This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows Xp PC running slow

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
My Dell PC with Windows XP Home is running pretty slow.
Internet explorer seems to take forever to start, especially after the computer has either been shut down or logged off. Often I find it quickest to get on IE by clicking on it, waiting a little bit, closing it out and then clicking it again and selecting "Go to homepage" rather "restore last session.
For a while I was using the free version of Malware Bytes and was running scans in safemode. ( especially after one of my daughters would use the PC).
I now have the paid version of MalwareBytes loaded for realtime protection but things still aren't right.
My wife said that even Windows Office seems to be acting odd.
The last couple of MalwareBytes scans showed nothing but a scan with my TrendMicros showed "Java_Bytever.DM", "Java_Bytever.BG" and "Java_Bytefy.w" and for each one, it said "Scan Action Unsuccessful".

I would appreciate any help that can be offered on this.
I'm not sure if it matters but I did notice that the fan would seem to be constantly screaming away on this computer as if it were really hard but after we moved the Pc to the other side and installed the paid verision of MalwareBytes, the fan never seems to be sbreaming anymore.
I also tried opening an art file in Paint shop pro X and the computer really flipped out and couldn't handle it, though it opens fine in my laptop with the same amount of memory and slower processor.

anyway, sorry to ramble on, here is my Hijack This Log.
Thanks

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:52:02 PM, on 9/23/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\dleeserv.exe
C:\WINDOWS\system32\dleecoms.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Dell V715w\dleemon.exe
C:\Program Files\Dell V715w\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Shannon Bartram\My Documents\My Downloads\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://m.www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1080228
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Toolbar\toolband.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [dleemon.exe] "C:\Program Files\Dell V715w\dleemon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Dell V715w\ezprint.exe"
O4 - HKLM\..\Run: [Dell V715w Fax Server] "C:\Program Files\Dell V715w\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [DellAutomatedPCTuneUp] "C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" /startup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.mikesarcade.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} (Plaxo Auto-Import Utility) - https://www.plaxo.com/activex/plx_upldr-2k-xp.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: dleeCATSCustConnectService - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\dleeserv.exe
O23 - Service: dlee_device - - C:\WINDOWS\system32\dleecoms.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 12680 bytes
Hello mgb203 and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.


    Before we begin, I would like to take a closer look at your system.

    Please work your way through the following steps. If you encounter any difficulties come back and let me know.

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please post the DDS logs and the GMER log in your next reply :)
Hi Jon, Thank you very much for your response and help. I appreciate it. I was able to get use the DDS tool but the GMER scans did not work out. I followed the directions and opened the tool. I unchecked "IAT/EAT" as instructed and the "Show All" box was already unchecked. So any way, every time I would run the scan, first off it takes about 3 hours (I'm not sure if it should take that long or not) if it would make it all the way through the scan, it would lock up and I would have to retart the computer. I had PC-Cillin, malwareBytes and Windows Defender all disabled while running the scans. Also I forgot to post in my original post that I have also noticed that I can not manualy perform windows updates or windows defender updates on this computer. here is the DDS.txt: (and attached is the attach.txt) DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 0:07:28.70 on Sat 09/25/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.537 [GMT -4:00] AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5} FW: PC-cillin Internet Security - Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\dleeserv.exe C:\WINDOWS\system32\dleecoms.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Program Files\Dell V715w\dleemon.exe C:\Program Files\Dell V715w\ezprint.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Shannon Bartram\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://m.www.yahoo.com/ mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html uInternet Settings,ProxyServer = http=127.0.0.1:5555 uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - BHO: Dell Toolbar: {09b71986-2ac5-482d-b6cb-42ea34f4f85b} - c:\program files\dell toolbar\toolband.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll TB: Dell Toolbar: {09b71986-2ac5-482d-b6cb-42ea34f4f85b} - c:\program files\dell toolbar\toolband.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [DellAutomatedPCTuneUp] "c:\program files\dellautomatedpctuneup\PTAgnt.exe" /startup uRun: [OE_OEM] "c:\program files\trend micro\internet security 14\tmas_oe\TMAS_OEMon.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10h_ActiveX.exe -update activex mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe" mRun: [] mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe" mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe" mRun: [pccguide.exe] "c:\program files\trend micro\internet security 14\pccguide.exe" mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Alcmtr] ALCMTR.EXE mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [dleemon.exe] "c:\program files\dell v715w\dleemon.exe" mRun: [EzPrint] "c:\program files\dell v715w\ezprint.exe" mRun: [Dell V715w Fax Server] "c:\program files\dell v715w\fm3032.exe" /s mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Corel Photo Downloader] c:\program files\corel\corel photo album 6\MediaDetect.exe mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL Trusted Zone: mikesarcade.com\www Trusted Zone: plaxo.com\www DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo2.walgreens.com/WalgreensActivia.cab DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} - hxxps://www.plaxo.com/activex/plx_upldr-2k-xp.cab Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll ============= SERVICES / DRIVERS =============== R2 dlee_device;dlee_device;c:\windows\system32\dleecoms.exe -service –> c:\windows\system32\dleecoms.exe -service [?] R2 dleeCATSCustConnectService;dleeCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dleeserv.exe [2010-7-8 98984] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-8-27 304464] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2006-11-16 36368] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-8-27 20952] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2006-11-9 280392] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-30 135664] S2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\trendm~1\intern~1\Tmntsrv.exe [2006-12-15 345696] S2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2006-11-9 923216] S2 tmproxy;Trend Micro Proxy Service;c:\progra~1\trendm~1\intern~1\tmproxy.exe [2006-11-9 566872] S3 FoxAwdWINFLASH;FoxAwdWINFLASH;\??\c:\docume~1\shanno~1\locals~1\temp\_e8ac.tmp\foxawdwinflash.sys –> c:\docume~1\shanno~1\locals~1\temp\_e8ac.tmp\FoxAwdWINFLASH.sys [?] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-28 30192] S3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\drivers\KORGUMDS.SYS [2007-2-21 20696] =============== Created Last 30 ================ 2010-09-24 02:52:51 0 d—–w- C:\Hijack This 2010-09-02 11:54:41 0 dc-h–w- c:\windows\ie8 2010-08-27 21:40:03 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-08-27 21:40:01 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-08-27 21:40:01 0 d—–w- c:\program files\Malwarebytes' Anti-Malware ==================== Find3M ==================== 2010-07-12 21:25:34 60866 —-a-w- c:\windows\system32\KorgUnin.exe 2010-06-29 20:38:04 233472 —-a-w- c:\windows\system32\REX Shared Library.dll 2010-06-28 00:33:22 1682 –sha-w- c:\windows\system32\KGyGaAvL.sys 2008-08-26 12:51:01 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082620080827\index.dat ============= FINISH: 0:08:56.65 ===============

Attachments:

Hello mgb203

Thank you for the logs.

the GMER scans did not work out

This can sometimes happen when running GMER. It is very important that we have a completed ARK scan.

Lets try this:


  • GMER


    • If you are having trouble getting GMER to complete a scan, please run it again, but this time uncheck everything EXCEPT "Sections" and "C:\".
    • If GMER does not produce a log please try running it from Safe Mode.

    • How to use the F8 method to Start Your Computer in Safe Mode

    • Restart your computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
    • Use the arrow keys to select the Safe mode menu item.
    • Press Enter.

    • If GMER in safe mode does not work, please try Rootkit Unhooker:

  • Rootkit Unhooker


    • Please Download Rootkit Unhooker and Save it to your desktop.
    • Now double-click on RKUnhookerLE.exe to run it.
    • Click the Report tab, then click Scan.
    • Check (Tick) Drivers, Stealth. Uncheck the rest, then Click OK.
    • Wait till the scanner has finished and then click File, Save Report.
    • Save the report somewhere where you can find it. Click Close.

    Copy the entire contents of the report and paste it in your next reply here.

    Note: You may get the following warning, just click OK and continue.

    "Rootkit Unhooker has detected a parasite inside itself!
    It is recommended to remove parasite, okay?"


    Please provide the GMER/Rootkit Unhooker log in your next reply. If you are still having trouble, come back and let me know :)
Hi Jon,
Thanks again for all your help.
again when I ran the scan (this time with just sections and c drive checked) I got a blue screen crash.

So I was able to run a scan in safe mode.
here is the text file:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-26 14:42:19
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pwdoapod.sys


—- Kernel code sections - GMER 1.0.15 —-

.rsrc C:\WINDOWS\system32\DRIVERS\termdd.sys entry point in ".rsrc" section [0xF76CD214]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\svchost.exe[636] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0084000A
.text C:\WINDOWS\system32\svchost.exe[636] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0085000A
.text C:\WINDOWS\system32\svchost.exe[636] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 003D000C
.text C:\WINDOWS\system32\svchost.exe[636] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00FF000A
.text C:\WINDOWS\Explorer.EXE[952] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D5000A
.text C:\WINDOWS\Explorer.EXE[952] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00D6000A
.text C:\WINDOWS\Explorer.EXE[952] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00AB000C

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Fastfat \Fat F6AD8D20
Device -> \Driver\atapi \Device\Harddisk0\DR0 86E37EC5

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\DRIVERS\termdd.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hello mgb203

Thank you for the logs.

I now have the paid version of MalwareBytes loaded for realtime protection

The paid version of MalwareBytes provides real-time protection. You also have PC-cillin Internet Security which does the same thing.

It is not recommended to have more than one real-time antivirus running on your system as they can conflict with each other, causing slower system performance and leaving you open to infection.

Please make sure that you only have one real-time AV running on your system at any one time.

So I was able to run a scan in safe mode.

Great job. That scan has shown us exactly what we needed to see. Please do the following:


  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi Jon,
I ran the Combofix and have attached the text.

As far as the MalwareBytes / Pc-cillin thing goes, I thought that PC-Cillin was antivirus and MalwareBytes is anti spyware and I thought that you can run them together.
So would I be better off disabling the PC-Cillin or the MalwareBytes. would it be good to just disable the spyware portion of the PC-Cillin?
for right now I have MalwareBytes disabled.
thanks again.

here is the Combofix log:



ComboFix 10-09-25.07 - Shannon Bartram 09/26/2010 19:37:24.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.379 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: PC-cillin Internet Security - Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kailyn Bartram\Application Data\alot
c:\documents and settings\Shannon Bartram\GoToAssistDownloadHelper.exe
c:\documents and settings\Shannon Bartram\My Documents\DPE.DUS
c:\program files\Mozilla Firefox\searchplugins\google_search.xml
c:\windows\system32\tmp.reg

Infected copy of c:\windows\system32\drivers\termdd.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_6TO4


((((((((((((((((((((((((( Files Created from 2010-08-26 to 2010-09-26 )))))))))))))))))))))))))))))))
.

2010-09-26 23:13 . 2010-09-26 23:15 ——– d—–w- C:\32788R22FWJFW
2010-09-24 02:52 . 2010-09-24 02:53 ——– d—–w- C:\Hijack This
2010-09-02 11:54 . 2010-09-02 11:55 ——– dc-h–w- c:\windows\ie8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 10:55 . 2008-03-24 16:09 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-27 21:40 . 2010-08-27 21:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-23 01:32 . 2010-07-08 23:03 ——– d—–w- c:\program files\Dell V715w
2010-08-13 21:34 . 2010-07-12 21:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Ableton
2010-08-07 16:02 . 2010-08-07 16:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Dell V715w
2010-07-31 21:16 . 2010-07-31 21:16 ——– d—–w- c:\documents and settings\Kailyn Bartram\Application Data\V715w
2010-07-12 21:25 . 2010-07-12 21:25 60866 —-a-w- c:\windows\system32\KorgUnin.exe
2010-07-07 14:22 . 2010-07-07 14:22 0 —-a-w- c:\windows\system32\lsp7F.tmp
2010-06-29 20:38 . 2010-07-13 02:04 233472 —-a-w- c:\windows\system32\REX Shared Library.dll
2010-06-28 00:33 . 2010-04-30 21:34 1682 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-11-01 321040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-28 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-17 16132608]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2010-06-24 126976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"dleemon.exe"="c:\program files\Dell V715w\dleemon.exe" [2010-01-18 770728]
"EzPrint"="c:\program files\Dell V715w\ezprint.exe" [2010-01-18 139944]
"Dell V715w Fax Server"="c:\program files\Dell V715w\fm3032.exe" [2010-01-18 316072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-18 202256]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-02 106496]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-05-13 00:20 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi5"=KORGUMDD.DRV

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-01-05 19:38 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
2010-06-24 03:46 126976 —-a-w- c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2004-05-12 20:18 241664 —-a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-06-25 15:24 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 14:44 249856 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 14:44 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-17 01:21 28672 —-a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 14:00 1116920 —-a-w- c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-06-28 19:00 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-03-18 00:22 202256 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxWatchTray9.exe"=
"c:\\WINDOWS\\system32\\dleecoms.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6609:TCP"= 6609:TCP:spport
"7384:TCP"= 7384:TCP:spport
"14597:TCP"= 14597:TCP:spport
"17037:TCP"= 17037:TCP:spport
"25175:TCP"= 25175:TCP:spport
"29678:TCP"= 29678:TCP:spport
"8643:TCP"= 8643:TCP:spport
"5972:TCP"= 5972:TCP:spport
"19117:TCP"= 19117:TCP:spport
"13187:TCP"= 13187:TCP:spport
"26930:TCP"= 26930:TCP:spport
"13809:TCP"= 13809:TCP:spport
"8034:TCP"= 8034:TCP:spport
"26994:TCP"= 26994:TCP:spport

R2 dlee_device;dlee_device;c:\windows\system32\dleecoms.exe -service –> c:\windows\system32\dleecoms.exe -service [?]
R2 dleeCATSCustConnectService;dleeCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dleeserv.exe [7/8/2010 07:10 PM 98984]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/27/2010 05:40 PM 304464]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [12/15/2006 07:08 PM 345696]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [11/9/2006 04:03 PM 923216]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [11/16/2006 02:27 PM 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [11/9/2006 04:04 PM 566872]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 07:19 PM 13592]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/27/2010 05:40 PM 20952]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [11/9/2006 04:03 PM 280392]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:00 PM 135664]
S3 FoxAwdWINFLASH;FoxAwdWINFLASH;\??\c:\docume~1\SHANNO~1\LOCALS~1\Temp\_E8AC.tmp\FoxAwdWINFLASH.sys –> c:\docume~1\SHANNO~1\LOCALS~1\Temp\_E8AC.tmp\FoxAwdWINFLASH.sys [?]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2/28/2008 02:12 AM 30192]
S3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\drivers\KORGUMDS.SYS [2/21/2007 01:10 AM 20696]
.
Contents of the 'Scheduled Tasks' folder

2010-09-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]

2010-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 02:00]

2010-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 02:00]

2010-05-02 c:\windows\Tasks\HP DArC Task 2004-05-12 09:44ewlett-Packard2004-05-12 09:44p psc 2400 series0C415CBA1D36E12EF1F94B5BB45ACEE2494FF64E204487102.job
- c:\program files\HP\hpcoretech\comp\hpdarc.exe [2004-05-12 20:18]

2010-09-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2010-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1111041401-2239628166-2788164826-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1111041401-2239628166-2788164826-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1111041401-2239628166-2788164826-1009.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1111041401-2239628166-2788164826-1010.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-23 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1111041401-2239628166-2788164826-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1111041401-2239628166-2788164826-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-21 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1111041401-2239628166-2788164826-1009.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1111041401-2239628166-2788164826-1010.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-09-26 c:\windows\Tasks\WebReg 20080312081831.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2003-07-07 05:43]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://m.www.yahoo.com/
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uInternet Settings,ProxyServer = http=127.0.0.1:5555
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
Trusted Zone: mikesarcade.com\www
Trusted Zone: plaxo.com\www
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-dellsupportcenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
MSConfigStartUp-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
MSConfigStartUp-dscactivate - c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
MSConfigStartUp-SmileboxTray - c:\documents and settings\Shannon Bartram\Application Data\Smilebox\SmileboxTray.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-26 19:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(992)
c:\windows\system32\Ati2evxx.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll

- - - - - - - > 'explorer.exe'(7036)
c:\program files\Google\Quick Search Box\bin\1.2.1151.245\qsb.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dleecoms.exe
c:\progra~1\TRENDM~1\INTERN~1\PcCtlCom.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\TRENDM~1\INTERN~1\PccGuide.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.EXE
c:\windows\RTHDCPL.EXE
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Completion time: 2010-09-26 19:57:05 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-26 23:57

Pre-Run: 185,467,285,504 bytes free
Post-Run: 185,414,602,752 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - E7F68F2E9586BC53D2BF38748CFEAC14
Hello mgb203

Thank you for the log.

As far as the MalwareBytes / Pc-cillin thing goes, I thought that PC-Cillin was antivirus and MalwareBytes is anti spyware

MBAM is capable of removing many different types of Malware (one of which happens to be spyware).

The paid for version has real-time protection enabled and it is never a good idea to have more than one real-time facility running on your system. As for which one to use, you could experiment with each one enabled for a while and see which one works best for you (probably the best way).

We need to run ComboFix again but this time, we will be running it in a slightly different way.


  • Please work through the following steps


  • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
  • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
  • Copy and Paste the text in the quotebox below into the open Notepad window:

    File::
    c:\windows\system32\lsp7F.tmp

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    Trusted Zone: mikesarcade.com\www
    Trusted Zone: plaxo.com\www

    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "6609:TCP"=-
    "7384:TCP"=-
    "14597:TCP"=-
    "17037:TCP"=-
    "25175:TCP"=-
    "29678:TCP"=-
    "8643:TCP"=-
    "5972:TCP"=-
    "19117:TCP"=-
    "13187:TCP"=-
    "26930:TCP"=-
    "13809:TCP"=-
    "8034:TCP"=-
    "26994:TCP"=-

  • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
  • Close any open browsers.
  • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Refering to the picture below, drag CFScript.txt into ComboFix.exe

    [external image: Posted Image]

  • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • Once the log is produced, re-engage your resident anti virus.
Hey Jon, Here the log from the latest run on Combo fix. Thanks ComboFix 10-09-27.05 - Shannon Bartram 09/28/2010 21:30:37.2.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.454 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Shannon Bartram\Desktop\CFScript.txt AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5} FW: PC-cillin Internet Security - Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6} FILE :: "c:\windows\system32\lsp7F.tmp" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\lsp7F.tmp . ((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-29 ))))))))))))))))))))))))))))))) . 2010-09-29 00:07 . 2010-09-29 00:07 ——– d—–w- c:\windows\LastGood 2010-09-27 00:38 . 2010-09-27 00:38 ——– d—–w- c:\windows\system32\XPSViewer 2010-09-27 00:38 . 2010-09-27 00:38 ——– d—–w- c:\program files\MSBuild 2010-09-27 00:38 . 2010-09-27 00:38 ——– d—–w- c:\program files\Reference Assemblies 2010-09-27 00:38 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll 2010-09-27 00:37 . 2010-09-27 00:38 ——– d—–w- C:\dadbf3647a2dec149b3404 2010-09-27 00:37 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2010-09-27 00:37 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll 2010-09-27 00:37 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll 2010-09-27 00:37 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll 2010-09-27 00:37 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll 2010-09-27 00:37 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll 2010-09-27 00:37 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2010-09-27 00:37 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2010-09-27 00:01 . 2010-06-14 14:31 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe 2010-09-24 02:52 . 2010-09-24 02:53 ——– d—–w- C:\Hijack This 2010-09-02 11:54 . 2010-09-02 11:55 ——– dc-h–w- c:\windows\ie8 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-09-29 00:07 . 2009-10-06 12:10 ——– d—–w- c:\program files\Microsoft Silverlight 2010-09-27 01:05 . 2008-03-03 13:01 62840 —-a-w- c:\documents and settings\Shannon Bartram\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-09-27 00:24 . 2008-02-28 06:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-09-21 10:55 . 2008-03-24 16:09 1324 —-a-w- c:\windows\system32\d3d9caps.dat 2010-08-27 21:40 . 2010-08-27 21:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-08-23 01:32 . 2010-07-08 23:03 ——– d—–w- c:\program files\Dell V715w 2010-08-17 13:17 . 2004-08-10 17:51 58880 —-a-w- c:\windows\system32\spoolsv.exe 2010-08-13 21:34 . 2010-07-12 21:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Ableton 2010-08-07 16:02 . 2010-08-07 16:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Dell V715w 2010-07-31 21:16 . 2010-07-31 21:16 ——– d—–w- c:\documents and settings\Kailyn Bartram\Application Data\V715w 2010-07-22 15:49 . 2004-08-10 17:51 590848 —-a-w- c:\windows\system32\rpcrt4.dll 2010-07-22 05:57 . 2009-04-15 10:24 5120 —-a-w- c:\windows\system32\xpsp4res.dll 2010-07-12 21:25 . 2010-07-12 21:25 60866 —-a-w- c:\windows\system32\KorgUnin.exe 2010-07-12 21:25 . 2010-07-12 21:25 292878 —-a-r- c:\documents and settings\Shannon Bartram\Application Data\Microsoft\Installer\{72C308AF-9F98-4EBC-8F5A-6D0ADC5AB851}\NewShortcut6_504C9DBC7EE645B2A9CF47F39BEDA88E.exe 2010-07-12 21:25 . 2010-07-12 21:25 292878 —-a-r- c:\documents and settings\Shannon Bartram\Application Data\Microsoft\Installer\{72C308AF-9F98-4EBC-8F5A-6D0ADC5AB851}\NewShortcut2_C8CBC5632A224D2D83650A01AF12D5F6.exe 2010-07-12 21:25 . 2010-07-12 21:25 292878 —-a-r- c:\documents and settings\Shannon Bartram\Application Data\Microsoft\Installer\{72C308AF-9F98-4EBC-8F5A-6D0ADC5AB851}\NewShortcut1_F627668DCED74C3B92937B05B370A211.exe 2010-07-12 21:25 . 2010-07-12 21:25 292878 —-a-r- c:\documents and settings\Shannon Bartram\Application Data\Microsoft\Installer\{72C308AF-9F98-4EBC-8F5A-6D0ADC5AB851}\ARPPRODUCTICON.exe 2010-06-28 00:33 . 2010-04-30 21:34 1682 –sha-w- c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136] "OE_OEM"="c:\program files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-11-01 321040] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-28 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784] "pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960] "RTHDCPL"="RTHDCPL.EXE" [2007-07-17 16132608] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600] "Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2010-06-24 126976] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832] "dleemon.exe"="c:\program files\Dell V715w\dleemon.exe" [2010-01-18 770728] "EzPrint"="c:\program files\Dell V715w\ezprint.exe" [2010-01-18 139944] "Dell V715w Fax Server"="c:\program files\Dell V715w\fm3032.exe" [2010-01-18 316072] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-18 202256] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2008-05-13 00:20 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "midi5"=KORGUMDD.DRV [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] 2010-01-05 19:38 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box] 2010-06-24 03:46 126976 —-a-w- c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager] 2004-05-12 20:18 241664 —-a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2003-06-25 15:24 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] 2005-06-10 14:44 249856 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] 2005-06-10 14:44 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection] 2002-07-17 01:21 28672 —-a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-11-11 04:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc] 2006-08-17 14:00 1116920 —-a-w- c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2009-06-28 19:00 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2010-03-18 00:22 202256 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxWatchTray9.exe"= "c:\\WINDOWS\\system32\\dleecoms.exe"= R2 dlee_device;dlee_device;c:\windows\system32\dleecoms.exe -service –> c:\windows\system32\dleecoms.exe -service [?] R2 dleeCATSCustConnectService;dleeCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dleeserv.exe [7/8/2010 07:10 PM 98984] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/27/2010 05:40 PM 304464] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [11/16/2006 02:27 PM 36368] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 07:19 PM 13592] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/27/2010 05:40 PM 20952] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [11/9/2006 04:03 PM 280392] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:00 PM 135664] S2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [12/15/2006 07:08 PM 345696] S2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [11/9/2006 04:03 PM 923216] S2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [11/9/2006 04:04 PM 566872] S3 FoxAwdWINFLASH;FoxAwdWINFLASH;\??\c:\docume~1\SHANNO~1\LOCALS~1\Temp\_E8AC.tmp\FoxAwdWINFLASH.sys –> c:\docume~1\SHANNO~1\LOCALS~1\Temp\_E8AC.tmp\FoxAwdWINFLASH.sys [?] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2/28/2008 02:12 AM 30192] S3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\drivers\KORGUMDS.SYS [2/21/2007 01:10 AM 20696] . Contents of the 'Scheduled Tasks' folder 2010-09-22 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34] 2010-09-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 02:00] 2010-09-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 02:00] 2010-05-02 c:\windows\Tasks\HP DArC Task 2004-05-12 09:44ewlett-Packard2004-05-12 09:44p psc 2400 series0C415CBA1D36E12EF1F94B5BB45ACEE2494FF64E204487102.job - c:\program files\HP\hpcoretech\comp\hpdarc.exe [2004-05-12 20:18] 2010-09-28 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20] 2010-09-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-29 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1111041401-2239628166-2788164826-1007.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1111041401-2239628166-2788164826-1008.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1111041401-2239628166-2788164826-1009.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1111041401-2239628166-2788164826-1010.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-23 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-29 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1111041401-2239628166-2788164826-1007.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1111041401-2239628166-2788164826-1008.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-28 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1111041401-2239628166-2788164826-1009.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1111041401-2239628166-2788164826-1010.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09] 2010-09-28 c:\windows\Tasks\WebReg 20080312081831.job - c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2003-07-07 05:43] . . ——- Supplementary Scan ——- . uStart Page = hxxp://m.www.yahoo.com/ mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(992) c:\windows\system32\Ati2evxx.dll c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll . Completion time: 2010-09-28 21:39:20 ComboFix-quarantined-files.txt 2010-09-29 01:39 ComboFix2.txt 2010-09-26 23:57 Pre-Run: 183,455,858,688 bytes free Post-Run: 183,650,590,720 bytes free - - End Of File - - 1BBA96D8105312FD845E19BAC4395477
Hello mgb203

Thank you for the log :)

Please work your way through the following steps:


  • Clean out your temporary files


    • Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
    • Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
    • Check the boxes to the left of the following:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Java Cache

    • The rest are optional. If you want to remove everything check the "Select All" box.
    • Click on "Empty Selected" to begin cleaning.
    • Once the "Done Cleaning" message appears, click OK.
    • If you use Firefox, Click on the Firefox tab and repeat the above process.
    • When you have finished cleaning, click on the "Exit" button in the main menu.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform full scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please update your Java


    • Click on "Start", then on "Control Panel".
    • Go to "Add or Remove Programs" and uninstall any previous versions of Java that you find.
    • Reboot your computer.
    • Next, download the latest version of Java by clicking here
    • Scroll down the page until you reach "Java Platform Standard Edition".
    • Beneath this and to the right, you will see a button marked "Download JRE".
    • Click the "Download JRE" button.
    • Select the platform (Windows, in your case), multi language.
    • Accept the license agreement and click on "Continue".
    • You do not have to register if you do not want to (the registration step is optional).
    • Scroll down and click on the file called jre-6u21-windows-i586.exe located under "Windows Offline Installation".
    • Save the file to your desktop.
    • Do not select Run.
    • Double click on the saved file (jre-6u21-windows-i586.exe) to install the update.
    • Delete the downloaded installation file after completing the above procedure and reboot your system if not prompted to do so.

  • Please perform the following scan:


    • This is a very deep scan that can take many hours. In some instances you may need to let it run overnight. Please be patient.


    • It is recommended that you disable your onboard antivirus program and antispyware programs while performing scans to eliminate software conflicts and to speed up scan time.
    • DO NOT surf the net while your resident protection is disabled!
    • Once the scan is finished remember to re-enable your resident antivirus protection along with whatever antispyware applications you use.


    • Please perform a Kaspersky Online Scan of your computer by clicking here or here.


    • Click on the Accept button and install any components it needs.
    • The program will install and then begin downloading the latest definition files.
    • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
    • This will start the program and scan your system.
    • The scan will take a while, so be patient and let it run (at times it may appear to stall).
    • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

    • Once the scan is complete, click on View scan report. To obtain the report:
    • Click on: Save Report As
    • Next, in the Save as prompt, Save in area, select: Desktop
    • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:Text file [*.txt]
    • Then, click: Save
    • Please post the Kaspersky Online Scanner Report in your reply.
    • If you need help performing the above steps, an animated tutorial can be found here.

    Please post the MBAM log and the Kaspersky Online Scan log in your next reply :)
Hi Jon, I ran ATF cleaner and then did a MalwareBytes scan. There were no infections found: I will finish the other tasks and post tomorrow. thanks Here is the log Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4719 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 9/29/2010 11:03:26 PM mbam-log-2010-09-29 (23-03-26).txt Scan type: Full scan (C:\|) Objects scanned: 285165 Time elapsed: 1 hour(s), 1 minute(s), 58 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi Jon, I updated my Java and ran the Kaspersky scan report. Here is the report from that scan: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, September 30, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, September 29, 2010 19:57:47 Records in database: 4257860 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 138345 Threats found: 24 Infected objects found: 75 Suspicious objects found: 0 Scan duration: 02:36:01 File name / Threat / Threats count C:\Program Files\Trend Micro\Internet Security 14\Quarantine\173.tmp Infected: Trojan-Downloader.Win32.Agent.dcgt 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\44.tmp Infected: Trojan-Downloader.Java.Agent.ft 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\44.tmp Infected: Trojan-Downloader.Java.Agent.fu 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\44.tmp Infected: Trojan-Downloader.Java.Agent.fv 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\6.tmp Infected: Trojan-Downloader.Java.Agent.fx 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\6.tmp Infected: Exploit.Java.Agent.f 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\6.tmp Infected: Trojan-Downloader.Java.Agent.fy 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\6F.tmp Infected: Trojan.Java.Agent.ab 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\6F.tmp Infected: Trojan.Java.Agent.aa 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\6F.tmp Infected: Trojan.Java.Agent.ac 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\77.tmp Infected: not-a-virus:AdWare.Win32.BHO.mjb 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\77.tmp Infected: not-a-virus:AdWare.Win32.RON.eee 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\77.tmp Infected: Trojan.Win32.BHO.ahtk 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\77.tmp Infected: Trojan-Downloader.Win32.Agent.dwst 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\85.tmp Infected: Trojan-Clicker.Win32.VBiframe.car 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\87.tmp Infected: Trojan.Win32.Pincav.acdw 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\89.tmp Infected: Trojan-Downloader.Win32.Murlo.fwn 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\8C.tmp Infected: not-a-virus:AdWare.Win32.BHO.mfb 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\90.tmp Infected: not-a-virus:AdWare.Win32.RON.dvc 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\92.tmp Infected: Trojan.Win32.BHO.ahxc 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\94.tmp Infected: Trojan-Downloader.NSIS.Agent.go 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\96.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\98.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\9A.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\9C.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\9E.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\9F.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\A2.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\A4.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\A6.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\A8.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\AA.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\AC.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\AE.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\B0.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\B2.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\B4.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\B7.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\BA.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\Backup\A0097538.RB0 Infected: Virus.Win32.TDSS.b 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\BE.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\C0.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\C2.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\C4.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\C6.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\C8.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\CA.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\CC.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\CE.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\D0.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\D2.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\D4.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\D6.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\D8.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\DA.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\DC.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\DE.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\E0.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\E2.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\E4.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\E6.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\E8.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\EA.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\EC.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\EE.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\F0.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\F2.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\F4.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\F5.tmp Infected: Rootkit.Win32.Agent.bert 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\FA.tmp Infected: not-a-virus:AdWare.Win32.BHO.mfb 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\FA.tmp Infected: not-a-virus:AdWare.Win32.RON.dvc 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\FA.tmp Infected: Trojan.Win32.BHO.ahxc 1 C:\Program Files\Trend Micro\Internet Security 14\Quarantine\FA.tmp Infected: Trojan-Downloader.NSIS.Agent.go 1 C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\searchplugins\google_search.xml.vir Infected: Trojan.Win32.Clicker.hd 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\termdd.sys.vir Infected: Virus.Win32.TDSS.b 1 Selected area has been scanned. Thanks
Hello mgb203

Thank you for the logs.

The items detected by Kaspersky have been quarantined by your Trend Micro Internet Security suite and ComboFix.

Files stored in your Trend Micro quarantine cannot harm your system, but if you wish to delete them, you can find instructions on how to do so here: http://esupport.trendmicro.com/3/How-do-I-…t-Security.aspx

Provided you are no longer experiencing any problems, I think we are alomost done :)

Please work your way through the following steps:


  • Please Uninstall Combofix


    • Click on "Start" and then on "Run".
    • Now type combofix /uninstall in the run box and click "OK". Please note the space between the "x" and the "/Uninstall", it needs to be there.

  • Removal of Tools


    • You no longer need DDS or GMER. Please delete them from your system.


    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • Firefox is generally considered to have greater browsing security in comparison to other popular programs. You can download Firefox 3.0 from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.
Hey Jon, sorry it took a while for me to get back. Thanks for all the help. I will look into the list of tools. Things seem better with the system now. My Internet Explorer still starts slow but I need check my settings and all that. I currently have my MalwareBytes turned off (for experimenting) and my Pc-Cillin is on with windows firewall off Thanks again for all the help
Hello mgb203

sorry it took a while for me to get back.

No problem :)

Try a few different configurations with your security programs and see which one you prefer. Make sure you have one real time AV and one Firewall running at all times.

Thanks again for all the help

You are Very Welcome :)

Best wishes
JonTom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI