candi7
Topic Starter
Hello,
The other day I was on my computer, as usual, when all the sudden my computer froze. I couldn't do anything at all so I shut it down, well, i turned it off. When I turned it back on all I got was a black screen. I tried it a few times but kept getting a black screen. I had "backed up" my computer a couple weeks ago (as i do every couple weeks or so) using Macrium Reflect. When i first used Macrium, about 8 months ago, it had me make a Windows Boot disc. I put in the Windows Boot disc and was able to get my computer back up running but its slow and programs still freeze. I have Spyware Terminator, and I did a virus scan (i do a scan every day or more and it was fine the day before) and it came back telling me that I had a Trojan (I believe it was called GenericFF-1) that looked like it was in a few different places- about 10 or so files, some of which were–, (about 4 files in) System Volume Information\_restore_a bunch of numbers .exe & .rbf, (the rest were in files like) – OS\ROOT\XP_Pro_ENG(D)\I386\System32\SMSS.EXE, cmdcons\System32\SMSS.EXE, Windows\Erdnt\cache\explorer.exe, Windown\$hf_mig$\KB956572\SP3DR\pdh.dll, Desktop\my downloads\openofficeorg32(en-us)Installation files\redist\vcredist_x86.exe, All users\Start Menu\Programs\Accessories\System tools\Activate Windows.Ink and Windows\Installer\14ac6ec.msi. I just remembered that I moved those into Quarantine so I could get on the internet to get some help. I did another scan today and now it says I have 2 Trojans…. the first is "GenericFF-1" (I think its the same one that it said I had in the other scan, the one i put in quarantine) and it looks like its in about 5 of my System Volume Info. _restore files, the other is "Fakesec" and at first it looked like it was in a lot of my Gimp program files, since i don't use the Gimp program to much I decided to uninstall it hoping that would get rid of at least the one Trojan. I went into add/remove programs and removed it that way. Then I did another Spyware Terminator Virus scan and I still have the same 2 Trojans except the Fakesec Trojan that was in the Gimp files now moved into over 100 of my restore files. So, I still have both Trojans. I did a Spybot Search and Destroy scan and also a Malwarebytes scan but neither of them picked up the Trojans and said nothing was found.
I downloaded that DDS to get the reports but when I went to run the scan, it froze and then I couldn't close it. I opened the DDS again (with the other still opened, since it wouldn't close but it wasn't doing anything since it was frozen, I hope that's ok cuz its the only way I could do it) and did the scan but it only gave me 1 report, which is below –
DDS (Ver_10-12-12.02) - NTFSx86
Run by [removed] at 16:38:13.31 on Fri 02/04/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.565 [GMT -5:00]
AV: Spyware Terminator *Enabled/Updated* {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
============== Running Processes ===============
G:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
G:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.EXE
svchost.exe
G:\WINDOWS\system32\inetsrv\inetinfo.exe
G:\Program Files\Java\jre6\bin\jqs.exe
G:\WINDOWS\system32\lxctcoms.exe
G:\Program Files\CDBurnerXP\NMSAccessU.exe
G:\Program Files\Macrium\Reflect\ReflectService.exe
G:\WINDOWS\System32\snmp.exe
G:\Program Files\Spyware Terminator\sp_rsser.exe
G:\Program Files\System Protect\SysProtect_srv.exe
G:\WINDOWS\system32\svchost.exe -k imgsvc
G:\WINDOWS\system32\SearchIndexer.exe
G:\WINDOWS\system32\igfxtray.exe
G:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
G:\Program Files\System Protect\SysProtect_Tray.exe
G:\Program Files\Lexmark 5400 Series\lxctmon.exe
G:\Program Files\Common Files\Java\Java Update\jusched.exe
G:\Program Files\Lexmark 5400 Series\ezprint.exe
G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
G:\Program Files\Messenger\msmsgs.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
G:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
G:\Program Files\Windows Desktop Search\WindowsSearch.exe
G:\WINDOWS\System32\svchost.exe -k HTTPFilter
G:\Documents and Settings\Administrator\Local Settings\Temp\793.tmp\MBR.DAT
G:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.crawler.com/?tbid=60347
uURLSearchHooks: N/A: {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - g:\progra~1\crawler\toolbar\ctbr.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - g:\program files\lexmark toolbar\toolband.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - g:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - g:\progra~1\crawler\toolbar\ctbr.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - g:\progra~1\spybot - search & destroy\SDHelper.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - g:\program files\siber systems\ai roboform\roboform.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - g:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - g:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - g:\progra~1\crawler\toolbar\ctbr.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - g:\program files\siber systems\ai roboform\roboform.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - g:\program files\lexmark toolbar\toolband.dll
uRun: [SpywareTerminatorUpdate] "g:\program files\spyware terminator\SpywareTerminatorUpdate.exe"
uRun: [OnlineVault] "g:\program files\online vault\OnlineVault.exe" /startup
uRun: [SpybotSD TeaTimer] g:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [MSMSGS] "g:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] g:\windows\system32\ctfmon.exe
uRun: [RoboForm] "g:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
mRun: [IgfxTray] g:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] g:\windows\system32\hkcmd.exe
mRun: [SpywareTerminator] "g:\program files\spyware terminator\SpywareTerminatorShield.exe"
mRun: [SystemProtect] g:\program files\system protect\SysProtect_Tray.exe
mRun: [lxctmon.exe] "g:\program files\lexmark 5400 series\lxctmon.exe"
mRun: [Lexmark 5400 Series Fax Server] "g:\program files\lexmark 5400 series\fm3032.exe" /s
mRun: [LXCTCATS] rundll32 g:\windows\system32\spool\drivers\w32x86\3\LXCTtime.dll,_RunDLLEntry@16
mRun: [SunJavaUpdateSched] "g:\program files\common files\java\java update\jusched.exe"
mRun: [EzPrint] "g:\program files\lexmark 5400 series\ezprint.exe"
mRun: [Adobe Reader Speed Launcher] "g:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "g:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: g:\docume~1\alluse~1\startm~1\programs\startup\microsoft works calendar reminders.lnk - g:\program files\common files\microsoft shared\works shared\wkcalrem.exe
StartupFolder: g:\docume~1\alluse~1\startm~1\programs\startup\windows search.lnk - g:\program files\windows desktop search\WindowsSearch.exe
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: Crawler Search - tbr:iemenu
IE: Customize Menu - file://g:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - g:\progra~1\microsoft office\office12\EXCEL.EXE/3000
IE: Fill Forms - file://g:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://g:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://g:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - g:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - g:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - g:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FA32182A-EA44-4583-803B-AA827F0D4E06} - g:\progra~1\online~2\ONLINE~1.EXE
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - g:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - g:\progra~1\spybot - search & destroy\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1275797429265
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - g:\progra~1\crawler\toolbar\ctbr.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - g:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - g:\program files\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - g:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\avpujchl.default\
FF - component: g:\documents and settings\administrator\application data\mozilla\firefox\profiles\avpujchl.default\extensions\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}\components\FFExternalAlert.dll
FF - component: g:\documents and settings\administrator\application data\mozilla\firefox\profiles\avpujchl.default\extensions\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}\components\RadioWMPCore.dll
FF - component: g:\progra~1\crawler\firefox\components\xcomm.dll
FF - component: g:\progra~1\crawler\firefox\components\xshared.dll
FF - component: g:\progra~1\crawler\firefox\components\xsupport.dll
FF - component: g:\program files\siber systems\ai roboform\firefox\components\rfproxy_31.dll
FF - plugin: g:\documents and settings\administrator\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: g:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: g:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: g:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: g:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - g:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Crawler Toolbar: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - g:\progra~1\crawler\toolbar\firefox
FF - Ext: Java Quick Starter: [removed] - g:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: AI Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - g:\program files\siber systems\ai roboform\Firefox
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: PriceBlink: [removed] - %profile%\extensions\[removed]
FF - Ext: United States English Spellchecker: [removed] - %profile%\extensions\[removed]
FF - Ext: Free TV Bar c3 Toolbar: {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - %profile%\extensions\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}
FF - Ext: Amazon Wish List: [removed] - %profile%\extensions\[removed]
FF - Ext: Christmas Boom: [removed] - %profile%\extensions\[removed]
FF - Ext: Surf Canyon - Search Engine Assistant: {75623d5d-4683-402a-b610-ac4bab767c86} - %profile%\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
============= SERVICES / DRIVERS ===============
R0 pssnap;Paramount Software Snapshot Filter;g:\windows\system32\drivers\pssnap.sys [2010-9-28 15328]
R1 sp_rsdrv2;Spyware Terminator Driver 2;g:\windows\system32\drivers\sp_rsdrv2.sys [2010-6-5 142592]
R2 ReflectService;Macrium Reflect Image Mounting Service;g:\program files\macrium\reflect\ReflectService.exe [2010-9-28 220128]
R2 SP_Service;System Protect Deletion Prevention Service;g:\program files\system protect\SysProtect_srv.exe [2010-6-5 598528]
R3 sp_prot;System Protect Filter Driver;g:\windows\system32\drivers\sp_prot.sys [2010-6-5 12288]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;g:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 cpudrv;cpudrv;g:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 DfSdkS;Defragmentation-Service;g:\program files\ashampoo\ashampoo winoptimizer 2010 advanced\DfSdkS.exe [2010-6-20 406016]
S3 PSMounter;Macrium Reflect Image Explorer Service;g:\windows\system32\drivers\psmounter.sys [2010-9-28 44512]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;g:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
==================== Find3M ====================
2010-12-13 20:14:51 103720 —-a-w- g:\documents and settings\administrator\GoToAssistDownloadHelper.exe
2010-11-18 18:12:44 81920 —-a-w- g:\windows\system32\isign32.dll
2010-11-12 23:53:06 472808 —-a-w- g:\windows\system32\deployJava1.dll
2010-11-12 21:34:10 73728 —-a-w- g:\windows\system32\javacpl.cpl
2010-11-09 14:52:35 249856 —-a-w- g:\windows\system32\odbc32.dll
2010-11-08 05:13:25 796672 —-a-w- g:\windows\GPInstall.exe
============= FINISH: 16:38:46.78 ===============
I'm not sure if I should take those one's out of quarantine or if I should leave them in there or if I should delete them. Could you please tell me what I should do, please? I had to put them in Quarantine or I couldn't get on the internet but if you give me something to get rid of the viruses I should probably take them out so I can get rid of the viruses in those file, too, right? Are they important files that I really need ( they look like they probably are) but if they aren't should I just delete them? I don't want to do anything without knowing what to do because I don't want to mess my computer up even more. If you could please help me, I would really, really appreciate it.
Thank you very much,
Candi
The other day I was on my computer, as usual, when all the sudden my computer froze. I couldn't do anything at all so I shut it down, well, i turned it off. When I turned it back on all I got was a black screen. I tried it a few times but kept getting a black screen. I had "backed up" my computer a couple weeks ago (as i do every couple weeks or so) using Macrium Reflect. When i first used Macrium, about 8 months ago, it had me make a Windows Boot disc. I put in the Windows Boot disc and was able to get my computer back up running but its slow and programs still freeze. I have Spyware Terminator, and I did a virus scan (i do a scan every day or more and it was fine the day before) and it came back telling me that I had a Trojan (I believe it was called GenericFF-1) that looked like it was in a few different places- about 10 or so files, some of which were–, (about 4 files in) System Volume Information\_restore_a bunch of numbers .exe & .rbf, (the rest were in files like) – OS\ROOT\XP_Pro_ENG(D)\I386\System32\SMSS.EXE, cmdcons\System32\SMSS.EXE, Windows\Erdnt\cache\explorer.exe, Windown\$hf_mig$\KB956572\SP3DR\pdh.dll, Desktop\my downloads\openofficeorg32(en-us)Installation files\redist\vcredist_x86.exe, All users\Start Menu\Programs\Accessories\System tools\Activate Windows.Ink and Windows\Installer\14ac6ec.msi. I just remembered that I moved those into Quarantine so I could get on the internet to get some help. I did another scan today and now it says I have 2 Trojans…. the first is "GenericFF-1" (I think its the same one that it said I had in the other scan, the one i put in quarantine) and it looks like its in about 5 of my System Volume Info. _restore files, the other is "Fakesec" and at first it looked like it was in a lot of my Gimp program files, since i don't use the Gimp program to much I decided to uninstall it hoping that would get rid of at least the one Trojan. I went into add/remove programs and removed it that way. Then I did another Spyware Terminator Virus scan and I still have the same 2 Trojans except the Fakesec Trojan that was in the Gimp files now moved into over 100 of my restore files. So, I still have both Trojans. I did a Spybot Search and Destroy scan and also a Malwarebytes scan but neither of them picked up the Trojans and said nothing was found.
I downloaded that DDS to get the reports but when I went to run the scan, it froze and then I couldn't close it. I opened the DDS again (with the other still opened, since it wouldn't close but it wasn't doing anything since it was frozen, I hope that's ok cuz its the only way I could do it) and did the scan but it only gave me 1 report, which is below –
DDS (Ver_10-12-12.02) - NTFSx86
Run by [removed] at 16:38:13.31 on Fri 02/04/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.565 [GMT -5:00]
AV: Spyware Terminator *Enabled/Updated* {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
============== Running Processes ===============
G:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
G:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.EXE
svchost.exe
G:\WINDOWS\system32\inetsrv\inetinfo.exe
G:\Program Files\Java\jre6\bin\jqs.exe
G:\WINDOWS\system32\lxctcoms.exe
G:\Program Files\CDBurnerXP\NMSAccessU.exe
G:\Program Files\Macrium\Reflect\ReflectService.exe
G:\WINDOWS\System32\snmp.exe
G:\Program Files\Spyware Terminator\sp_rsser.exe
G:\Program Files\System Protect\SysProtect_srv.exe
G:\WINDOWS\system32\svchost.exe -k imgsvc
G:\WINDOWS\system32\SearchIndexer.exe
G:\WINDOWS\system32\igfxtray.exe
G:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
G:\Program Files\System Protect\SysProtect_Tray.exe
G:\Program Files\Lexmark 5400 Series\lxctmon.exe
G:\Program Files\Common Files\Java\Java Update\jusched.exe
G:\Program Files\Lexmark 5400 Series\ezprint.exe
G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
G:\Program Files\Messenger\msmsgs.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
G:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
G:\Program Files\Windows Desktop Search\WindowsSearch.exe
G:\WINDOWS\System32\svchost.exe -k HTTPFilter
G:\Documents and Settings\Administrator\Local Settings\Temp\793.tmp\MBR.DAT
G:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.crawler.com/?tbid=60347
uURLSearchHooks: N/A: {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - g:\progra~1\crawler\toolbar\ctbr.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - g:\program files\lexmark toolbar\toolband.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - g:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - g:\progra~1\crawler\toolbar\ctbr.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - g:\progra~1\spybot - search & destroy\SDHelper.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - g:\program files\siber systems\ai roboform\roboform.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - g:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - g:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - g:\progra~1\crawler\toolbar\ctbr.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - g:\program files\siber systems\ai roboform\roboform.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - g:\program files\lexmark toolbar\toolband.dll
uRun: [SpywareTerminatorUpdate] "g:\program files\spyware terminator\SpywareTerminatorUpdate.exe"
uRun: [OnlineVault] "g:\program files\online vault\OnlineVault.exe" /startup
uRun: [SpybotSD TeaTimer] g:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [MSMSGS] "g:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] g:\windows\system32\ctfmon.exe
uRun: [RoboForm] "g:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
mRun: [IgfxTray] g:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] g:\windows\system32\hkcmd.exe
mRun: [SpywareTerminator] "g:\program files\spyware terminator\SpywareTerminatorShield.exe"
mRun: [SystemProtect] g:\program files\system protect\SysProtect_Tray.exe
mRun: [lxctmon.exe] "g:\program files\lexmark 5400 series\lxctmon.exe"
mRun: [Lexmark 5400 Series Fax Server] "g:\program files\lexmark 5400 series\fm3032.exe" /s
mRun: [LXCTCATS] rundll32 g:\windows\system32\spool\drivers\w32x86\3\LXCTtime.dll,_RunDLLEntry@16
mRun: [SunJavaUpdateSched] "g:\program files\common files\java\java update\jusched.exe"
mRun: [EzPrint] "g:\program files\lexmark 5400 series\ezprint.exe"
mRun: [Adobe Reader Speed Launcher] "g:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "g:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: g:\docume~1\alluse~1\startm~1\programs\startup\microsoft works calendar reminders.lnk - g:\program files\common files\microsoft shared\works shared\wkcalrem.exe
StartupFolder: g:\docume~1\alluse~1\startm~1\programs\startup\windows search.lnk - g:\program files\windows desktop search\WindowsSearch.exe
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: Crawler Search - tbr:iemenu
IE: Customize Menu - file://g:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - g:\progra~1\microsoft office\office12\EXCEL.EXE/3000
IE: Fill Forms - file://g:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://g:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://g:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - g:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - g:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - g:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FA32182A-EA44-4583-803B-AA827F0D4E06} - g:\progra~1\online~2\ONLINE~1.EXE
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - g:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - g:\progra~1\spybot - search & destroy\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1275797429265
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - g:\progra~1\crawler\toolbar\ctbr.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - g:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - g:\program files\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - g:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\avpujchl.default\
FF - component: g:\documents and settings\administrator\application data\mozilla\firefox\profiles\avpujchl.default\extensions\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}\components\FFExternalAlert.dll
FF - component: g:\documents and settings\administrator\application data\mozilla\firefox\profiles\avpujchl.default\extensions\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}\components\RadioWMPCore.dll
FF - component: g:\progra~1\crawler\firefox\components\xcomm.dll
FF - component: g:\progra~1\crawler\firefox\components\xshared.dll
FF - component: g:\progra~1\crawler\firefox\components\xsupport.dll
FF - component: g:\program files\siber systems\ai roboform\firefox\components\rfproxy_31.dll
FF - plugin: g:\documents and settings\administrator\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: g:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: g:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: g:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: g:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - g:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Crawler Toolbar: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - g:\progra~1\crawler\toolbar\firefox
FF - Ext: Java Quick Starter: [removed] - g:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: AI Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - g:\program files\siber systems\ai roboform\Firefox
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: PriceBlink: [removed] - %profile%\extensions\[removed]
FF - Ext: United States English Spellchecker: [removed] - %profile%\extensions\[removed]
FF - Ext: Free TV Bar c3 Toolbar: {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - %profile%\extensions\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}
FF - Ext: Amazon Wish List: [removed] - %profile%\extensions\[removed]
FF - Ext: Christmas Boom: [removed] - %profile%\extensions\[removed]
FF - Ext: Surf Canyon - Search Engine Assistant: {75623d5d-4683-402a-b610-ac4bab767c86} - %profile%\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
============= SERVICES / DRIVERS ===============
R0 pssnap;Paramount Software Snapshot Filter;g:\windows\system32\drivers\pssnap.sys [2010-9-28 15328]
R1 sp_rsdrv2;Spyware Terminator Driver 2;g:\windows\system32\drivers\sp_rsdrv2.sys [2010-6-5 142592]
R2 ReflectService;Macrium Reflect Image Mounting Service;g:\program files\macrium\reflect\ReflectService.exe [2010-9-28 220128]
R2 SP_Service;System Protect Deletion Prevention Service;g:\program files\system protect\SysProtect_srv.exe [2010-6-5 598528]
R3 sp_prot;System Protect Filter Driver;g:\windows\system32\drivers\sp_prot.sys [2010-6-5 12288]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;g:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 cpudrv;cpudrv;g:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 DfSdkS;Defragmentation-Service;g:\program files\ashampoo\ashampoo winoptimizer 2010 advanced\DfSdkS.exe [2010-6-20 406016]
S3 PSMounter;Macrium Reflect Image Explorer Service;g:\windows\system32\drivers\psmounter.sys [2010-9-28 44512]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;g:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
==================== Find3M ====================
2010-12-13 20:14:51 103720 —-a-w- g:\documents and settings\administrator\GoToAssistDownloadHelper.exe
2010-11-18 18:12:44 81920 —-a-w- g:\windows\system32\isign32.dll
2010-11-12 23:53:06 472808 —-a-w- g:\windows\system32\deployJava1.dll
2010-11-12 21:34:10 73728 —-a-w- g:\windows\system32\javacpl.cpl
2010-11-09 14:52:35 249856 —-a-w- g:\windows\system32\odbc32.dll
2010-11-08 05:13:25 796672 —-a-w- g:\windows\GPInstall.exe
============= FINISH: 16:38:46.78 ===============
I'm not sure if I should take those one's out of quarantine or if I should leave them in there or if I should delete them. Could you please tell me what I should do, please? I had to put them in Quarantine or I couldn't get on the internet but if you give me something to get rid of the viruses I should probably take them out so I can get rid of the viruses in those file, too, right? Are they important files that I really need ( they look like they probably are) but if they aren't should I just delete them? I don't want to do anything without knowing what to do because I don't want to mess my computer up even more. If you could please help me, I would really, really appreciate it.
Thank you very much,
Candi