\ServicePackFiles\i386\linkinfo.dll | c:\windows\system32\linkinfo.dll
    c:\windows\ServicePackFiles\i386\tapisrv.dll | c:\windows\system32\tapisrv.dll
    c:\windows\ServicePackFiles\i386\user32.dll | c:\windows\system32\user32.dll
    c:\windows\ServicePackFiles\i386\explorer.exe | c:\windows\explorer.exe
    c:\windows\ServicePackFiles\i386\shsvcs.dll | c:\windows\system32\shsvcs.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.

Also please tell me how the computer is running now.Thanks
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4322

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

7/17/2010 8:51:22 PM
mbam-log-2010-07-17 (20-51-22).txt

Scan type: Quick scan
Objects scanned: 167080
Time elapsed: 14 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\{NSINAME} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


ComboFix 10-07-16.02 - Mom 07/18/2010 14:24:00.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.125 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\COMBOFIX2.EXE
Command switches used :: c:\documents and settings\Mom\Desktop\cfscript.txt
AV: avast! antivirus 4.8.1368 [VPS 100718-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
.

2010-07-18 00:35 . 2010-07-18 00:35 ——– d—–w- c:\documents and settings\Mom\Application Data\Malwarebytes
2010-07-18 00:35 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-18 00:35 . 2010-07-18 00:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-18 00:35 . 2010-07-18 00:35 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-18 00:35 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-17 03:23 . 2010-07-17 03:24 ——– d—–w- c:\windows\LastGood
2010-07-07 17:22 . 2010-07-07 17:24 ——– d—–w- c:\program files\Windows Live Safety Center
2010-07-07 16:35 . 2010-07-08 11:54 ——– d—–w- c:\documents and settings\All Users\Application Data\SpeedyPC
2010-07-07 16:35 . 2010-07-07 16:42 ——– d—–w- c:\program files\SpeedyPC
2010-07-06 21:25 . 2010-07-18 00:34 ——– d—–w- C:\MxDownload

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-18 17:50 . 2007-09-13 22:52 ——– d—–w- c:\documents and settings\Mom\Application Data\MxBoost
2010-07-15 01:20 . 2008-08-06 18:27 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-14 19:51 . 2007-09-13 22:51 ——– d—–w- c:\program files\Maxthon2
2010-07-12 21:48 . 2007-07-10 13:04 ——– d—–w- c:\program files\HP
2010-07-06 21:21 . 2007-10-12 22:58 ——– d—–w- c:\program files\Glary Utilities
2010-06-27 23:09 . 2005-08-23 20:56 ——– d—–w- c:\program files\PCStitch 6
2010-06-18 04:26 . 2007-12-17 15:30 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-28 04:26 . 2009-06-22 20:04 ——– d—–w- c:\program files\CCleaner
2006-03-31 01:38 . 2006-03-31 01:39 774144 -c–a-w- c:\program files\RngInterstitial.dll
2005-01-14 19:48 . 2005-01-14 19:47 1107968 -c–a-w- c:\program files\My Money.mny
.

——- Sigcheck ——-

[7] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\$NtServicePackUninstall$\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\system32\netman.dll
[-] 2005-08-22 . 3516D8A18B36784B1005B950B84232E1 . 197632 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
[7] 2004-08-04 . DAB9E6C7105D2EF49876FE92C524F565 . 198144 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB905414$\netman.dll

[7] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\system32\rpcss.dll
[-] 2005-07-26 . C369DF215D352B6F3A0B8C3469AA34F8 . 398336 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll
[-] 2005-04-28 . DA383FB39A6F1C445F3AFC94B3EB1248 . 396288 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
[-] 2005-04-28 . C8061F289E000703E7672916B7FE1571 . 395776 . . [5.1.2600.2665] . . c:\windows\$NtUninstallKB902400$\rpcss.dll
[-] 2005-01-14 . 94456045BEB4545B5EBE1DCC85951AFA . 395776 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2QFE\rpcss.dll
[7] 2004-08-04 . 5C83A4408604F737717AB96371201680 . 395776 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB894391$\rpcss.dll
[-] 2003-08-25 . 7A6F20EEAC4B2168451878AF9054396F . 260608 . . [5.1.2600.1263] . . c:\windows\$NtUninstallKB828741$\rpcss.dll
[-] 2002-08-29 . 493FCBED180DCACF0B5D4C8C29949CA9 . 260608 . . [5.1.2600.1106] . . c:\windows\$NtUninstallKB826939$\rpcss.dll

[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe
[7] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896423$\spoolsv.exe

[7] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
[7] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll
[7] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[7] 2008-07-07 20:06 . A4AB3DCA4A383F0DF4988ABDEB84F9A4 . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
[7] 2008-04-14 00:11 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtServicePackUninstall$\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtUninstallKB950974$\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtUninstallKB950974_0$\es.dll
[-] 2005-07-26 04:39 . 34BBD9ACC1538818F2C878898C64E793 . 243200 . . [2001.12.4414.308] . . c:\windows\system32\es.dll
[-] 2005-07-26 04:20 . 95F5FEA4C6DE2C3F28784D0DCC8F0DD3 . 243200 . . [2001.12.4414.308] . . c:\windows\$hf_mig$\KB902400\SP2QFE\es.dll
[7] 2004-08-04 12:00 . ACD36A2DD7D1E9D8A060AA651DC07E63 . 243200 . . [2001.12.4414.258] . . c:\windows\$NtUninstallKB902400$\es.dll
[-] 2002-08-29 12:00 . C9702DDD814C39DC1254CF757C31C6E4 . 225280 . . [2001.12.4414.46] . . c:\windows\$NtUninstallKB828741$\es.dll

[7] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
[-] 2005-09-01 . 648BF0B4DDE4F7A1156DAE7174D36EFA . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\system32\linkinfo.dll
[7] 2004-08-04 . C2BBD044C741EA4292016C36F718D2E4 . 18944 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB900725$\linkinfo.dll
[-] 2002-08-29 . 7D8C58C0CBB7331E9296A7357827CA8E . 15360 . . [5.1.2600.0] . . c:\windows\$NtUninstallKB841356$\linkinfo.dll

[7] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[-] 2005-07-08 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\system32\tapisrv.dll
[7] 2004-08-04 . EB4A4187D74A8EFDCBEA3EA2CB1BDFBD . 246272 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB893756$\tapisrv.dll

[7] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2007-03-08 . 7AA4F6C00405DFC4B70ED4214E7D687B . 578048 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\system32\user32.dll
[-] 2005-03-02 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2005-03-02 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\$NtUninstallKB925902$\user32.dll
[7] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB890859$\user32.dll
[-] 2002-11-01 . 68E1F4EF02DF52CA9C5E157045D23582 . 528896 . . [5.1.2600.1134] . . c:\windows\$NtUninstallKB891711$\user32.dll
[-] 2002-08-29 . DD9269230C21EE8FB7FD3FCCC3B1CFCB . 560128 . . [5.1.2600.1106] . . c:\windows\$NtUninstallKB826939$\user32.dll

[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe

[7] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\system32\shsvcs.dll
[-] 2006-12-19 . 53D9184A21C5CBF600D918E51EF3A7E5 . 135168 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll
[7] 2004-08-04 . E7518DC542D3EBDCB80EDD98462C7821 . 134656 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB928255$\shsvcs.dll
[-] 2002-08-29 . 61684089A54936E40F65DA02D47A28AE . 116224 . . [6.00.2800.1106] . . c:\windows\$NtUninstallKB885835_0$\shsvcs.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-07-18_00.06.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-18 01:01 . 2010-07-18 01:01 16384 c:\windows\temp\Perflib_Perfdata_59d4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-07-02 2347216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3tray2.exe" [2003-02-25 69632]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^Mom^Start Menu^Programs^Startup^CNET TechTracker.lnk]
backup=c:\windows\pss\CNET TechTracker.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-09 16:09 63712 -c–a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"HostManager"=c:\program files\Common Files\AOL\1105230214\ee\AOLSoftware.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\aim6.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Maxthon\\Maxthon.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Maxthon2\\Maxthon.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Maxthon2\\Modules\\MxDownloader\\MxDownloadServer.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/20/2009 6:02 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/20/2009 6:02 PM 20560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/20/2007 10:57 PM 24652]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [7/7/2010 11:45 AM 312152]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [12/2/2008 4:25 PM 27904]

— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2008-04-23 04:16 124928 -c—-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]

2010-07-16 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-12-31 17:03]

2010-07-17 c:\windows\Tasks\SpeedyPC Program Check.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]

2010-07-18 c:\windows\Tasks\SpeedyPC.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.slingo.com/
mStart Page = hxxp://www.msn.com
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Settings,ProxyOverride = *.local
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1A781DED-4153-C22D-3213-A3211E29DF13} - hxxp://cached.gamedesire.com/g_bin/eng/cards_2_0_0_81.cab
FF - ProfilePath - c:\documents and settings\Mom\Application Data\Mozilla\Firefox\Profiles\la2lruc1.default\
FF - prefs.js: browser.search.selectedEngine - Ask

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-18 14:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-4198444561-2043493450-2835451435-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(8436)
c:\program files\AOL Deskbar\deskbar.dll
c:\program files\Common Files\AOL\AOL Toolbar\smartbox.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-07-18 14:52:02
ComboFix-quarantined-files.txt 2010-07-18 18:51
ComboFix2.txt 2010-07-18 00:31
ComboFix3.txt 2010-07-16 23:02

Pre-Run: 56,436,441,088 bytes free
Post-Run: 56,432,869,376 bytes free

- - End Of File - - 27262C0CBDE94F4BE79932C74F2EF3F4


I ran the free eset online antivirus program you gave me link to run. It said there were 97 infected files but it did not give me a log. It only took me to another page to purchase or do a 30 day free trial of 2 other programs.

My computer is running great now. But that eset saying 97 infected files and no log has me worried.
Please advise.
Locate ESET Online Scanner Log

I need to get a look at the complete file if possible.

Please do the following:
On your keyboard press the Windows key + R
By pressing those two keys at the same time this should display the run dialog box.
Once the Run Dialog box appears please copy and paste the following:
C:\Program Files\ESET\log.txt
After you've copied and pasted the above please select OK.
This should display the ESET Online Scanner log.

Once the ESET Online Scanner log is displayed please copy and paste the contents of the file into your next post.



There are numerous files with failed signature checks on your machine, this is an indication that the catroot is busted.

The best way to fix this is to uninstall, then re-install service pack 3.

For the best results, this should be done in safe mode:


Please download SP3 from here. Save it to your desktop.

http://www.microsoft.com/downloads/details…;displaylang=en

This page will say that this installation package is intended for IT professionals and developers. However, you can safely download this file.


Now tap into safe mode:

(on startup tap F8 repeatedly till an option menu appears - arrow up to safe mode)

Now uninstall SP3
  • Click Start, click Run, copy/paste c:\windows\$NtServicePackUninstall$\spuninst\spuninst.exe into the open box, and then click OK.
  • When the Windows XP Service Pack 3 Removal Wizard starts, click Next.
  • Follow the instructions on the screen to remove Windows XP SP3.

Reboot and boot back into safe mode again.

Now install the SP3 that you had previously downloaded.

Please let me know how that goes.
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # Maxthon.exe=2, 5, 14, 277 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=911d499e263a294eb602fa54ae1e6b0e # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-07-18 09:05:23 # local_time=2010-07-18 05:05:23 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=769 16775141 100 98 0 214843717 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=216778 # found=97 # cleaned=0 # scan_time=6563 C:\Program Files\Internet Explorer\AprtUrNG.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\fMWorLR.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\ggThC.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\GVnICLH.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\jDsMNBSX.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\kdcTnVOrF.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\ltxqKMaEH.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\plBHd.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\QSAgPRPVH.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\uSxOXc.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\vNxtLnvBw.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\YFdqvjivt.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Program Files\Internet Explorer\YVDbrAs.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\bKiPaJNNx.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\cjxkt.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\CtytIR.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\iyDjmc.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\kuCdpJL.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\mBgmPxJ.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\OMaVwWkan.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\pNcpGtOY.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\QaDRFRlal.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\ucjGuGW.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\uosRv.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\uypoh.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\VKJdX.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Mom\Application Data\XQIsbxot.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\msimg32.dll.vir Win32/Toolbar.MyWebSearch application 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\DENKk.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\ePUioK.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\GgRMrOLut.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\kqOcc.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\QPkIUax.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\RXNqhtHu.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\VOjHm.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\WLqkoOJt.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\wwDCpCQb.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\aNcBICdy.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\dfVmKGpk.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\eYMJjAIA.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\FaanTcw.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\mHgEcc.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\MqvLkba.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\nxiMkP.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\qVurMiMR.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\VkTYf.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\XPaUN.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\EbOvFImFu.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\eKSTkwvvo.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\HjTxW.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\pISmdLQvv.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\QoHlyiLEu.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\SfwPc.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\sKehlNIsJ.exe.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\THnFBJ.dll.vir Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223797.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223799.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223800.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223806.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223807.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223808.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223810.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223811.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223813.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223815.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223816.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223817.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223819.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223820.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223821.dll Win32/Toolbar.MyWebSearch application 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223824.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223828.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223831.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223834.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223840.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223841.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223878.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223880.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223883.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223884.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223888.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223893.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223894.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223895.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223896.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223898.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223904.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223905.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223911.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223912.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223913.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223915.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223918.exe Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223920.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223922.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223923.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{963BE347-39CA-4EE9-93DD-C3D92B51EA53}\RP1090\A0223924.dll Win32/Patched.EH trojan 00000000000000000000000000000000 I removed the service pack 3 and reinstalled. Not sure what I should be looking for now. How do I know if the failed signature checks are working correctly?
Hello mattsgrandma please do the following

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/index.php?showtopic=113203
    
    Collect:: 
    C:\Program Files\Internet Explorer\AprtUrNG.exe 
    C:\Program Files\Internet Explorer\fMWorLR.exe 
    C:\Program Files\Internet Explorer\ggThC.dll 
    C:\Program Files\Internet Explorer\GVnICLH.dll 
    C:\Program Files\Internet Explorer\jDsMNBSX.dll 
    C:\Program Files\Internet Explorer\kdcTnVOrF.dll 
    C:\Program Files\Internet Explorer\ltxqKMaEH.exe
    C:\Program Files\Internet Explorer\plBHd.dll 
    C:\Program Files\Internet Explorer\QSAgPRPVH.dll
    C:\Program Files\Internet Explorer\uSxOXc.dll 
    C:\Program Files\Internet Explorer\vNxtLnvBw.dll 
    C:\Program Files\Internet Explorer\YFdqvjivt.dll 
    C:\Program Files\Internet Explorer\YVDbrAs.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 10-07-19.01 - Mom 07/19/2010 21:18:18.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.175 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\COMBOFIX2.EXE
.

((((((((((((((((((((((((( Files Created from 2010-06-20 to 2010-07-20 )))))))))))))))))))))))))))))))
.

2010-07-20 00:44 . 2010-07-20 01:06 ——– d—–w- C:\COMBOFIX229615C
2010-07-19 21:24 . 2010-07-20 01:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-19 03:26 . 2008-04-14 09:42 1306624 -c—-w- c:\windows\system32\dllcache\msxml6.dll
2010-07-19 03:26 . 2008-04-14 02:57 79872 -c—-w- c:\windows\system32\dllcache\msxml6r.dll
2010-07-19 03:21 . 2010-07-19 03:26 ——– d—–w- c:\windows\ServicePackFiles
2010-07-19 03:18 . 2008-04-14 02:06 144384 ——w- c:\windows\system32\drivers\hdaudbus.sys
2010-07-19 03:18 . 2008-04-14 04:10 10240 ——w- c:\windows\system32\drivers\sffp_mmc.sys
2010-07-18 19:12 . 2010-07-18 19:12 ——– d—–w- c:\program files\ESET
2010-07-18 18:18 . 2010-07-18 18:52 ——– d—–w- C:\COMBOFIX2
2010-07-18 00:35 . 2010-07-18 00:35 ——– d—–w- c:\documents and settings\Mom\Application Data\Malwarebytes
2010-07-18 00:35 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-18 00:35 . 2010-07-18 00:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-18 00:35 . 2010-07-18 00:35 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-18 00:35 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-07 17:22 . 2010-07-07 17:24 ——– d—–w- c:\program files\Windows Live Safety Center
2010-07-07 16:35 . 2010-07-08 11:54 ——– d—–w- c:\documents and settings\All Users\Application Data\SpeedyPC
2010-07-07 16:35 . 2010-07-07 16:42 ——– d—–w- c:\program files\SpeedyPC
2010-07-06 21:25 . 2010-07-19 02:14 ——– d—–w- C:\MxDownload

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-20 01:11 . 2007-09-13 22:52 ——– d—–w- c:\documents and settings\Mom\Application Data\MxBoost
2010-07-19 21:29 . 2009-05-20 22:01 ——– d—–w- c:\program files\Alwil Software
2010-07-19 03:28 . 2003-07-16 02:59 76487 —-a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2010-07-15 01:20 . 2008-08-06 18:27 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-14 19:51 . 2007-09-13 22:51 ——– d—–w- c:\program files\Maxthon2
2010-07-12 21:48 . 2007-07-10 13:04 ——– d—–w- c:\program files\HP
2010-07-06 21:21 . 2007-10-12 22:58 ——– d—–w- c:\program files\Glary Utilities
2010-06-27 23:09 . 2005-08-23 20:56 ——– d—–w- c:\program files\PCStitch 6
2010-06-18 04:26 . 2007-12-17 15:30 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-28 04:26 . 2009-06-22 20:04 ——– d—–w- c:\program files\CCleaner
2010-04-30 20:29 . 2010-04-30 20:29 862872 ——w- c:\documents and settings\Mom\Application Data\yahoo!\SearchProtection\fudogs_2.0.1.13_msgr_bts_setup.2010.04.01.01.exe
2006-03-31 01:38 . 2006-03-31 01:39 774144 -c–a-w- c:\program files\RngInterstitial.dll
2005-01-14 19:48 . 2005-01-14 19:47 1107968 -c–a-w- c:\program files\My Money.mny
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3tray2.exe" [2003-02-25 69632]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^Mom^Start Menu^Programs^Startup^CNET TechTracker.lnk]
backup=c:\windows\pss\CNET TechTracker.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-09 16:09 63712 -c–a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"HostManager"=c:\program files\Common Files\AOL\1105230214\ee\AOLSoftware.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105230214\\EE\\aim6.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Maxthon\\Maxthon.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [7/7/2010 11:45 AM 312152]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/20/2007 10:57 PM 24652]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [12/2/2008 4:25 PM 27904]

— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2008-04-23 04:16 124928 -c—-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]

2010-07-20 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-12-31 17:03]

2010-07-19 c:\windows\Tasks\SpeedyPC Program Check.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]

2010-07-18 c:\windows\Tasks\SpeedyPC.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.slingo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Settings,ProxyOverride = *.local
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1A781DED-4153-C22D-3213-A3211E29DF13} - hxxp://cached.gamedesire.com/g_bin/eng/cards_2_0_0_81.cab
FF - ProfilePath - c:\documents and settings\Mom\Application Data\Mozilla\Firefox\Profiles\la2lruc1.default\
FF - prefs.js: browser.search.selectedEngine - Ask

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-19 21:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-4198444561-2043493450-2835451435-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3072)
c:\program files\AOL Deskbar\deskbar.dll
c:\program files\Common Files\AOL\AOL Toolbar\smartbox.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\aolshare\aolshcpy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\windows\system32\HPZipm12.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\wanmpsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
c:\program files\IObit\IObit Security 360\is360.exe
.
**************************************************************************
.
Completion time: 2010-07-19 21:49:02 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-20 01:48
ComboFix2.txt 2010-07-18 18:52
ComboFix3.txt 2010-07-18 00:31
ComboFix4.txt 2010-07-16 23:02

Pre-Run: 54,784,552,960 bytes free
Post-Run: 55,002,034,176 bytes free

- - End Of File - - D2610F907D2E81A65BD7BF4B0F9E577A

Even tho I had click to disable the avast antivirus program combofix said it was still running. I removed the avast program while I ran this, am going to download it again.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI