This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

viruses found

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, please bare with me asw I'm very new to computing and have been advised to come here for your help by a friend who is helping me.
My pc has been running very slowly and so I ran eset online scanner umong others, They say I have a virus but I have no idea how to remove it. Here is my hijackthis log.
Thanks in advance for any help.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:35:22, on 15/09/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\F-Secure Internet Security\Common\FSHDLL32.EXE
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\BisonCam\BisonHK.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Camera\DRIVERM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lorraine Ross\Local Settings\Temporary Internet Files\Content.IE5\OF844MYA\HiJackThis[1].exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ALOT Toolbar Helper - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\BHO\alotBHO.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: LitmusBHO - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\F-Secure Internet Security\NRS\iescript\baselitmus.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll
O2 - BHO: SimpleAdblock Class - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Common Files\Simple Adblock\SimpleAdblock.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: MP3 Rocket Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Browsing Protection Toolbar - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\F-Secure Internet Security\NRS\iescript\baselitmus.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [BisonHK] C:\WINDOWS\BisonCam\BisonHK.exe
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking10\Ereg.ini
O4 - HKLM\..\Run: [Nuance.ctfmngr] C:\Program Files\Nuance\NaturallySpeaking10\Program\ctfmngr.exe /restore
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Directrec Configuration Tool.lnk = C:\Program Files\Olympus\DeviceDetector\DirectrecConfig.exe
O4 - Global Startup: DRIVER PNP Monitor.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1232369004558
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1232369160230
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…086/mcfscan.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: DM1Service - OLYMPUS IMAGING CORP. - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\ORSP Client\fsorsp.exe
O23 - Service: Google Update Service (gupdate1c9ad3c2f05a774) (gupdate1c9ad3c2f05a774) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 12094 bytes
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi there thanks for your help. I have the logs you requested from MBRCHECK.exe and DDS which are below, but when i tried to run GMER Rootkit Scanner my pc rebooted automatically the first two times i tried to run it, the third time i tried i got the blue screen of death! MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000001c Kernel Drivers (total 143): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806E4000 \WINDOWS\system32\hal.dll 0xBA5A8000 \WINDOWS\system32\KDCOM.DLL 0xBA4B8000 \WINDOWS\system32\BOOTVID.dll 0xB9F79000 ACPI.sys 0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xB9F68000 pci.sys 0xBA0A8000 isapnp.sys 0xBA0B8000 ohci1394.sys 0xBA0C8000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xBA4BC000 compbatt.sys 0xBA4C0000 \WINDOWS\system32\DRIVERS\BATTC.SYS 0xBA670000 pciide.sys 0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xBA0D8000 MountMgr.sys 0xB9F49000 ftdisk.sys 0xBA4C4000 ACPIEC.sys 0xBA671000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 0xBA330000 PartMgr.sys 0xBA338000 pavboot.sys 0xBA0E8000 VolSnap.sys 0xB9F31000 atapi.sys 0xBA0F8000 disk.sys 0xBA108000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xB9F11000 fltMgr.sys 0xB9EFF000 sr.sys 0xB9EE8000 KSecDD.sys 0xB9E5B000 Ntfs.sys 0xB9E49000 fsdfw.sys 0xB9E1C000 \WINDOWS\System32\drivers\NDIS.SYS 0xB9DB1000 timntr.sys 0xB9D58000 tdrpman.sys 0xB9D3A000 snapman.sys 0xB9D20000 Mup.sys 0xBA118000 fsbts.sys 0xB89E0000 \SystemRoot\system32\DRIVERS\igxpmp32.sys 0xB89CC000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xBA488000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xB89A8000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xBA498000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xB8980000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xB860A000 \SystemRoot\system32\DRIVERS\NETw5x32.sys 0xB85EC000 \SystemRoot\system32\DRIVERS\Rtenicxp.sys 0xB902B000 \SystemRoot\system32\DRIVERS\nic1394.sys 0xB85D7000 \SystemRoot\system32\DRIVERS\jmcr.sys 0xB85BF000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS 0xB900B000 \SystemRoot\system32\DRIVERS\serial.sys 0xB9C7F000 \SystemRoot\system32\DRIVERS\serenum.sys 0xB8FFB000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xBA4B0000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xBA348000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xB8FDB000 \SystemRoot\system32\DRIVERS\imapi.sys 0xBA378000 \SystemRoot\system32\drivers\Afc.sys 0xB8FBB000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xB8FAB000 \SystemRoot\system32\DRIVERS\redbook.sys 0xB859C000 \SystemRoot\system32\DRIVERS\ks.sys 0xB9C6F000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0xB9C67000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0xBA138000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xBA73F000 \SystemRoot\system32\DRIVERS\audstub.sys 0xBA148000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xB9C5F000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xB75B2000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xBA168000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xBA178000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xBA388000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xB75A1000 \SystemRoot\system32\DRIVERS\psched.sys 0xBA198000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xBA398000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xBA3A8000 \SystemRoot\system32\DRIVERS\raspti.sys 0xBA1B8000 \SystemRoot\system32\DRIVERS\termdd.sys 0xBA5CE000 \SystemRoot\system32\DRIVERS\swenum.sys 0xB7543000 \SystemRoot\system32\DRIVERS\update.sys 0xB9C47000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xBA1F8000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xBA218000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xBA5D8000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xA6DF5000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xA6DD1000 \SystemRoot\system32\drivers\portcls.sys 0xBA238000 \SystemRoot\system32\drivers\drmk.sys 0xA6CE0000 \SystemRoot\system32\DRIVERS\smserial.sys 0xBA3B8000 \SystemRoot\System32\Drivers\Modem.SYS 0xA6CC0000 \SystemRoot\system32\drivers\IntcHdmi.sys 0xBA5E0000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xBA7C4000 \SystemRoot\System32\Drivers\Null.SYS 0xBA5E4000 \SystemRoot\System32\Drivers\Beep.SYS 0xBA408000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xBA418000 \SystemRoot\System32\drivers\vga.sys 0xBA5E8000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xBA5EC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xBA420000 \SystemRoot\System32\Drivers\Msfs.SYS 0xBA430000 \SystemRoot\System32\Drivers\Npfs.SYS 0xA72B7000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xA6C3D000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xA6BE4000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xA6B94000 \SystemRoot\system32\DRIVERS\netbt.sys 0xA6B6E000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xA6B4C000 \SystemRoot\System32\drivers\afd.sys 0xBA2A8000 \SystemRoot\system32\DRIVERS\netbios.sys 0xA6B21000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xA6AB1000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xBA2D8000 \SystemRoot\System32\Drivers\Fips.SYS 0xBA2E8000 \??\C:\Program Files\F-Secure Internet Security\HIPS\drivers\fshs.sys 0xA6A8D000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xBA448000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xA6989000 \SystemRoot\System32\Drivers\BisonC07.sys 0xBA308000 \SystemRoot\System32\Drivers\STREAM.SYS 0xB901B000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xB8FCB000 \SystemRoot\system32\DRIVERS\arp1394.sys 0xBA458000 \SystemRoot\System32\Drivers\BTHUSB.sys 0xA687E000 \SystemRoot\System32\Drivers\bthport.sys 0xA6C90000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xBA158000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xA6C88000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xA6C80000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xBA188000 \SystemRoot\system32\DRIVERS\rfcomm.sys 0xBA460000 \SystemRoot\system32\DRIVERS\BthEnum.sys 0xA6865000 \SystemRoot\system32\DRIVERS\bthpan.sys 0xBA1D8000 \SystemRoot\system32\DRIVERS\bthmodem.sys 0xBA470000 \SystemRoot\system32\DRIVERS\hidbth.sys 0xA684D000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xBA5F2000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xA6C78000 \SystemRoot\System32\drivers\Dxapi.sys 0xBA478000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xBA79A000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF024000 \SystemRoot\System32\igxpgd32.dll 0xBF012000 \SystemRoot\System32\igxprd32.dll 0xBF04F000 \SystemRoot\System32\igxpdv32.DLL 0xBF25B000 \SystemRoot\System32\igxpdx32.DLL 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xA6901000 \SystemRoot\system32\DRIVERS\tifsfilt.sys 0xA670D000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA6488000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xA6229000 \SystemRoot\system32\DRIVERS\srv.sys 0xA5E97000 \??\C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys 0xA5B12000 \SystemRoot\system32\drivers\wdmaud.sys 0xA5D5F000 \SystemRoot\system32\drivers\sysaudio.sys 0xA5991000 \SystemRoot\System32\Drivers\HTTP.sys 0xA5829000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xA4F4B000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 50): 0 System Idle Process 4 System 636 C:\WINDOWS\system32\smss.exe 1084 csrss.exe 1112 C:\WINDOWS\system32\winlogon.exe 1156 C:\WINDOWS\system32\services.exe 1176 C:\WINDOWS\system32\lsass.exe 1356 C:\WINDOWS\system32\svchost.exe 1404 svchost.exe 1548 C:\WINDOWS\system32\svchost.exe 1628 svchost.exe 1800 svchost.exe 256 C:\WINDOWS\system32\spoolsv.exe 496 svchost.exe 524 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 540 C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe 604 svchost.exe 692 C:\Program Files\Olympus\DeviceDetector\DM1Service.exe 728 C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe 760 C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE 768 C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32.exe 824 C:\Program Files\Java\jre6\bin\jqs.exe 884 C:\Program Files\F-Secure Internet Security\Common\FSHDLL32.EXE 932 C:\Program Files\Common Files\Motive\McciCMService.exe 988 C:\WINDOWS\system32\svchost.exe 1940 C:\WINDOWS\system32\searchindexer.exe 1572 fsorsp.exe 2060 C:\Program Files\F-Secure Internet Security\FWES\program\fsdfwd.exe 2068 C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe 2244 alg.exe 2764 C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav32.exe 3416 C:\WINDOWS\explorer.exe 3868 C:\WINDOWS\system32\rundll32.exe 3884 C:\WINDOWS\system32\igfxpers.exe 3936 C:\WINDOWS\RTHDCPL.exe 4032 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe 4044 C:\WINDOWS\BisonCam\BisonHK.exe 4064 C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe 1052 C:\PROGRA~1\F-SECU~1\Common\FSM32.EXE 680 C:\WINDOWS\system32\igfxsrvc.exe 2160 C:\WINDOWS\system32\ctfmon.exe 2216 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 2896 C:\Program Files\Digital Camera\DRIVERM.exe 2532 C:\WINDOWS\system32\svchost.exe 1992 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 3600 C:\Program Files\Internet Explorer\iexplore.exe 2000 C:\Program Files\Internet Explorer\iexplore.exe 2460 C:\WINDOWS\system32\searchprotocolhost.exe 3264 searchfilterhost.exe 3480 C:\Documents and Settings\Lorraine Ross\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000013`b8427000 (NTFS) PhysicalDrive0 Model Number: HitachiHTS542520K9SA00, Rev: BBDOC31P Size Device Name MBR Status ——————————————– 186 GB \\.\PhysicalDrive0 Legit MBR code detected SHA1: B318F1C92B8A3DFD3186D8699AC5CE5462A877E6 Done! DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 16:35:25.21 on 21/09/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2009.1394 [GMT 1:00] AV: F-Secure Internet Security 2010 10.00 *On-access scanning enabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15} FW: F-Secure Internet Security 2010 10.00 *disabled* {D4747503-0346-49EB-9262-997542F79BF4} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe svchost.exe C:\Program Files\Olympus\DeviceDetector\DM1Service.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\F-Secure Internet Security\Common\FSHDLL32.EXE C:\Program Files\Common Files\Motive\McciCMService.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\BisonCam\BisonHK.exe C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Digital Camera\DRIVERM.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Lorraine Ross\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.uk/ uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: ALOT Toolbar Helper: {14ceeaff-96dd-4101-ae37-d5ecdc23c3f6} - c:\program files\alot\bin\bho\alotBHO.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll BHO: Browsing Protection Class: {c6867eb7-8350-4856-877f-93cf8ae3dc9c} - c:\program files\f-secure internet security\nrs\iescript\baselitmus.dll BHO: MP3 Rocket Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn3\YTSingleInstance.dll BHO: SimpleAdblock Class: {ffcb3198-32f3-4e8b-9539-4324694ed664} - c:\program files\common files\simple adblock\SimpleAdblock.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: MP3 Rocket Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: Browsing Protection Toolbar: {265eee8e-3228-44d3-aea5-f7fdf5860049} - c:\program files\f-secure internet security\nrs\iescript\baselitmus.dll TB: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe mRun: [BisonHK] c:\windows\bisoncam\BisonHK.exe mRun: [RemoteControl8] "c:\program files\cyberlink\powerdvd8\PDVD8Serv.exe" mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [DNS7reminder] "c:\program files\nuance\naturallyspeaking10\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\nuance\naturallyspeaking10\Ereg.ini mRun: [Nuance.ctfmngr] c:\program files\nuance\naturallyspeaking10\program\ctfmngr.exe /restore mRun: [F-Secure Manager] "c:\program files\f-secure internet security\common\FSM32.EXE" /splash mRun: [F-Secure TNB] "c:\program files\f-secure internet security\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\direct~1.lnk - c:\program files\olympus\devicedetector\DirectrecConfig.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\driver~1.lnk - c:\program files\digital camera\DRIVERM.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: c:\program files\f-secure internet security\fsps\program\FSLSP.DLL Trusted Zone: motive.com\pbttbc.bt DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232369004558 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1232369160230 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,6086/mcfscan.cab Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll LSA: Authentication Packages = msv1_0 relog_ap ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\lorrai~1\applic~1\mozilla\firefox\profiles\cg6r8q4n.default\ FF - component: c:\program files\f-secure internet security\nrs\[removed]\components\litmus-ff.dll FF - plugin: c:\documents and settings\lorraine ross\application data\mozilla\firefox\profiles\cg6r8q4n.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\documents and settings\lorraine ross\local settings\application data\yahoo!\browserplus\2.9.2\plugins\npybrowserplus_2.9.2.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npBTEmailConfig.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2009-1-19 41624] R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2009-1-19 80000] R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-9-2 28552] R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\f-secure internet security\hips\drivers\fshs.sys [2009-1-19 68064] R2 F-Secure Gatekeeper Handler Starter;FSGKHS;c:\program files\f-secure internet security\anti-virus\fsgk32st.exe [2009-1-19 215648] R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\f-secure internet security\anti-virus\minifilter\fsgk.sys [2009-1-19 124072] R3 FSORSPClient;F-Secure ORSP Client;c:\program files\f-secure internet security\orsp client\fsorsp.exe [2009-1-19 58024] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2009-1-19 108032] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2009-1-19 84240] S2 gupdate1c9ad3c2f05a774;Google Update Service (gupdate1c9ad3c2f05a774);c:\program files\google\update\GoogleUpdate.exe [2009-3-25 133104] S4 F-Secure Filter;F-Secure File System Filter;c:\program files\f-secure internet security\anti-virus\win2k\fsfilter.sys [2009-1-19 39776] S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\f-secure internet security\anti-virus\win2k\fsrec.sys [2009-1-19 25184] =============== Created Last 30 ================ 2010-09-15 09:34:11 0 d—–w- c:\docume~1\lorrai~1\applic~1\Malwarebytes 2010-09-15 09:34:03 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-09-15 09:34:02 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-09-15 09:34:02 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-09-15 09:34:02 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-09-15 07:18:31 0 d—–w- c:\program files\alot 2010-09-15 07:18:31 0 d—–w- c:\docume~1\lorrai~1\applic~1\alot 2010-09-06 09:24:18 7680 –sha-w- c:\windows\Thumbs.db 2010-09-02 18:40:26 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys 2010-09-02 18:40:09 0 d—–w- c:\program files\Panda Security 2010-09-02 14:26:59 0 d—–w- c:\program files\ESET ==================== Find3M ==================== 2010-08-31 11:12:10 41624 —-a-w- c:\windows\system32\drivers\fsbts.sys 2010-08-17 13:17:06 58880 —-a-w- c:\windows\system32\spoolsv.exe 2010-07-22 15:49:15 590848 —-a-w- c:\windows\system32\rpcrt4.dll 2010-07-22 05:57:20 5120 —-a-w- c:\windows\system32\xpsp4res.dll 2010-07-17 04:00:04 423656 —-a-w- c:\windows\system32\deployJava1.dll 2010-06-30 12:31:35 149504 —-a-w- c:\windows\system32\schannel.dll 2010-06-24 12:22:03 916480 —-a-w- c:\windows\system32\wininet.dll ============= FINISH: 16:35:46.73 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 19/01/2009 11:57:20 System Uptime: 21/09/2010 09:40:02 (7 hours ago) Motherboard: CLEVO Co. | | L390T Processor: Intel Pentium III Xeon processor | U2E1 | 2262/mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 79 GiB total, 60.251 GiB free. D: is FIXED (NTFS) - 100 GiB total, 96.813 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP401: 23/06/2010 20:50:07 - System Checkpoint RP402: 24/06/2010 00:16:25 - Software Distribution Service 3.0 RP403: 25/06/2010 18:02:37 - System Checkpoint RP404: 27/06/2010 21:56:28 - System Checkpoint RP405: 28/06/2010 22:12:20 - System Checkpoint RP406: 30/06/2010 08:08:33 - System Checkpoint RP407: 01/07/2010 08:41:08 - System Checkpoint RP408: 02/07/2010 09:29:46 - System Checkpoint RP409: 03/07/2010 10:20:04 - System Checkpoint RP410: 04/07/2010 11:16:24 - System Checkpoint RP411: 05/07/2010 16:53:28 - System Checkpoint RP412: 07/07/2010 12:55:55 - System Checkpoint RP413: 11/07/2010 09:48:33 - System Checkpoint RP414: 12/07/2010 15:42:44 - System Checkpoint RP415: 13/07/2010 16:19:33 - System Checkpoint RP416: 14/07/2010 20:10:50 - System Checkpoint RP417: 14/07/2010 23:29:18 - Software Distribution Service 3.0 RP418: 15/07/2010 23:33:21 - System Checkpoint RP419: 16/07/2010 18:57:10 - Installed Simple Adblock RP420: 16/07/2010 19:28:31 - Software Distribution Service 3.0 RP421: 17/07/2010 20:49:24 - System Checkpoint RP422: 18/07/2010 21:07:56 - System Checkpoint RP423: 19/07/2010 21:23:33 - System Checkpoint RP424: 20/07/2010 23:43:59 - System Checkpoint RP425: 22/07/2010 11:01:24 - System Checkpoint RP426: 23/07/2010 15:49:24 - System Checkpoint RP427: 24/07/2010 17:53:29 - System Checkpoint RP428: 25/07/2010 19:05:57 - System Checkpoint RP429: 26/07/2010 19:16:26 - System Checkpoint RP430: 27/07/2010 19:39:48 - System Checkpoint RP431: 29/07/2010 17:33:21 - System Checkpoint RP432: 30/07/2010 21:14:13 - System Checkpoint RP433: 01/08/2010 21:31:57 - System Checkpoint RP434: 02/08/2010 22:43:02 - System Checkpoint RP435: 03/08/2010 01:08:23 - Software Distribution Service 3.0 RP436: 04/08/2010 17:10:43 - System Checkpoint RP437: 05/08/2010 17:27:04 - System Checkpoint RP438: 06/08/2010 21:50:49 - System Checkpoint RP439: 07/08/2010 22:04:54 - System Checkpoint RP440: 09/08/2010 12:51:19 - System Checkpoint RP441: 10/08/2010 20:30:55 - System Checkpoint RP442: 11/08/2010 20:43:27 - System Checkpoint RP443: 13/08/2010 13:27:52 - Software Distribution Service 3.0 RP444: 14/08/2010 18:06:53 - System Checkpoint RP445: 15/08/2010 18:22:22 - System Checkpoint RP446: 17/08/2010 17:38:44 - System Checkpoint RP447: 19/08/2010 01:32:08 - System Checkpoint RP448: 20/08/2010 18:11:27 - System Checkpoint RP449: 21/08/2010 18:30:47 - System Checkpoint RP450: 22/08/2010 18:31:14 - System Checkpoint RP451: 24/08/2010 18:44:53 - System Checkpoint RP452: 27/08/2010 10:10:49 - System Checkpoint RP453: 28/08/2010 13:52:53 - System Checkpoint RP454: 29/08/2010 16:02:23 - System Checkpoint RP455: 30/08/2010 16:18:12 - System Checkpoint RP456: 31/08/2010 17:39:14 - System Checkpoint RP457: 01/09/2010 17:50:01 - System Checkpoint RP458: 02/09/2010 18:20:45 - Installed Java™ 6 Update 21 RP459: 03/09/2010 18:26:29 - System Checkpoint RP460: 04/09/2010 19:11:24 - System Checkpoint RP461: 06/09/2010 10:44:30 - System Checkpoint RP462: 07/09/2010 11:35:28 - System Checkpoint RP463: 08/09/2010 10:34:21 - Software Distribution Service 3.0 RP464: 09/09/2010 11:17:43 - System Checkpoint RP465: 10/09/2010 16:22:44 - System Checkpoint RP466: 11/09/2010 16:29:48 - System Checkpoint RP467: 12/09/2010 16:46:40 - System Checkpoint RP468: 13/09/2010 16:53:47 - System Checkpoint RP469: 14/09/2010 17:04:31 - System Checkpoint RP470: 15/09/2010 18:02:25 - System Checkpoint RP471: 15/09/2010 22:57:47 - Software Distribution Service 3.0 RP472: 16/09/2010 23:46:57 - System Checkpoint RP473: 18/09/2010 10:52:10 - System Checkpoint RP474: 20/09/2010 19:12:18 - System Checkpoint ==== Installed Programs ====================== Acronis True Image Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.1.4 ALOT Toolbar ArcSoft MediaImpression Ask Toolbar µTorrent BisonCam BT Broadband Desktop Help BT Email Configuration Tool BT Wireless Connection Manager BT Yahoo! Applications BTHomeHub Canon MP Navigator EX 1.0 Canon MX310 series Canon MX310 series User Registration Canon My Printer Canon Utilities Easy-PhotoPrint EX Canon Utilities Solution Menu CCleaner Critical Update for Windows Media Player 11 (KB959772) CyberLink PowerDVD 8 Dragon NaturallySpeaking 10 DRIVER ESET Online Scanner v3 F-Secure Internet Security 2010 F-Secure PSC Prerequisites Google Earth Google Toolbar for Internet Explorer Google Update Helper HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB915800-v4) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HotKey_Driver Intel® Graphics Media Accelerator Driver Java Auto Updater Java™ 6 Update 21 Java™ SE Runtime Environment 6 Update 1 JMicron JMB38X Flash Media Controller Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Standard 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable MindGenius Education Motorola SM56 Data Fax Modem Mozilla Firefox (3.6.6) MSN MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) myibay eBay bid sniper 1.0.40 Nero 8 Essentials neroxml Olympus DSS Player Panda ActiveScan 2.0 Presto! PageManager 7.15.16 QuickTime REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver SAMSUNG CDMA Modem Driver Set SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung PC Studio Samsung PC Studio 3 USB Driver Installer ScanSoft OmniPage SE 4 Security Update for 2007 Microsoft Office System (KB2277947) Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for 2007 Microsoft Office System (KB982312) Security Update for 2007 Microsoft Office System (KB982331) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB982308) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office Outlook 2007 (KB2288953) Security Update for Microsoft Office PowerPoint 2007 (KB982158) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2251419) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Search 4 - KB963093 Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Segoe UI Simple Adblock TeamViewer 5 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Word 2007 Help (KB963665) Update for Microsoft Script Editor Help (KB957253) Update for Microsoft Windows (KB971513) Update for Outlook 2007 Junk Email Filter (kb2291599) Update for Windows Internet Explorer 8 (KB971930) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows Internet Explorer 8 (KB982632) Update for Windows XP (KB2141007) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VCRedistSetup Visual C++ Runtime for Dragon NaturallySpeaking Vodafone 804SS USB driver Software WebFldrs XP Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live OneCare safety scanner Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Format 11 runtime Windows Media Player 11 Windows Search 4.0 Yahoo! BrowserPlus 2.9.8 Yahoo! Search Protection Yahoo! Software Update ==== Event Viewer Messages From Past Week ======== 21/09/2010 09:49:44, error: System Error [1003] - Error code 10000050, parameter1 a57cdb30, parameter2 00000001, parameter3 a541afa6, parameter4 00000000. 21/09/2010 09:37:32, error: System Error [1003] - Error code 10000050, parameter1 e1ce8000, parameter2 00000000, parameter3 a6c1bc3e, parameter4 00000001. 21/09/2010 09:19:28, error: F-Secure Gatekeeper [1] - 21/09/2010 01:42:36, error: PlugPlayManager [11] - The device Root\LEGACY_FSBL\0000 disappeared from the system without first being prepared for removal. 20/09/2010 21:23:06, error: System Error [1003] - Error code 100000d1, parameter1 00000000, parameter2 0000001c, parameter3 00000001, parameter4 857c200c. 20/09/2010 20:37:48, error: System Error [1003] - Error code 10000050, parameter1 a6002b30, parameter2 00000001, parameter3 a5f6cfa6, parameter4 00000000. ==== End Of File ===========================
Try this scan instead:

Please download Rootkit Unhooker and save it on your desktop.
  • Disable your security programs
  • Double click RKUnhookerLE.exe to run it
  • Click the Report tab, then click Scan
  • Check Drivers and Stealth Code,
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.
Note - You may get this warning, it is ok, just ignore it:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"

Hi there, heres the report from rootkit unhooker RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #2 ============================================== >Drivers ============================================== 0xB89F3000 C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 6008832 bytes (Intel Corporation, Intel Graphics Miniport Driver) 0xA7AC8000 C:\WINDOWS\system32\drivers\RtkHDAud.sys 4874240 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0xB861D000 C:\WINDOWS\system32\DRIVERS\NETw5x32.sys 3629056 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver) 0xBF25B000 C:\WINDOWS\System32\igxpdx32.DLL 3174400 bytes (Intel Corporation, DirectDraw® Driver for Intel® Graphics Technology) 0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2150400 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2150400 bytes 0x804D7000 RAW 2150400 bytes 0x804D7000 WMIxWDM 2150400 bytes 0xBF04F000 C:\WINDOWS\System32\igxpdv32.DLL 2146304 bytes (Intel Corporation, Component GHAL Driver) 0xBF800000 Win32k 1855488 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xA765C000 C:\WINDOWS\System32\Drivers\BisonC07.sys 1064960 bytes (Bison Electronics. Inc. , Universal Serial Bus Camera Driver) 0xA79B3000 C:\WINDOWS\system32\DRIVERS\smserial.sys 987136 bytes (Motorola Inc., Motorola SM56 Modem WDM Driver) 0xB9E5B000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xA7784000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xB9DB1000 timntr.sys 438272 bytes (Acronis, Acronis True Image Backup Archive Explorer) 0xB8216000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xA78B7000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xB9D58000 tdrpman.sys 364544 bytes (Acronis, Acronis Try&Decide and Restore Points Volume Filter Driver) 0xA6EFC000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver) 0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xA7551000 C:\WINDOWS\System32\Drivers\bthport.sys 274432 bytes (Microsoft Corporation, Bluetooth Bus Driver) 0xA64B5000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xA715B000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xB9E1C000 C:\WINDOWS\System32\drivers\NDIS.SYS 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xBF024000 C:\WINDOWS\System32\igxpgd32.dll 176128 bytes (Intel Corporation, Intel Graphics 2D Driver) 0xA77F4000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xB8993000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a) 0xA7867000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xA7841000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xA7760000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xA7AA4000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xB89BB000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xB85AF000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xA781F000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0xA6ACA000 C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys 139264 bytes (-, -) 0x806E4000 ACPI_HAL 134400 bytes 0x806E4000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xB9F11000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xA7993000 C:\WINDOWS\system32\drivers\IntcHdmi.sys 131072 bytes (Intel® Corporation, Intel® High Definition Audio HDMI) 0xB9F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xB85FF000 C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 122880 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver ) 0xB9D3A000 snapman.sys 122880 bytes (Acronis, Acronis Snapshot API) 0xB9D20000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xA7538000 C:\WINDOWS\system32\DRIVERS\bthpan.sys 102400 bytes (Microsoft Corporation, Bluetooth Personal Area Networking) 0xB9F31000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xA7520000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xB85D2000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver) 0xB9EE8000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xB8598000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xB85EA000 C:\WINDOWS\system32\DRIVERS\jmcr.sys 86016 bytes (JMicron Technology Corp., JMicron JMB38X Memory Card Reader Driver) 0xA67BF000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xB89DF000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xA7910000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xB9E49000 fsdfw.sys 73728 bytes (F-Secure Corporation, F-Secure Internet Shield Driver) 0xBF012000 C:\WINDOWS\System32\igxprd32.dll 73728 bytes (Intel Corporation, Intel Graphics 2D Rotation Driver) 0xB9EFF000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xB8274000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xA6FFB000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xB8FAE000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xB901E000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager) 0xBA0B8000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0xB8FFE000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xBA148000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client) 0xBA268000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xBA318000 C:\Program Files\F-Secure Internet Security\HIPS\drivers\fshs.sys 61440 bytes (F-Secure Corporation, HIPS 32-bit kernel module) 0xBA138000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xBA1C8000 C:\WINDOWS\system32\DRIVERS\rfcomm.sys 61440 bytes (Microsoft Corporation, Bluetooth RFCOMM Driver) 0xA6CD4000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xBA248000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xBA0C8000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0xBA108000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xB8FEE000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xBA168000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xB902E000 C:\WINDOWS\System32\Drivers\STREAM.SYS 53248 bytes (Microsoft Corporation, WDM CODEC Class Device Driver 2.0) 0xBA0E8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xBA198000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xBA308000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xB8FCE000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xBA0D8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xBA188000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xBA208000 C:\WINDOWS\system32\DRIVERS\bthmodem.sys 40960 bytes (Microsoft Corporation, Bluetooth Communications Driver) 0xBA0A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xBA228000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xBA1D8000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xA75D4000 C:\WINDOWS\system32\DRIVERS\tifsfilt.sys 40960 bytes (Acronis, Acronis True Image File System Filter) 0xBA0F8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xBA118000 fsbts.sys 36864 bytes (-, -) 0xBA1A8000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xBA158000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xBA1B8000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xBA2D8000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xA6300000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xB8FDE000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xBA4B0000 C:\WINDOWS\system32\drivers\Afc.sys 32768 bytes (Arcsoft, Inc., Arcsoft® ASPI Shell) 0xBA3B0000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver) 0xBA430000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xBA450000 C:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xBA488000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xBA490000 C:\WINDOWS\system32\DRIVERS\hidbth.sys 28672 bytes (Microsoft Corporation, Bluetooth Miniport Driver for HID Devices) 0xBA408000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xBA328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xBA4A0000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xBA4A8000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xBA338000 pavboot.sys 24576 bytes (Panda Security, S.L., Panda Boot Driver) 0xBA478000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xBA418000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xBA470000 C:\WINDOWS\system32\DRIVERS\BthEnum.sys 20480 bytes (Microsoft Corporation, Bluetooth Bus Extender) 0xBA468000 C:\WINDOWS\System32\Drivers\BTHUSB.sys 20480 bytes (Microsoft Corporation, Bluetooth Miniport Driver) 0xBA420000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xBA388000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xBA398000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xBA378000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xBA498000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xBA4C0000 C:\WINDOWS\system32\DRIVERS\BATTC.SYS 16384 bytes (Microsoft Corporation, Battery Class Driver) 0xB9C67000 C:\WINDOWS\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0xA795F000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xB9C43000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xA73E4000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xB9C77000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xBA4C4000 ACPIEC.sys 12288 bytes (Microsoft Corporation, ACPI Embedded Controller Driver) 0xBA4B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xBA4BC000 compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0xA7957000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xA796F000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xA7967000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xB9C57000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xA7F86000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xB9C5F000 C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI) 0xBA5F6000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xBA610000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xBA5F2000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xBA5A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xBA5FA000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xBA5FE000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xBA5D2000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xBA5DC000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xBA5AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xBA778000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xBA731000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xBA6F0000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xBA671000 C:\WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 4096 bytes (Microsoft Corporation, ACPI Operation Registration Driver) 0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ==============================================
hi

please do the following:

Download ComboFix from either of these locations:
Link 1
Link 2


VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi there, here is my combo fix log

ComboFix 10-09-21.01 - Lorraine Ross 21/09/2010 22:21:03.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2009.1475 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: F-Secure Internet Security 2010 10.00 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: F-Secure Internet Security 2010 10.00 *disabled* {D4747503-0346-49EB-9262-997542F79BF4}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Lorraine Ross\Application Data\alot
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_0\Button_0.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_0\Button_0.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_1\Button_1.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_1\Button_1.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_10\Button_10.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_10\Button_10.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_2\Button_2.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_2\Button_2.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_3\Button_3.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_3\Button_3.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_4\Button_4.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_4\Button_4.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_5\Button_5.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_5\Button_5.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_6\Button_6.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_6\Button_6.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_7\Button_7.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_7\Button_7.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_8\Button_8.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_8\Button_8.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_9\Button_9.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Button_9\Button_9.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\configurator\configurator.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\configurator\configurator.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\contextMenu\contextMenu.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\contextMenu\contextMenu.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\ErrorSearch\ErrorSearch.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\ErrorSearch\ErrorSearch.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\hideToolbarLayout\hideToolbarLayout.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\hideToolbarLayout\hideToolbarLayout.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\postInstallLayout\postInstallLayout.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\postInstallLayout\postInstallLayout.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\products\products.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\products\products.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\BrowserSearch\alot_search_defend.html
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\BrowserSearch\images\favicon.ico
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_0\images\alot_logo_button.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_0\images\alot_logo_button.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_image_search.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_image_search.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_news_search.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_news_search.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_search_button.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_search_button.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_shop_search.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_shop_search.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_videos_search.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_videos_search.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_web_search.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_1\images\alot_web_search.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_10\images\1925_icon.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_2\images\alot_configure.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_2\images\alot_configure.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_3\images\default_1212_alot_new_search.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_3\images\default_1212_alot_new_search.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_4\images\default_1217_alot_new_newsrss.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_4\images\default_1217_alot_new_newsrss.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_5\images\default_1220_alot_new_newsroom.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_5\images\default_1220_alot_new_newsroom.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_6\images\default_1007_alot_weather_widget.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_6\images\default_1007_alot_weather_widget.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_7\images\default_2254_email.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_7\images\default_2254_email.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_7\images\icon_configure.JPG
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_8\images\2938_icon.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Button_9\images\3269_icon.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\contextMenu\images\alot_icon.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\contextMenu\images\alot_icon.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\contextMenu\images\alot_logo_button.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\contextMenu\images\alot_logo_button.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\domains.dat
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\alot_brand.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\alot_splitter.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\discover.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\intro_popup.png
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\spinner.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_bottom.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_btnclose0.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_btnclose1.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_btnconfig0.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_btnconfig1.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_btnrefresh0.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_btnrefresh1.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_caption.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_error_bg.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_error_close.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\Resources\Shared\images\widget_error_icon.bmp
c:\documents and settings\Lorraine Ross\Application Data\alot\TimerManager\TimerManager.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\TimerManager\TimerManager.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\toolbar.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\toolbar.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\toolbarContextMenu\toolbarContextMenu.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\toolbarContextMenu\toolbarContextMenu.xml.backup
c:\documents and settings\Lorraine Ross\Application Data\alot\ToolbarSearch\ToolbarSearch.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Updater\Updater.xml
c:\documents and settings\Lorraine Ross\Application Data\alot\Updater\Updater.xml.backup
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_1.tmp
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_2.tmp
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_23.tmp
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_24.tmp
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_2B.tmp
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_2C.tmp
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_2D.tmp
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_2E.tmp
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_31.tmp
c:\documents and settings\m and e\Local Settings\Temporary Internet Files\ab_32.tmp
c:\windows\system\BisonC07.dll

.
((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
.

2010-09-15 09:34 . 2010-09-15 09:34 ——– d—–w- c:\documents and settings\Lorraine Ross\Application Data\Malwarebytes
2010-09-15 09:34 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-15 09:34 . 2010-09-15 09:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-15 09:34 . 2010-09-15 09:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-15 09:34 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-15 07:18 . 2010-09-15 07:18 ——– d—–w- c:\program files\alot
2010-09-02 18:40 . 2009-06-30 08:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys
2010-09-02 18:40 . 2010-09-02 18:40 ——– d—–w- c:\program files\Panda Security
2010-09-02 14:26 . 2010-09-02 14:26 ——– d—–w- c:\program files\ESET
2010-08-28 20:38 . 2010-08-28 20:38 503808 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-10789ea6-n\msvcp71.dll
2010-08-28 20:38 . 2010-08-28 20:38 499712 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-10789ea6-n\jmc.dll
2010-08-28 20:38 . 2010-08-28 20:38 348160 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-10789ea6-n\msvcr71.dll
2010-08-28 20:38 . 2010-08-28 20:38 61440 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-489c07cc-n\decora-sse.dll
2010-08-28 20:38 . 2010-08-28 20:38 12800 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-489c07cc-n\decora-d3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-15 22:01 . 2009-01-19 14:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-09-15 17:31 . 2009-11-19 14:41 ——– d—–w- c:\program files\myibay
2010-09-11 09:28 . 2010-07-16 17:57 ——– d—–w- c:\documents and settings\Lorraine Ross\Application Data\Simple Adblock
2010-09-08 17:04 . 2009-01-19 13:14 ——– d—–w- c:\program files\Microsoft Silverlight
2010-09-02 18:22 . 2010-07-19 20:04 ——– d—–w- c:\documents and settings\Lorraine Ross\Application Data\MP3Rocket
2010-09-02 18:22 . 2010-07-19 20:04 ——– d—–w- c:\program files\MP3 Rocket
2010-09-02 17:25 . 2010-07-16 18:36 ——– d—–w- c:\program files\CCleaner
2010-09-02 17:22 . 2009-01-19 12:40 ——– d—–w- c:\program files\Common Files\Java
2010-09-02 17:22 . 2009-01-19 12:40 ——– d—–w- c:\program files\Java
2010-08-31 11:12 . 2009-01-19 15:06 41624 —-a-w- c:\windows\system32\drivers\fsbts.sys
2010-08-22 14:39 . 2010-07-24 20:53 ——– d—–w- c:\documents and settings\m and e\Application Data\Simple Adblock
2010-08-17 13:17 . 2008-04-14 12:00 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-09 21:02 . 2010-08-09 21:02 61440 —-a-w- c:\documents and settings\Lorraine Ross\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3942b276-n\decora-sse.dll
2010-08-09 21:02 . 2010-08-09 21:02 503808 —-a-w- c:\documents and settings\Lorraine Ross\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-68111cd5-n\msvcp71.dll
2010-08-09 21:02 . 2010-08-09 21:02 499712 —-a-w- c:\documents and settings\Lorraine Ross\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-68111cd5-n\jmc.dll
2010-08-09 21:02 . 2010-08-09 21:02 348160 —-a-w- c:\documents and settings\Lorraine Ross\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-68111cd5-n\msvcr71.dll
2010-08-09 21:02 . 2010-08-09 21:02 12800 —-a-w- c:\documents and settings\Lorraine Ross\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3942b276-n\decora-d3d.dll
2010-08-05 17:03 . 2010-08-05 17:03 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-08-04 21:18 . 2009-11-19 14:27 ——– d—–w- c:\program files\Windows Live Safety Center
2010-08-01 21:01 . 2010-07-19 20:04 ——– d—–w- c:\program files\Ask.com
2010-07-22 15:49 . 2008-04-14 12:00 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-16 17:49 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2010-07-17 04:00 . 2010-04-28 17:30 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-05 14:38 . 2010-07-05 14:38 503808 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-38ccbb39-n\msvcp71.dll
2010-07-05 14:38 . 2010-07-05 14:38 499712 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-38ccbb39-n\jmc.dll
2010-07-05 14:38 . 2010-07-05 14:38 348160 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-38ccbb39-n\msvcr71.dll
2010-07-05 14:38 . 2010-07-05 14:38 12800 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-201964b4-n\decora-d3d.dll
2010-07-05 14:38 . 2010-07-05 14:38 61440 —-a-w- c:\documents and settings\m and e\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-201964b4-n\decora-sse.dll
2010-06-30 12:31 . 2008-04-14 12:00 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 14:23 1385864 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-28 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-17 141848]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-16 634880]
"BisonHK"="c:\windows\BisonCam\BisonHK.exe" [2008-03-25 77824]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" [2007-04-16 259624]
"Nuance.ctfmngr"="c:\program files\Nuance\NaturallySpeaking10\Program\ctfmngr.exe" [2009-02-13 46440]
"F-Secure Manager"="c:\program files\F-Secure Internet Security\Common\FSM32.EXE" [2009-07-09 199264]
"F-Secure TNB"="c:\program files\F-Secure Internet Security\FSGUI\TNBUtil.exe" [2009-07-09 2349664]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Directrec Configuration Tool.lnk - c:\program files\Olympus\DeviceDetector\DirectrecConfig.exe [2009-1-19 122880]
DRIVER PNP Monitor.lnk - c:\program files\Digital Camera\DRIVERM.exe [2009-12-24 163840]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotKeyDriver.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HotKeyDriver.lnk
backup=c:\windows\pss\HotKeyDriver.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Lorraine Ross^Start Menu^Programs^Startup^MP3 Rocket (Minimized).lnk]
path=c:\documents and settings\Lorraine Ross\Start Menu\Programs\Startup\MP3 Rocket (Minimized).lnk
backup=c:\windows\pss\MP3 Rocket (Minimized).lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2008-08-07 14:51 140568 —-a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2008-08-07 15:44 909248 —-a-w- c:\program files\Acronis\TrueImage\TimounterMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 01:04 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-03-18 11:19 207360 —-a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-10-15 09:14 202024 —-a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-04-03 16:50 1603152 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-05-14 16:01 644696 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeLay]
2008-03-11 17:08 53248 —-a-w- c:\windows\BisonCam\DeLay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-06-01 09:17 5252408 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-02-04 12:02 79400 —-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
2007-12-14 11:36 50472 ——w- c:\program files\CyberLink\PowerDVD8\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
2009-02-03 13:15 111856 —-a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2008-08-07 14:49 1326488 —-a-w- c:\program files\Acronis\TrueImage\TrueImageMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
2009-02-03 13:15 111856 —-a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [19/01/2009 16:06 41624]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [19/01/2009 15:44 80000]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [02/09/2010 19:40 28552]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\F-Secure Internet Security\HIPS\drivers\fshs.sys [19/01/2009 15:43 68064]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys [19/01/2009 15:43 124072]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\F-Secure Internet Security\ORSP Client\fsorsp.exe [19/01/2009 15:43 58024]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [19/01/2009 13:26 108032]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [19/01/2009 13:26 84240]
S2 gupdate1c9ad3c2f05a774;Google Update Service (gupdate1c9ad3c2f05a774);c:\program files\Google\Update\GoogleUpdate.exe [25/03/2009 12:23 133104]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\F-Secure Internet Security\Anti-Virus\win2k\fsfilter.sys [19/01/2009 15:43 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\F-Secure Internet Security\Anti-Virus\win2k\fsrec.sys [19/01/2009 15:43 25184]

— Other Services/Drivers In Memory —

*NewlyCreated* - NORMANDY
*Deregistered* - Normandy
.
Contents of the 'Scheduled Tasks' folder

2010-09-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-25 11:23]

2010-09-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-25 11:23]

2010-09-21 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\F-SECU~1\ANTI-V~1\fsav.exe [2009-01-19 09:31]

2010-09-21 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-26 14:23]

2010-09-21 c:\windows\Tasks\User_Feed_Synchronization-{75F200BC-5D38-479C-BFC5-20D1DCED97CD}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
LSP: c:\program files\F-Secure Internet Security\FSPS\program\FSLSP.DLL
Trusted Zone: motive.com\pbttbc.bt
FF - ProfilePath - c:\documents and settings\Lorraine Ross\Application Data\Mozilla\Firefox\Profiles\cg6r8q4n.default\
FF - component: c:\program files\F-Secure Internet Security\NRS\[removed]\components\litmus-ff.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npBTEmailConfig.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-btbb_McciTrayApp - c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
MSConfigStartUp-btbb_wcm_McciTrayApp - c:\program files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe
AddRemove-BT Broadband Desktop Help - c:\program files\BT Broadband Desktop Help\btbb\unBTBDH.exe
AddRemove-BT Wireless Connection Manager - c:\program files\Common Files\Motive\InstallHelper.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-21 22:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1108)
c:\program files\f-secure internet security\hips\fshook32.dll
c:\windows\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(1172)
c:\windows\system32\relog_ap.dll
c:\program files\F-Secure Internet Security\FSPS\program\FSLSP.DLL
c:\program files\f-secure internet security\hips\fshook32.dll
.
Completion time: 2010-09-21 22:25:01
ComboFix-quarantined-files.txt 2010-09-21 21:24

Pre-Run: 64,585,949,184 bytes free
Post-Run: 65,120,129,024 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - E56FF93AE0C9586560CEB82264FCF4EE
Hi,

Please do the following


  • Open your Malwarebytes' Anti-Malware program and select the update tab, select update now
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.


NEXT


Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hi there, You were kindly helping me clean my PC of an infection and I had given you the logs of several scans you asked me to perform which were MBRCheck.exe, DDS, GMER Rootkit Scanner , Rootkit Unhooker and combofix. The next scan logs you asked for was Kaspersky online scanner and Malwarebytes. I have been away for weeks and therefore havnt touched my PC and so am hoping that these logs are still relevent and we can start where we left off? Thanks, Lorraine.
Hi Please re-run the MalwareBytes program and the On-line Kaspersky scan and post the logs How is the computer running? Are there any outstanding issues?
Hi there, sorry for the delay in replying. I've ran malwarebytes scan and Kaspersky on line scan and nothing was found buy either, but my pc is still exremely slow connecting to the internet.
Please do the following:

Download Flush Flash Cookies by Bobbi Flekman.
Select the Windows version and save flushflash.exe to your Desktop.
Double-click flushflash.exe to run it.
Select Everything but Site settings.
Click Make it so!.
When the "Killed off all Flash cookies" window opens, click OK.
Close Flush Flash Cookies.



clear all other cookies

Delete all currently saved cookies from your computer.

In Internet Explorer,
click Tools > Internet Options and then click the Delete Cookies button on the General tab.

In Firefox,
click Tools > Clear Recent History > Set Time range to clear to Everything
Click on the arrow next to Details to expand the list of history items.
Select Cookies and make sure that other items you want to keep are not selected.
Click Clear Now to clear the cookies and close the Clear Recent History window

NEXT

Please download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should reboot your machine, if not, manually reboot to ensure a complete clean

NEXT


Reset your Hosts file back to default

Use the 'fix-It" button on this microsoft site;

http://support.microsoft.com/kb/972034


NEXT

Download and run Auslogics Disc Defragmenter


Make sure when installing that you watch for, then say NO to the ASK toolbar.

Please let me know if that made any difference
Hi there, thanx for your continued support. I have ran the programs as requested and accessing web sites is still extremely slower than a mnth ago, my friend suggested using firefox as an experiment to see if i gained any speed and voila! speed of accessing pages in firefox is far supeererio to internet explorer……So I must have a problem with internet explorer as I had no problem with speed of loading pages before?? thanx again, Lorraine.
Hi

Reset IE back to default

http://support.microsoft.com/kb/923737

Use the "Fix It" button.

Let me know if that helps, then if there are no further issues, we can clean up our tools

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI