This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Incredibly Slow PC -- Hijackthis log attached

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:24:53 PM, on 8/19/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
C:\WINDOWS\system32\NLSSRV32.EXE
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\2PT5JV2V\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.doginhispen.com
O15 - Trusted Zone: http://*.turbotax.com
O15 - Trusted Zone: *.whataboutadog.com
O16 - DPF: Tinypic Publisher - http://tinypic.com/flix/tinypic_publisher.CAB
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/as…rl/LSSupCtl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1156033497170
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: Google Update Service (gupdate1ca0b39c7632d4c) (gupdate1ca0b39c7632d4c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NitroPDFDriverCreatorReadSpool (NitroDriverReadSpool) - Nitro PDF Software - C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\NLSSRV32.EXE
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 14207 bytes
And now it freezes for a few mins, especially after reboot. I've cleaned out temp files, defrag'd, and reduced my programs upon startup. Same deal. Monitor freezes here and there, take forever to show "my computer" and just shows the flashlight waving for awhile. Good times.
Hi

Please do the following:


  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O15 - Trusted Zone: *.doginhispen.com
O15 - Trusted Zone: http://*.turbotax.com
O15 - Trusted Zone: *.whataboutadog.com

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.







NEXT



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
My PC hangs after a few mins when I run GMER, so here are the other log results (MBR, Attach, DDS). I'll post GMER if I can ever get itto complete running without stalling out. MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x000003fc Kernel Drivers (total 189): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806FF000 \WINDOWS\system32\hal.dll 0xF7AFF000 \WINDOWS\system32\KDCOM.DLL 0xF7A0F000 \WINDOWS\system32\BOOTVID.dll 0xF75B0000 ACPI.sys 0xF7B01000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF759F000 pci.sys 0xF75FF000 isapnp.sys 0xF7BC7000 pciide.sys 0xF787F000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7B03000 aliide.sys 0xF7B05000 cmdide.sys 0xF7B07000 toside.sys 0xF7B09000 viaide.sys 0xF7B0B000 intelide.sys 0xF760F000 MountMgr.sys 0xF7580000 ftdisk.sys 0xF7887000 PartMgr.sys 0xF761F000 VolSnap.sys 0xF7A13000 cpqarray.sys 0xF7568000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS 0xF7550000 atapi.sys 0xF7A17000 aha154x.sys 0xF788F000 sparrow.sys 0xF7A1B000 symc810.sys 0xF762F000 aic78xx.sys 0xF7A1F000 dac960nt.sys 0xF763F000 ql10wnt.sys 0xF7A23000 amsint.sys 0xF7897000 asc.sys 0xF7A27000 asc3550.sys 0xF789F000 mraid35x.sys 0xF78A7000 i2omp.sys 0xF7A2B000 ini910u.sys 0xF764F000 ql1240.sys 0xF765F000 aic78u2.sys 0xF78AF000 symc8xx.sys 0xF78B7000 sym_hi.sys 0xF78BF000 sym_u3.sys 0xF78C7000 ABP480N5.SYS 0xF78CF000 asc3350p.sys 0xF7B0D000 cd20xrnt.sys 0xF766F000 ultra.sys 0xF7537000 adpu160m.sys 0xF78D7000 dpti2o.sys 0xF767F000 ql1080.sys 0xF768F000 ql1280.sys 0xF769F000 ql12160.sys 0xF78DF000 perc2.sys 0xF7B0F000 perc2hib.sys 0xF78E7000 hpn.sys 0xF7A2F000 cbidf2k.sys 0xF750B000 dac2w2k.sys 0xF76AF000 disk.sys 0xF76BF000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF74EB000 fltmgr.sys 0xF74D9000 sr.sys 0xF76CF000 PxHelp20.sys 0xF74C2000 KSecDD.sys 0xF74AF000 WudfPf.sys 0xF7422000 Ntfs.sys 0xF73F5000 NDIS.sys 0xF78EF000 sonypvl2.sys 0xF76DF000 sisagp.sys 0xF76EF000 viaagp.sys 0xF76FF000 ohci1394.sys 0xF770F000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xF73DB000 Mup.sys 0xF771F000 agp440.sys 0xF772F000 alim1541.sys 0xF773F000 amdagp.sys 0xF774F000 agpCPQ.sys 0xF777F000 \SystemRoot\system32\DRIVERS\nic1394.sys 0xF77CF000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF62BF000 \SystemRoot\system32\DRIVERS\ialmnt5.sys 0xF62AB000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF6283000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF79A7000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF625F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF79AF000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF6229000 \SystemRoot\system32\DRIVERS\HSFHWBS2.sys 0xF6206000 \SystemRoot\system32\DRIVERS\ks.sys 0xF6107000 \SystemRoot\system32\DRIVERS\HSF_DP.sys 0xF605F000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys 0xF79B7000 \SystemRoot\System32\Drivers\Modem.SYS 0xF6039000 \SystemRoot\system32\DRIVERS\e100b325.sys 0xF6025000 \SystemRoot\system32\DRIVERS\parport.sys 0xF77DF000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF77EF000 \SystemRoot\system32\DRIVERS\L8042mou.Sys 0xF77FF000 \SystemRoot\system32\DRIVERS\LMouKE.Sys 0xF79BF000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF72F3000 \SystemRoot\system32\DRIVERS\L8042Kbd.sys 0xF79C7000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF780F000 \SystemRoot\system32\DRIVERS\serial.sys 0xF72EF000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF72EB000 \SystemRoot\System32\Drivers\cdrbsvsd.SYS 0xF781F000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF782F000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF783F000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF79CF000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0xF7CAB000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF7B4B000 \SystemRoot\System32\Drivers\RootMdm.sys 0xF784F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF72DF000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF600E000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF785F000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF786F000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF79D7000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF5FFD000 \SystemRoot\system32\DRIVERS\psched.sys 0xF73CB000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF79DF000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF79E7000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF79EF000 \SystemRoot\system32\DRIVERS\RimSerial.sys 0xF73BB000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7B4D000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF5F9F000 \SystemRoot\system32\DRIVERS\update.sys 0xF72D3000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF73AB000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xAA594000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xAA570000 \SystemRoot\system32\drivers\portcls.sys 0xF738B000 \SystemRoot\system32\drivers\drmk.sys 0xF737B000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7B51000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF7AE7000 \SystemRoot\System32\Drivers\i2omgmt.SYS 0xF7B53000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7D30000 \SystemRoot\System32\Drivers\Null.SYS 0xF7B55000 \SystemRoot\System32\Drivers\Beep.SYS 0xF79FF000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF7A07000 \SystemRoot\System32\drivers\vga.sys 0xF7B57000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7B59000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF6445000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF643D000 \SystemRoot\System32\Drivers\Npfs.SYS 0xAA0E8000 \SystemRoot\System32\Drivers\sonypvf2.SYS 0xAA080000 \SystemRoot\System32\Drivers\sonypvt2.SYS 0xF730B000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xAA045000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xA9FEC000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xA9FAC000 \SystemRoot\System32\Drivers\SYMTDI.SYS 0xA9F86000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF735B000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xA9F69000 \??\C:\Program Files\Symantec\SYMEVENT.SYS 0xF734B000 \SystemRoot\system32\DRIVERS\arp1394.sys 0xA9F2F000 \SystemRoot\System32\Drivers\avgtdix.sys 0xF6435000 \??\C:\WINDOWS\System32\Drivers\sunkfilt39.sys 0xF642D000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xA9F07000 \SystemRoot\system32\DRIVERS\netbt.sys 0xF5F43000 \SystemRoot\System32\drivers\ws2ifsl.sys 0xA9EE5000 \SystemRoot\System32\drivers\afd.sys 0xF733B000 \SystemRoot\system32\DRIVERS\netbios.sys 0xA9EBA000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xA9E4A000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF6EB2000 \SystemRoot\System32\Drivers\Fips.SYS 0xF6425000 \SystemRoot\System32\Drivers\avgmfx86.sys 0xA9DEE000 \SystemRoot\System32\Drivers\avgldx86.sys 0xF6415000 \SystemRoot\System32\Drivers\ASPI32.SYS 0xA9DCA000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xF6E92000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xA9DB2000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7B65000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xAA558000 \SystemRoot\System32\drivers\Dxapi.sys 0xF63FD000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7D0B000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF020000 \SystemRoot\System32\ialmdnt5.dll 0xBF012000 \SystemRoot\System32\ialmrnt5.dll 0xBF042000 \SystemRoot\System32\ialmdev5.DLL 0xBF077000 \SystemRoot\System32\ialmdd5.DLL 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xF7927000 \SystemRoot\system32\DRIVERS\AegisP.sys 0xA9C96000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xF792F000 \SystemRoot\system32\DRIVERS\pnarp.sys 0xF793F000 \SystemRoot\system32\DRIVERS\purendis.sys 0xA98ED000 \SystemRoot\system32\drivers\wdmaud.sys 0xA9D42000 \SystemRoot\system32\drivers\sysaudio.sys 0xA94B0000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xA9555000 \SystemRoot\System32\Drivers\DgiVecp.sys 0xA9304000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys 0xA9189000 \SystemRoot\system32\DRIVERS\srv.sys 0xA9A52000 \SystemRoot\system32\DRIVERS\secdrv.sys 0xA9001000 \SystemRoot\System32\Drivers\SYMREDRV.SYS 0xF7B8D000 \SystemRoot\System32\Drivers\SYMDNS.SYS 0xA8EA1000 \SystemRoot\System32\Drivers\SYMNDIS.SYS 0xA8E18000 \SystemRoot\System32\Drivers\SYMFW.SYS 0xF797F000 \SystemRoot\System32\Drivers\SYMIDS.SYS 0xA8826000 \SystemRoot\System32\Drivers\HTTP.sys 0xA572A000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 57): 0 System Idle Process 4 System 696 C:\WINDOWS\system32\smss.exe 748 csrss.exe 772 C:\WINDOWS\system32\winlogon.exe 816 C:\WINDOWS\system32\services.exe 828 C:\WINDOWS\system32\lsass.exe 992 C:\WINDOWS\system32\svchost.exe 1060 svchost.exe 1156 C:\WINDOWS\system32\svchost.exe 1196 C:\WINDOWS\system32\svchost.exe 1300 svchost.exe 1460 svchost.exe 1540 C:\Program Files\AVG\AVG9\avgchsvx.exe 1548 C:\Program Files\AVG\AVG9\avgrsx.exe 1672 C:\WINDOWS\system32\spoolsv.exe 1700 C:\Program Files\AVG\AVG9\avgcsrvx.exe 1108 C:\WINDOWS\explorer.exe 1124 C:\Program Files\Google\Update\1.2.183.23\GoogleCrashHandler.exe 1244 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe 1400 C:\Program Files\Pure Networks\Network Magic\nmapp.exe 1436 C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe 1516 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 872 C:\Program Files\Logitech\SetPoint\KEM.exe 1952 C:\Program Files\NETGEAR\WPN111\WPN111.exe 164 C:\Program Files\OpenOffice.org 3\program\soffice.exe 180 C:\Program Files\Logitech\SetPoint\KHALMNPR.exe 220 C:\Program Files\OpenOffice.org 3\program\soffice.bin 328 C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe 408 C:\WINDOWS\system32\svchost.exe 420 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 432 C:\Program Files\AVG\AVG9\avgwdsvc.exe 456 C:\Program Files\Bonjour\mDNSResponder.exe 536 C:\Program Files\Flip Video\FlipShare\FlipShareService.exe 1904 C:\Program Files\Java\jre6\bin\jqs.exe 2100 C:\Program Files\AVG\AVG9\avgnsx.exe 2160 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe 2216 C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe 2348 C:\WINDOWS\system32\NLSSRV32.EXE 2620 C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS 2692 C:\Program Files\CyberLink\Shared Files\RichVideo.exe 3276 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe 3336 C:\WINDOWS\system32\svchost.exe 3416 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 3484 C:\Program Files\AVG\AVG9\avgemc.exe 3548 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe 3568 C:\Program Files\AVG\AVG9\avgcsrvx.exe 3892 wmiprvse.exe 3508 C:\WINDOWS\system32\ctfmon.exe 3800 C:\WINDOWS\system32\wuauclt.exe 3124 unsecapp.exe 2436 alg.exe 944 C:\WINDOWS\system32\svchost.exe 5188 C:\Program Files\Internet Explorer\iexplore.exe 1208 C:\Program Files\Internet Explorer\iexplore.exe 4568 C:\Program Files\Internet Explorer\iexplore.exe 3816 C:\Documents and Settings\Owner\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000001`0f1dd200 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (FAT32) PhysicalDrive0 Model Number: WDCWD2000JD-22HBB0, Rev: 08.02D08 Size Device Name MBR Status ——————————————– 186 GB \\.\PhysicalDrive0 Gateway MBR code detected SHA1: 007DADCB3671462B53686F6996D328CFD544ABBD Done! UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 10/29/2005 6:39:03 PM System Uptime: 8/20/2010 3:27:27 PM (50 hours ago) Motherboard: Intel Corporation | | D915GAG Processor: Intel® Pentium® 4 CPU 3.20GHz | | 3200/800mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 182 GiB total, 123.202 GiB free. D: is FIXED (FAT32) - 4 GiB total, 1.682 GiB free. E: is CDROM () F: is CDROM (CDFS) G: is Removable H: is Removable I: is Removable J: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1525: 8/19/2010 6:30:37 PM - Installed Adobe Photoshop Elements 8.0. RP1526: 8/20/2010 9:50:10 PM - System Checkpoint ==== Installed Programs ====================== 3ivx MPEG-4 5.0.3 (remove only) Ad-Aware SE Personal Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Photoshop Elements 8.0 Adobe Photoshop.com Inspiration Browser Adobe Reader 7.1.0 Akamai NetSession Interface AnswerWorks 4.0 Runtime - English Apple Application Support Apple Mobile Device Support Apple Software Update AutoUpdate AVG 9.0 BigFix BlackBerry Desktop Software 5.0.1 BlackBerry® Media Sync Bonjour BroadJump Client Foundation Call of Duty® 2 Cisco Network Magic Compatibility Pack for the 2007 Office system CompuTrainer 3D ver.3 CompuTrainer Challenge PC1 CompuTrainer Coaching Software 1.5 CyclingPeaks CyclingPeaks WKO+ Digital Media Reader Digital Photo Navigator 1.5 DivX Author 1.5 DivX Converter DivX Player DivX Web Player Dr. DivX 2.0 OSS ERUNT 1.1j Flickr Uploadr 3.2.1 FlipShare Google Chrome Google Earth Google Toolbar for Internet Explorer Google Update Helper Google Updater Google Video Uploader High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Home Designer Suite 8 Home Designer Tutorial Training Videos Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Image Resizer Powertoy for Windows XP Inkscape 0.47 Intel® Graphics Media Accelerator Driver Intel® PRO Network Adapters and Drivers IntelliCoach Erg+ 2.0 Intellicoach Profiler iPod for Windows 2005-10-12 iPod for Windows 2006-01-10 iSofter DVD Ripper Platinum 3.0.2007.228 ItsDeductible Express iTunes J2SE Runtime Environment 5.0 Update 5 J2SE Runtime Environment 5.0 Update 6 Java 2 Runtime Environment, SE v1.4.2 Java Auto Updater Java™ 6 Update 20 Learn2 Player (Uninstall Only) Logitech SetPoint Macromedia Flash Player Malwarebytes' Anti-Malware MetaFrame Presentation Server Web Client for Win32 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft Office 2000 SR-1 Premium Microsoft Office XP Professional with FrontPage Microsoft Picture It! Photo Premium 9 Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Works Mozilla Firefox (3.5.8) MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Multimedia Keyboard Driver muvee Plugin 1.0 Nero BurnRights Nero OEM Net MD Simple Burner NETGEAR RangeMax™ Wireless USB 2.0 Adapter WPN111 Network Magic Nitro PDF Professional Norton Spyware Scan Norton Spyware Scan provided by Yahoo! OpenMG Limited Patch 4.3-05-10-05-01 OpenMG Secure Module 4.3.00 OpenOffice.org 3.2 Opera 10.00 PDF-to-Image 1.0 PhotoPad Image Editor Pixillion Image Converter Power-Tap Link PowerCinema NE for Everio PowerDirector Express PowerDVD PowerProducer Punch! Super Home Suite Pure Networks Platform QuickTime RealPlayer Realtek High Definition Audio Driver Roxio Media Manager Samsung ML-1740 Series Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) SmartFTP Client SmartFTP Client 4.0 Setup Files (remove only) SoftV92 Data Fax Modem with SmartCP SonicStage 3.3 Sony DVD Handycam USB Driver Sony Net MD Help Sony USB Driver Sony Vegas Movie Studio 4.0 SRM Evaluation Software V 6.32.57 SRM Multimedia CD Version 1.8 Symantec Network Drivers Update TurboTax Deluxe 2004 TurboTax Deluxe 2005 TurboTax Deluxe Deduction Maximizer 2006 TurboTax ItsDeductible 2005 TurboTax ItsDeductible 2006 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB978506) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) USB 2.0 Single Slot Reader Viewpoint Media Player WebEx Support Manager for Internet Explorer WebFldrs XP WexTech AnswerWorks Windows Backup Utility Windows Driver Package - Prolific (Ser2pl) Ports (07/25/2005 2.0.2.1) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows XP Service Pack 3 WinPatrol Yahoo! BrowserPlus 2.9.8 Yahoo! Install Manager Yahoo! Search Protection Yahoo! Software Update Yahoo! Toolbar ZIP Reader 8.00.0018 ==== Event Viewer Messages From Past Week ======== 8/20/2010 10:17:36 AM, error: Dhcp [1002] - The IP address lease 192.168.1.102 for the Network Card with network address 001111BA5530 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 8/19/2010 7:45:07 PM, error: Service Control Manager [7034] - The Yahoo! Updater service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:07 PM, error: Service Control Manager [7034] - The Symantec Network Drivers Service service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:07 PM, error: Service Control Manager [7034] - The Pure Networks Platform Service service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:07 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:06 PM, error: Service Control Manager [7034] - The PrismXL service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:06 PM, error: Service Control Manager [7034] - The NLS Service service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:06 PM, error: Service Control Manager [7034] - The NitroPDFDriverCreatorReadSpool service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:06 PM, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:04 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:04 PM, error: Service Control Manager [7034] - The FlipShare Service service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:04 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:03 PM, error: Service Control Manager [7034] - The Adobe Active File Monitor V8 service terminated unexpectedly. It has done this 1 time(s). 8/19/2010 7:45:03 PM, error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 8/19/2010 7:45:03 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8/19/2010 6:15:25 PM, error: Service Control Manager [7031] - The Akamai NetSession Interface service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. 8/19/2010 1:35:10 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 001111BA5530 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 8/18/2010 9:22:05 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found. 8/18/2010 7:34:15 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher 9 service to connect. 8/18/2010 7:34:15 PM, error: Service Control Manager [7000] - The WebClient service failed to start due to the following error: %%1290 8/18/2010 7:34:15 PM, error: Service Control Manager [7000] - The MCSTRM service failed to start due to the following error: The system cannot find the file specified. 8/18/2010 7:26:43 PM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 001111BA5530 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). ==== End Of File =========================== DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 17:26:25.78 on Sun 08/22/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.546 [GMT -7:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Google\Update\1.2.183.23\GoogleCrashHandler.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe C:\Program Files\Pure Networks\Network Magic\nmapp.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\NETGEAR\WPN111\wpn111.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe C:\WINDOWS\System32\svchost.exe -k Akamai C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Flip Video\FlipShare\FlipShareService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe C:\WINDOWS\system32\NLSSRV32.EXE C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Owner\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uInternet Connection Wizard,ShellNext = hxxp://yahoo.com/ uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/keyword/%s uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar3.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File uRun: [Yahoo! Pager] 1 uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe" mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash mRun: [] mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe" mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot StartupFolder: c:\docume~1\owner\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\KEM.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpn111\wpn111.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Trusted Zone: turbotax.com DPF: Tinypic Publisher - hxxp://tinypic.com/flix/tinypic_publisher.CAB DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} - hxxp://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} - hxxp://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://support.gateway.com/support/profiler/PCPitStop.CAB DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156033497170 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://download.yahoo.com/dl/installs/yab_af.cab DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} - hxxp://photos.yahoo.com/ocx/us/yexplorer1_9us.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\xkyds75s.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p= FF - prefs.js: browser.search.selectedEngine - Yahoo! Search FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p= FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\documents and settings\owner\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1636.7222\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npybrowserplus_2.4.17.dll FF - plugin: c:\program files\opera\program\plugins\npdivx32.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R0 sonypvl2;sonypvl2;c:\windows\system32\drivers\sonypvl2.sys [2007-9-2 19478] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-28 216400] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-28 29584] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-28 243024] R1 sonypvf2;sonypvf2;c:\windows\system32\drivers\sonypvf2.sys [2007-9-2 635012] R1 sonypvt2;sonypvt2;c:\windows\system32\drivers\sonypvt2.sys [2007-9-2 431236] R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\adobe\elements organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-9 169312] R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2004-8-26 14336] R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-18 921952] R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-18 308136] R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\nitro pdf\professional\NitroPDFDriverService.exe [2010-6-24 196928] R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-6-24 65856] S1 sonypvd2;sonypvd2;c:\windows\system32\drivers\sonypvd2.sys [2007-9-2 64093] S2 gupdate1ca0b39c7632d4c;Google Update Service (gupdate1ca0b39c7632d4c);c:\program files\google\update\GoogleUpdate.exe [2009-7-22 133104] S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2009-12-8 17149] S3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [2009-5-12 23096] S3 SndTVideo;SndTVideo;c:\windows\system32\drivers\SndTVideo.sys [2009-5-12 3768] S3 softctrl;Software Flow Control Driver;c:\windows\system32\drivers\softctrl.sys [2006-8-12 9760] S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2009-12-8 384608] =============== Created Last 30 ================ 2010-08-20 22:07:22 0 d—–w- c:\docume~1\owner\applic~1\WinPatrol 2010-08-20 22:07:01 0 d—–w- c:\program files\BillP Studios 2010-08-20 01:38:21 0 d—–w- c:\program files\common files\Macrovision Shared 2010-08-20 01:07:03 0 d—–w- c:\program files\Photoshop 2010-08-20 01:01:04 772 —-a-w- c:\documents and settings\owner\.recently-used.xbel 2010-08-20 00:58:55 0 d—–w- c:\program files\common files\Akamai 2010-08-19 04:02:00 0 d—–w- c:\docume~1\owner\applic~1\NCH Software 2010-08-19 03:49:43 0 d—–w- c:\program files\NCH Software 2010-08-19 03:37:36 0 d—–w- c:\program files\Intelligent Converters 2010-08-19 03:17:13 17728 —-a-w- c:\windows\system32\nitrolocalui.dll 2010-08-19 03:17:12 26432 —-a-w- c:\windows\system32\nitrolocalmon.dll 2010-08-19 03:16:17 0 d—–w- c:\program files\common files\Nitro PDF 2010-08-19 03:15:42 0 d—–w- c:\program files\Nitro PDF 2010-08-19 03:12:29 0 d—–w- c:\docume~1\owner\applic~1\Downloaded Installations 2010-08-19 02:53:53 0 d—–w- c:\docume~1\owner\applic~1\inkscape 2010-08-19 02:42:28 0 d—–w- c:\program files\Inkscape 2010-08-18 03:23:05 0 d—–w- c:\docume~1\owner\applic~1\OpenOffice.org 2010-08-18 02:10:36 0 d—–w- c:\program files\JRE 2010-08-18 02:10:08 0 d—–w- c:\program files\OpenOffice.org 3 2010-08-18 02:09:43 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-08-18 02:09:43 411368 —-a-w- c:\windows\system32\deployJava1.dll 2010-08-18 02:03:30 0 d—–w- c:\program files\Openoffice ==================== Find3M ==================== 2010-07-18 23:46:03 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2010-07-18 23:45:59 12536 —-a-w- c:\windows\system32\avgrsstx.dll 2010-07-18 23:45:51 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2010-07-06 16:55:12 62896 —ha-w- c:\windows\system32\mlfcache.dat 2010-06-30 12:31:35 149504 —-a-w- c:\windows\system32\schannel.dll 2010-06-24 18:09:14 65856 —-a-w- c:\windows\system32\NLSSRV32.EXE 2010-06-24 12:22:03 916480 —-a-w- c:\windows\system32\wininet.dll 2010-06-23 13:44:04 1851904 —-a-w- c:\windows\system32\win32k.sys 2010-06-17 14:03:00 80384 —-a-w- c:\windows\system32\iccvid.dll 2010-06-14 07:41:45 1172480 —-a-w- c:\windows\system32\msxml3.dll 2010-06-04 02:25:22 256 —-a-w- c:\documents and settings\owner\pool.bin 2005-11-06 23:11:01 0 –sha-w- c:\windows\sminst\HPCD.sys ============= FINISH: 17:27:12.18 ===============

try running GMER with just the "sections" and the "c:\" drive checked

or try running it in safe mode.


Nope. With just those two checked it hangs after a minute or two. Can't save or anything, it's session over at that point and reboot.

In safe mode, there are no scan, etc, buttons. Only OK and cancel. Each reboot takes ~5 mins and another ~5 mins for an IE window to appear (even though it's sitting silently, which of course means I open another sesstion, and another, and nothing… until all of them open at once!).

Yikes.

try running GMER with just the "sections" and the "c:\" drive checked

or try running it in safe mode.


A few more attempts, and I got it to run with just sections/c: checked.




GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-22 20:49:20
Windows 5.1.2600 Service Pack 3
Running: xdrmdhwb.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\pxtdapow.sys


—- Kernel code sections - GMER 1.0.15 —-

init C:\WINDOWS\System32\Drivers\sunkfilt39.sys entry point in "init" section [0xF791F360]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AD5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD135 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254666 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[616] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4EF0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3980] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3980] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3980] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3980] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3980] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3980] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3980] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3980] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3980] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
OK, here you go! ComboFix 10-08-23.02 - Owner 08/23/2010 20:01:48.2.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.713 [GMT -7:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix2.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((( Files Created from 2010-07-24 to 2010-08-24 ))))))))))))))))))))))))))))))) . 2010-08-23 03:33 . 2010-08-23 03:34 ——– d—–w- c:\documents and settings\Administrator.PC 2010-08-21 04:51 . 2010-08-21 04:51 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Nitro PDF 2010-08-20 22:07 . 2009-12-19 18:01 50 —-a-w- c:\documents and settings\Owner\Application Data\WinPatrol\Autoexec.bat 2010-08-20 22:07 . 2004-08-26 18:04 0 —-a-w- c:\documents and settings\Owner\Application Data\WinPatrol\Config.sys 2010-08-20 22:07 . 2010-08-20 22:07 ——– d—–w- c:\documents and settings\Owner\Application Data\WinPatrol 2010-08-20 22:07 . 2010-08-20 22:07 ——– d—–w- c:\program files\BillP Studios 2010-08-20 01:41 . 2010-08-20 01:41 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet 2010-08-20 01:39 . 2010-08-20 01:39 ——– d—–w- c:\program files\Common Files\Adobe AIR 2010-08-20 01:38 . 2010-08-20 01:38 ——– d—–w- c:\program files\Common Files\Macrovision Shared 2010-08-20 01:07 . 2010-08-20 01:22 ——– d—–w- c:\program files\Photoshop 2010-08-20 00:58 . 2010-08-24 02:34 ——– d—–w- c:\program files\Common Files\Akamai 2010-08-19 05:04 . 2010-08-19 05:04 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-381e86d9-n\decora-sse.dll 2010-08-19 05:04 . 2010-08-19 05:04 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-6cfdd4ed-n\msvcp71.dll 2010-08-19 05:04 . 2010-08-19 05:04 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-6cfdd4ed-n\jmc.dll 2010-08-19 05:04 . 2010-08-19 05:04 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-6cfdd4ed-n\msvcr71.dll 2010-08-19 05:04 . 2010-08-19 05:04 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-381e86d9-n\decora-d3d.dll 2010-08-19 04:17 . 2010-08-19 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip 2010-08-19 04:02 . 2010-08-19 04:02 ——– d—–w- c:\documents and settings\Owner\Application Data\NCH Software 2010-08-19 03:49 . 2010-08-19 04:01 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Software 2010-08-19 03:49 . 2010-08-19 04:01 ——– d—–w- c:\program files\NCH Software 2010-08-19 03:37 . 2010-08-19 03:37 ——– d—–w- c:\program files\Intelligent Converters 2010-08-19 03:18 . 2010-08-19 03:18 ——– d—–w- c:\documents and settings\Owner\Application Data\Nitro PDF 2010-08-19 03:17 . 2010-06-24 18:06 17728 —-a-w- c:\windows\system32\nitrolocalui.dll 2010-08-19 03:17 . 2010-06-24 18:06 26432 —-a-w- c:\windows\system32\nitrolocalmon.dll 2010-08-19 03:16 . 2010-08-19 03:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Nitro PDF 2010-08-19 03:12 . 2010-08-19 03:12 ——– d—–w- c:\documents and settings\Owner\Application Data\Downloaded Installations 2010-08-19 02:53 . 2010-08-19 02:53 ——– d—–w- c:\documents and settings\Owner\Application Data\inkscape 2010-08-19 02:42 . 2010-08-19 02:52 ——– d—–w- c:\program files\Inkscape 2010-08-18 03:50 . 2010-08-18 03:50 686080 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\CF.tmp_\sun-pdfimport.oxt\pdfimport.uno.dll 2010-08-18 03:50 . 2010-08-18 03:50 655872 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\CF.tmp_\sun-pdfimport.oxt\msvcr90.dll 2010-08-18 03:50 . 2010-08-18 03:50 583168 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\CF.tmp_\sun-pdfimport.oxt\xpdfimport.exe 2010-08-18 03:50 . 2010-08-18 03:50 568832 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\CF.tmp_\sun-pdfimport.oxt\msvcp90.dll 2010-08-18 03:50 . 2010-08-18 03:50 224768 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\CF.tmp_\sun-pdfimport.oxt\msvcm90.dll 2010-08-18 03:23 . 2010-08-19 03:23 1 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2010-08-18 03:23 . 2010-08-18 03:23 ——– d—–w- c:\documents and settings\Owner\Application Data\OpenOffice.org 2010-08-18 02:10 . 2010-08-18 02:10 ——– d—–w- c:\program files\JRE 2010-08-18 02:10 . 2010-08-18 02:10 ——– d—–w- c:\program files\OpenOffice.org 3 2010-08-18 02:09 . 2010-08-18 02:09 411368 —-a-w- c:\windows\system32\deployJava1.dll 2010-08-18 02:03 . 2010-08-18 03:38 ——– d—–w- c:\program files\Openoffice . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-08-23 00:19 . 2009-12-29 03:58 ——– d—–w- c:\program files\Trend Micro 2010-08-20 01:41 . 2002-04-21 23:50 89696 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-08-20 01:40 . 2005-10-30 01:43 ——– d—–w- c:\program files\Common Files\Adobe 2010-08-18 02:09 . 2004-11-17 14:17 ——– d—–w- c:\program files\Common Files\Java 2010-08-18 02:09 . 2004-11-17 14:17 ——– d—–w- c:\program files\Java 2010-07-18 23:46 . 2009-06-29 03:21 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2010-07-18 23:45 . 2010-07-18 23:45 12536 —-a-w- c:\windows\system32\avgrsstx.dll 2010-07-18 23:45 . 2009-06-29 03:21 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2010-07-06 16:55 . 2010-01-17 04:18 62896 —ha-w- c:\windows\system32\mlfcache.dat 2010-06-30 12:31 . 2004-08-26 16:12 149504 —-a-w- c:\windows\system32\schannel.dll 2010-06-26 14:47 . 2010-06-04 02:28 256 —-a-w- c:\windows\system32\pool.bin 2010-06-24 18:09 . 2010-06-24 18:09 65856 —-a-w- c:\windows\system32\NLSSRV32.EXE 2010-06-24 12:22 . 2004-08-26 16:12 916480 —-a-w- c:\windows\system32\wininet.dll 2010-06-23 13:44 . 2004-08-26 16:12 1851904 —-a-w- c:\windows\system32\win32k.sys 2010-06-21 15:27 . 2004-08-26 16:12 354304 —-a-w- c:\windows\system32\drivers\srv.sys 2010-06-17 14:03 . 2004-08-26 16:11 80384 —-a-w- c:\windows\system32\iccvid.dll 2010-06-14 14:31 . 2004-08-26 18:01 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe 2010-06-14 07:41 . 2004-08-26 16:12 1172480 —-a-w- c:\windows\system32\msxml3.dll 2010-06-04 02:25 . 2010-06-04 02:25 256 —-a-w- c:\documents and settings\Owner\pool.bin 2010-06-03 02:58 . 2009-06-29 03:21 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys 2005-11-06 23:11 . 2005-11-06 23:11 0 –sha-w- c:\windows\SMINST\HPCD.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}] 2009-11-25 21:02 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Yahoo! Pager"="1" [X] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-23 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216] "nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2009-07-08 472112] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-07-08 236016] "WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-05-31 323976] c:\documents and settings\Owner\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2005-11-6 581632] NETGEAR WPN111 Smart Wizard.lnk - c:\program files\NETGEAR\WPN111\wpn111.exe [2009-12-8 884795] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2010-07-18 23:45 12536 —-a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] 1 [X] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2004-09-24 05:44 57344 —-a-w- c:\windows\ALCMTR.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd] 2004-09-25 02:06 2559488 —-a-w- c:\windows\ALCWZRD.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey] 2004-05-18 02:30 543232 —-a-w- c:\windows\zHotkey.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] 2004-03-17 23:10 61952 ——w- c:\windows\system32\Hdaudpropshortcut.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2009-11-13 00:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2001-07-09 19:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-11-11 07:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard] 2002-09-13 20:42 212992 —-a-w- c:\windows\SMINST\Recguard.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder] 2004-08-27 17:50 970752 —-a-w- c:\windows\creator\Remind_XP.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] 2003-11-01 03:42 32768 —-a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowWnd] 2003-09-19 17:09 36864 —-a-w- c:\windows\ShowWnd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] 2004-09-24 03:27 77824 —-a-w- c:\windows\SOUNDMAN.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2005-08-27 02:14 36975 —-a-w- c:\program files\Java\jre1.5.0_05\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM] 2004-10-18 22:05 135168 —-a-w- c:\program files\Digital Media Reader\shwiconEM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor] 2005-11-01 03:41 100056 —-a-w- c:\progra~1\SYMNET~1\SNDMon.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe"= "c:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\AVG\\AVG9\\avgam.exe"= "c:\\Program Files\\AVG\\AVG9\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= "c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe"= c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet,0.0.0.0/255.255.255.255:Enabled:Pure Networks Platform Service [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "1034:TCP"= 1034:TCP:Akamai NetSession Interface "5000:UDP"= 5000:UDP:Akamai NetSession Interface R0 sonypvl2;sonypvl2;c:\windows\system32\drivers\sonypvl2.sys [9/2/2007 8:00 PM 19478] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/28/2009 8:21 PM 216400] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/28/2009 8:21 PM 243024] R1 sonypvf2;sonypvf2;c:\windows\system32\drivers\sonypvf2.sys [9/2/2007 8:00 PM 635012] R1 sonypvt2;sonypvt2;c:\windows\system32\drivers\sonypvt2.sys [9/2/2007 8:00 PM 431236] R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [10/9/2009 5:45 AM 169312] R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/26/2004 9:12 AM 14336] R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [7/18/2010 4:45 PM 921952] R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [7/18/2010 4:45 PM 308136] R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [6/24/2010 11:09 AM 65856] S1 sonypvd2;sonypvd2;c:\windows\system32\drivers\sonypvd2.sys [9/2/2007 8:00 PM 64093] S2 gupdate1ca0b39c7632d4c;Google Update Service (gupdate1ca0b39c7632d4c);c:\program files\Google\Update\GoogleUpdate.exe [7/22/2009 7:03 PM 133104] S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [12/8/2009 8:17 PM 17149] S3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [5/12/2009 6:19 PM 23096] S3 SndTVideo;SndTVideo;c:\windows\system32\drivers\SndTVideo.sys [5/12/2009 6:19 PM 3768] S3 softctrl;Software Flow Control Driver;c:\windows\system32\drivers\softctrl.sys [8/12/2006 6:48 PM 9760] S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [12/8/2009 8:17 PM 384608] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder 2010-07-07 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] 2010-08-24 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-03 01:35] 2010-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-23 02:03] 2010-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-23 02:03] 2010-08-20 c:\windows\Tasks\pixillionShakeIcon.job - c:\program files\NCH Software\Pixillion\pixillion.exe [2010-08-19 03:49] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ uInternet Connection Wizard,ShellNext = hxxp://yahoo.com/ uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000 Trusted Zone: turbotax.com DPF: Tinypic Publisher - hxxp://tinypic.com/flix/tinypic_publisher.CAB FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xkyds75s.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;= FF - prefs.js: browser.search.selectedEngine - Yahoo! Search FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;= FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\documents and settings\Owner\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npybrowserplus_2.4.17.dll FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); . - - - - ORPHANS REMOVED - - - - MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe MSConfigStartUp-HotKeysCmds - c:\windows\system32\hkcmd.exe MSConfigStartUp-SsAAD - c:\progra~1\Sony\SONICS~1\SsAAD.exe MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe MSConfigStartUp-_AntiSpyware - c:\progra~1\mcafee\MCAFEE~1\MssCli.exe ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai] "ServiceDll"="C:/Program Files/Common Files/Akamai/rswin_3745.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai] "ServiceDll"="C:/Program Files/Common Files/Akamai/rswin_3745.dll" . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'explorer.exe'(2956) c:\windows\system32\WININET.dll c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL c:\program files\Logitech\SetPoint\lgscroll.dll c:\program files\SmartFTP Client\en-US\sfShellTools.dll.mui c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2010-08-23 20:14:40 ComboFix-quarantined-files.txt 2010-08-24 03:14 ComboFix2.txt 2010-02-04 01:33 Pre-Run: 133,157,769,216 bytes free Post-Run: 133,158,813,696 bytes free - - End Of File - - 9C3F3C11A3FC31D4D916681862E4FC7F
Hi

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista/Win7 users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

I couldn't update the Malware. It gave me an error message, so I am running it as is.


Can't run the Kaspersky. It says I need Java 1.5 or higher. I run 1.6!! The Malware found nothing:

Malwarebytes' Anti-Malware 1.44
Database version: 3675
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

8/24/2010 7:22:03 PM
mbam-log-2010-08-24 (19-22-02).txt

Scan type: Quick Scan
Objects scanned: 128198
Time elapsed: 5 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi

Try this scanner instead:


**Vista users - right click on the IE icon and run as administrator

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Won't run – just hangs saying "waiting for http:/…" in the lower left. PC runs the same – reasonable speed once rolling, but takes a few mins for an IE window to open up. And it gets bogged down from time to time with no good reason. When I look at performance in task manager, just waving the cursor/arrow around takes 5-10% of CPU.
Please run the following;

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
  • Scroll down to where it says Java Runtime Environment (JRE) 6 Update 21 The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the Download button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement
  • Click Continue The page will refresh.
  • Click on the link to download Windows Offline Installation and Save the file to your Desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start(or My Computer) > Control Panel and double-click on Add or Remove Programs and remove all older versions of Java.
  • Click (highlight) any item with Java Runtime Environment (JRE, J2SE, Java™ SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.
  • After the install is complete, go back to your Control Panel(using Classic View) and click the Java icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button.
    • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
    • Trace and Log Files
  • Click OK on Delete Temporary Files Window. Note: This deletes ALL the Downloaded Applications and Applets from the CACHE
  • Click OK to leave the Temporary Files Window.
  • Click OK to leave the Java Control Panel.
  • Delete jre-6u21-windows-i586-p.exe from your desktop.


NEXT

Please download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should reboot your machine, if not, manually reboot to ensure a complete clean

NEXT

Download and run this program Auslogics Disk Defragmenter

Note: make sure you watch for ansd say NO to the installation of the ASK toolbar.

Try and re-run Kaspersky or ESET after this is completed

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI