This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

urlfraudcheck redirect

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the combo fix log:

ComboFix 11-02-13.01 - Administrator 02/13/2011 19:22:12.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1217 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Security Suite *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Application Data\completescan
c:\documents and settings\Administrator\Application Data\install
c:\documents and settings\Administrator\Recent\Thumbs.db
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job

.
((((((((((((((((((((((((( Files Created from 2011-01-14 to 2011-02-14 )))))))))))))))))))))))))))))))
.

2011-02-14 00:34 . 2011-02-14 00:34 ——– d—–w- c:\windows\LastGood
2011-02-13 16:13 . 2011-02-13 16:13 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-13 16:13 . 2011-02-13 16:13 ——– d—–w- c:\program files\Trend Micro
2011-02-13 16:09 . 2011-02-13 16:09 ——– d—–w- c:\program files\Conduit
2011-02-13 16:09 . 2011-02-13 16:17 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Soft32
2011-02-13 16:04 . 2011-02-13 16:09 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
2011-02-13 16:04 . 2011-02-13 16:04 ——– d—–w- c:\program files\Soft32
2011-02-13 16:04 . 2011-02-13 16:04 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2011-02-13 16:01 . 2011-02-13 16:04 ——– d—–w- c:\documents and settings\Administrator\Application Data\GetRightToGo
2011-02-13 01:59 . 2011-02-13 02:06 ——– d—–w- c:\program files\Windows Live Safety Center
2011-01-17 01:57 . 2011-01-17 01:57 ——– d—–w- c:\documents and settings\Default User\Application Data\Apple Computer
2011-01-17 01:55 . 2011-01-17 01:57 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Apple Computer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 01:09 . 2010-11-08 20:29 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 01:08 . 2010-11-08 20:29 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-11-30 00:38 . 2010-11-30 00:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-30 00:38 . 2010-11-30 00:38 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-11-27 01:51 . 2010-11-27 01:51 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2010-11-27 01:51 . 2010-11-27 01:51 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-11-26 23:16 . 2010-11-26 23:16 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{d1fce654-5fd1-48ad-b13c-5064736120b7}"= "c:\program files\Soft32\prxtbSoft.dll" [2011-01-03 175400]

[HKEY_CLASSES_ROOT\clsid\{d1fce654-5fd1-48ad-b13c-5064736120b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-03 17:16 175400 —-a-w- c:\program files\ConduitEngine\prxConduitEngine.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1fce654-5fd1-48ad-b13c-5064736120b7}]
2011-01-03 17:16 175400 —-a-w- c:\program files\Soft32\prxtbSoft.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d1fce654-5fd1-48ad-b13c-5064736120b7}"= "c:\program files\Soft32\prxtbSoft.dll" [2011-01-03 175400]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-03 175400]

[HKEY_CLASSES_ROOT\clsid\{d1fce654-5fd1-48ad-b13c-5064736120b7}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D1FCE654-5FD1-48AD-B13C-5064736120B7}"= "c:\program files\Soft32\prxtbSoft.dll" [2011-01-03 175400]

[HKEY_CLASSES_ROOT\clsid\{d1fce654-5fd1-48ad-b13c-5064736120b7}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"PMX Daemon"="ICO.EXE" [2006-06-09 47104]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2008-06-05 125208]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-23 176128]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"lxdqmon.exe"="c:\program files\Lexmark Z2400 Series\lxdqmon.exe" [2008-03-27 656040]
"lxdqamon"="c:\program files\Lexmark Z2400 Series\lxdqamon.exe" [2008-03-27 16040]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-15 47904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-14 421160]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Philips Device Manager.lnk - c:\program files\Philips\GoGear Mix Device Manager\main.exe [2009-12-25 124816]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\lxdqcoms.exe"=
"c:\\Program Files\\Lexmark Z2400 Series\\lxdqmon.exe"=
"c:\\WINDOWS\\system32\\lxdqcfg.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdqpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdqtime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdqjswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdqwbgw.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [1/2/2008 17:02 3456]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0403000.005\symds.sys [11/27/2010 10:12 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0403000.005\symefa.sys [11/27/2010 10:12 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101123.003\BHDrvx86.sys [11/22/2010 19:20 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0403000.005\cchpx86.sys [11/27/2010 10:12 501888]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41 67656]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0403000.005\ironx86.sys [11/27/2010 10:12 116784]
R2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe -service –> c:\windows\system32\lxdqcoms.exe -service [?]
R2 lxdqCATSCustConnectService;lxdqCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdqserv.exe [4/28/2009 08:58 94208]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe [11/27/2010 10:11 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [11/26/2010 23:59 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110211.002\IDSXpx86.sys [2/11/2011 21:15 341944]
S0 icvajr;icvajr; [x]
S0 khqlmxop;khqlmxop;c:\windows\system32\drivers\oopuhnpkpjv.sys –> c:\windows\system32\drivers\oopuhnpkpjv.sys [?]
S0 sxmwgcxzwratw;sxmwgcxzwratw;c:\windows\system32\drivers\culed.sys –> c:\windows\system32\drivers\culed.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-11-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-07-31 c:\windows\Tasks\expressburnShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-07-24 17:32]

2010-07-31 c:\windows\Tasks\expressripShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressRip\expressrip.exe [2010-07-24 17:33]

2011-01-24 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2010-07-24 17:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\
FF - prefs.js: browser.search.selectedEngine - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.myyahoo.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Soft32 Community Toolbar: {d1fce654-5fd1-48ad-b13c-5064736120b7} - %profile%\extensions\{d1fce654-5fd1-48ad-b13c-5064736120b7}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn
FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-SigmatelSysTrayApp - %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-13 19:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\4.3.0.5\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1454471165-1563985344-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ac,d5,83,6b,0f,b4,80,47,b2,6d,ff,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3d,54,23,62,b0,5f,d5,4d,8f,3e,d4,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ab,22,6a,3d,5a,3f,e3,40,a7,fb,70,\

[HKEY_USERS\S-1-5-21-1454471165-1563985344-725345543-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(680)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2011-02-13 19:34:38
ComboFix-quarantined-files.txt 2011-02-14 02:34

Pre-Run: 28,226,297,856 bytes free
Post-Run: 31,843,692,544 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - FE2FD426232C6BC3915F19946FE358E6
COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File:: 
    c:\windows\system32\drivers\oopuhnpkpjv.sys 
    c:\windows\system32\drivers\culed.sys
    
    
    Driver:: 
    icvajr
    khqlmxop
    sxmwgcxzwratw
    
    RegLock::
    [HKEY_USERS\S-1-5-21-1454471165-1563985344-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
    
    RegNull::
    [HKEY_USERS\S-1-5-21-1454471165-1563985344-725345543-500\Software\Microsoft\SystemCertificates\AddressBook*]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.










Next


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.



Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Here is the last combofix log:

ComboFix 11-02-13.01 - Administrator 02/13/2011 21:15:55.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1235 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: Norton Security Suite *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

FILE ::
"c:\windows\system32\drivers\culed.sys"
"c:\windows\system32\drivers\oopuhnpkpjv.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_icvajr
——-\Service_khqlmxop
——-\Service_sxmwgcxzwratw


((((((((((((((((((((((((( Files Created from 2011-01-14 to 2011-02-14 )))))))))))))))))))))))))))))))
.

2011-02-14 00:37 . 2010-11-02 15:17 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys
2011-02-14 00:33 . 2010-10-11 14:59 45568 -c—-w- c:\windows\system32\dllcache\wab.exe
2011-02-13 16:13 . 2011-02-13 16:13 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-13 16:13 . 2011-02-13 16:13 ——– d—–w- c:\program files\Trend Micro
2011-02-13 16:09 . 2011-02-13 16:09 ——– d—–w- c:\program files\Conduit
2011-02-13 16:09 . 2011-02-13 16:17 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Soft32
2011-02-13 16:04 . 2011-02-13 16:09 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
2011-02-13 16:04 . 2011-02-13 16:04 ——– d—–w- c:\program files\Soft32
2011-02-13 16:04 . 2011-02-13 16:04 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2011-02-13 16:01 . 2011-02-13 16:04 ——– d—–w- c:\documents and settings\Administrator\Application Data\GetRightToGo
2011-02-13 01:59 . 2011-02-13 02:06 ——– d—–w- c:\program files\Windows Live Safety Center
2011-01-21 14:44 . 2011-01-21 14:44 439296 -c—-w- c:\windows\system32\dllcache\shimgvw.dll
2011-01-17 01:57 . 2011-01-17 01:57 ——– d—–w- c:\documents and settings\Default User\Application Data\Apple Computer
2011-01-17 01:55 . 2011-01-17 01:57 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Apple Computer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2006-03-15 12:00 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2006-03-15 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2006-03-15 12:00 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2006-03-15 12:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-21 01:09 . 2010-11-08 20:29 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 01:08 . 2010-11-08 20:29 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 23:59 . 2006-03-15 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2006-03-15 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59 . 2006-03-15 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26 . 2006-03-15 12:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2006-03-15 12:00 385024 —-a-w- c:\windows\system32\html.iec
2010-12-09 15:15 . 2006-03-15 12:00 718336 —-a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2006-03-15 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:42 . 2006-03-15 12:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2004-08-03 22:59 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-11-30 00:38 . 2010-11-30 00:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-30 00:38 . 2010-11-30 00:38 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-11-27 01:51 . 2010-11-27 01:51 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2010-11-27 01:51 . 2010-11-27 01:51 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-11-26 23:16 . 2010-11-26 23:16 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-11-18 18:12 . 2008-01-02 22:44 81920 —-a-w- c:\windows\system32\isign32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{d1fce654-5fd1-48ad-b13c-5064736120b7}"= "c:\program files\Soft32\prxtbSoft.dll" [2011-01-03 175400]

[HKEY_CLASSES_ROOT\clsid\{d1fce654-5fd1-48ad-b13c-5064736120b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-03 17:16 175400 —-a-w- c:\program files\ConduitEngine\prxConduitEngine.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1fce654-5fd1-48ad-b13c-5064736120b7}]
2011-01-03 17:16 175400 —-a-w- c:\program files\Soft32\prxtbSoft.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d1fce654-5fd1-48ad-b13c-5064736120b7}"= "c:\program files\Soft32\prxtbSoft.dll" [2011-01-03 175400]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-03 175400]

[HKEY_CLASSES_ROOT\clsid\{d1fce654-5fd1-48ad-b13c-5064736120b7}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D1FCE654-5FD1-48AD-B13C-5064736120B7}"= "c:\program files\Soft32\prxtbSoft.dll" [2011-01-03 175400]

[HKEY_CLASSES_ROOT\clsid\{d1fce654-5fd1-48ad-b13c-5064736120b7}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"PMX Daemon"="ICO.EXE" [2006-06-09 47104]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2008-06-05 125208]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-23 176128]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"lxdqmon.exe"="c:\program files\Lexmark Z2400 Series\lxdqmon.exe" [2008-03-27 656040]
"lxdqamon"="c:\program files\Lexmark Z2400 Series\lxdqamon.exe" [2008-03-27 16040]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-15 47904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-14 421160]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Philips Device Manager.lnk - c:\program files\Philips\GoGear Mix Device Manager\main.exe [2009-12-25 124816]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\lxdqcoms.exe"=
"c:\\Program Files\\Lexmark Z2400 Series\\lxdqmon.exe"=
"c:\\WINDOWS\\system32\\lxdqcfg.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdqpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdqtime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdqjswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdqwbgw.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [1/2/2008 17:02 3456]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0403000.005\symds.sys [11/27/2010 10:12 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0403000.005\symefa.sys [11/27/2010 10:12 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101123.003\BHDrvx86.sys [11/22/2010 19:20 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0403000.005\cchpx86.sys [11/27/2010 10:12 501888]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41 67656]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0403000.005\ironx86.sys [11/27/2010 10:12 116784]
R2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe -service –> c:\windows\system32\lxdqcoms.exe -service [?]
R2 lxdqCATSCustConnectService;lxdqCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdqserv.exe [4/28/2009 08:58 94208]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe [11/27/2010 10:11 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [11/26/2010 23:59 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110211.002\IDSXpx86.sys [2/11/2011 21:15 341944]
.
Contents of the 'Scheduled Tasks' folder

2010-11-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-07-31 c:\windows\Tasks\expressburnShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-07-24 17:32]

2010-07-31 c:\windows\Tasks\expressripShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressRip\expressrip.exe [2010-07-24 17:33]

2011-01-24 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2010-07-24 17:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\
FF - prefs.js: browser.search.selectedEngine - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.myyahoo.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Soft32 Community Toolbar: {d1fce654-5fd1-48ad-b13c-5064736120b7} - %profile%\extensions\{d1fce654-5fd1-48ad-b13c-5064736120b7}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn
FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-13 21:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\4.3.0.5\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1454471165-1563985344-725345543-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(680)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(2852)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\lxdqcoms.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\SearchProtocolHost.exe
c:\windows\system32\ICO.EXE
c:\windows\eHome\ehmsas.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\program files\Lexmark Z2400 Series\lxdqMsdMon.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Completion time: 2011-02-13 21:34:17 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-14 04:34
ComboFix2.txt 2011-02-14 02:34

Pre-Run: 32,219,619,328 bytes free
Post-Run: 32,050,130,944 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 8EB7A57FB4660B6DA60C3F382F2BFC78
Malware log is as follows: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5758 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 2/13/2011 21:51:07 mbam-log-2011-02-13 (21-51-07).txt Scan type: Quick scan Objects scanned: 143301 Time elapsed: 3 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
I just did the eset and it found and removed 27 threats. But I didn't hit the details tab before the window closed. I can't find the txt.log? Do I have to re-run the whole scan? I didn't realize it was a a one shot log… Thank you again for all your help!! Kitten
This is the latest, OTL log. My computer is running like a champ. In fact it is running better than it has in 6 months or better….. I finally got 18 Windows updates I'd been trying to get for months that had been being blocked from me. Words cannot express how grateful I am. I've turned it it off and on a few times. When I woke up this morning, even after "snoozing" ..it woke up like a nice kitty and went right back on the internet like I asked it, instead of needing me to reboot it because it couldn't connect! I'm so thrilled, words are not enough. I guess I know where to come back to! I guess I could have gone to a shop but I'm too stubborn, cheap and tenacious…lol.

You are amazing! When I have the "all clear", stop my bugging of you with my tech ignorance(Where does the file go?), but I surely appreciate all your help!!!!!!
Kitten





OTL logfile created on: 2/14/2011 06:39:26 - Run 3
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 29.80 Gb Free Space | 39.98% Space Free | Partition Type: NTFS
Drive E: | 243.69 Mb Total Space | 118.16 Mb Free Space | 48.49% Space Free | Partition Type: FAT

Computer Name: OWNER-0520282D7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/14 06:38:25 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/02/25 17:21:50 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe
PRC - [2010/01/13 08:49:21 | 000,124,816 | —- | M] (KeenHigh Tech.) – C:\Program Files\Philips\GoGear Mix Device Manager\main.exe
PRC - [2009/05/21 11:13:58 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/28 08:58:26 | 000,094,208 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqserv.exe
PRC - [2009/02/03 06:15:18 | 000,111,856 | —- | M] (Yahoo! Inc) – C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/06/05 15:06:32 | 000,125,208 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/03/27 08:04:22 | 000,025,256 | —- | M] () – C:\Program Files\Lexmark Z2400 Series\lxdqmsdmon.exe
PRC - [2008/02/27 16:09:44 | 000,594,600 | —- | M] ( ) – C:\WINDOWS\system32\lxdqcoms.exe
PRC - [2006/06/09 12:47:52 | 000,047,104 | —- | M] (Primax Electronics Ltd.) – C:\WINDOWS\system32\ico.exe
PRC - [2005/07/22 19:33:48 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
PRC - [2003/06/25 11:24:48 | 000,049,152 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd.exe


========== Modules (SafeList) ==========

MOD - [2011/02/14 06:38:25 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
MOD - [2010/09/20 12:26:01 | 000,415,088 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll
MOD - [2010/08/23 09:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 01:02:02 | 000,653,120 | R— | M] (Microsoft Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcr90.dll
MOD - [2009/07/12 01:02:00 | 000,569,664 | R— | M] (Microsoft Corporation) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcp90.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/02/25 17:21:50 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe – (N360)
SRV - [2009/04/28 08:58:26 | 000,094,208 | —- | M] () [Auto | Running] – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdqserv.exe – (lxdqCATSCustConnectService)
SRV - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/02/27 16:09:44 | 000,594,600 | —- | M] ( ) [Auto | Running] – C:\WINDOWS\System32\lxdqcoms.exe – (lxdq_device)
SRV - [2007/10/11 10:49:46 | 000,076,016 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe – (DellAMBrokerService)
SRV - [2007/03/19 13:44:44 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] – – (catchme)
DRV - [2010/12/16 16:06:00 | 001,360,760 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVEX15.SYS – (NAVEX15)
DRV - [2010/12/16 16:06:00 | 000,086,008 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110213.003\NAVENG.SYS – (NAVENG)
DRV - [2010/11/26 18:51:08 | 000,124,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2010/11/26 01:00:00 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2010/11/26 01:00:00 | 000,102,448 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2010/11/22 23:47:46 | 000,341,944 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110211.002\IDSXpx86.sys – (IDSxpx86)
DRV - [2010/11/22 19:20:07 | 000,691,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101123.003\BHDrvx86.sys – (BHDrvx86)
DRV - [2010/05/10 11:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/05/05 21:01:59 | 000,361,904 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS – (SYMTDI)
DRV - [2010/04/28 22:03:51 | 000,116,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS – (SymIRON)
DRV - [2010/04/21 20:02:20 | 000,173,104 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS – (SymEFA)
DRV - [2010/04/21 19:29:50 | 000,325,680 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS – (SRTSP)
DRV - [2010/04/21 19:29:50 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 17:22:57 | 000,501,888 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys – (ccHP)
DRV - [2010/02/17 11:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/10/14 20:50:05 | 000,328,752 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS – (SymDS)
DRV - [2008/04/13 11:46:22 | 000,015,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mpe.sys – (MPE)
DRV - [2008/04/13 09:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2007/12/04 22:26:40 | 002,782,208 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2007/08/23 19:29:10 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\datunidr.sys – (datunidr)
DRV - [2007/05/10 10:24:34 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2007/03/16 18:10:56 | 000,604,928 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2007/02/25 13:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2007/01/29 19:20:04 | 000,361,728 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emBDA.sys – (USB28xxBGA)
DRV - [2007/01/29 19:19:48 | 000,039,680 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emOEM.sys – (USB28xxOEM)
DRV - [2006/11/15 01:16:24 | 000,032,256 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2006/10/05 18:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys – (PTproct)
DRV - [2006/09/13 19:41:46 | 000,003,456 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\atiide.sys – (atiide)
DRV - [2006/07/01 22:39:40 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2006/03/08 12:35:10 | 000,191,872 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2005/12/01 01:40:56 | 000,936,960 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2005/12/01 01:40:12 | 000,192,512 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSXHWAZL.sys – (HSXHWAZL)
DRV - [2005/12/01 01:40:08 | 000,669,696 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2005/08/12 18:50:46 | 000,016,128 | —- | M] (Dell Inc) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS – (APPDRV)
DRV - [2005/02/09 10:59:00 | 000,014,165 | —- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\Pclepci.sys – (PCLEPCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://my.yahoo.com/
IE - HKCU\..\URLSearchHook: {d1fce654-5fd1-48ad-b13c-5064736120b7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="
FF - prefs.js..browser.startup.homepage: "http://www.myyahoo.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: {d1fce654-5fd1-48ad-b13c-5064736120b7}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/11/27 10:11:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/11/26 18:52:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/22 11:21:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/22 11:21:11 | 000,000,000 | —D | M]

[2010/08/30 11:35:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/02/13 13:11:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\extensions
[2010/11/27 14:50:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/02/13 09:09:41 | 000,000,000 | —D | M] (Soft32 Community Toolbar) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\extensions\{d1fce654-5fd1-48ad-b13c-5064736120b7}
[2010/05/26 14:18:50 | 000,002,333 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\searchplugins\askcom.xml
[2010/11/25 14:40:31 | 000,001,919 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i1lxd3kc.default\searchplugins\bing-zugo.xml
[2011/02/13 13:11:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/09/14 06:14:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/26 07:59:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/13 12:27:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/26 18:52:22 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\COFFPLGN
[2010/11/27 10:11:43 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPLGN
[2008/12/23 21:36:41 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/02/13 21:26:12 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Soft32 Toolbar) - {d1fce654-5fd1-48ad-b13c-5064736120b7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Soft32 Toolbar) - {d1fce654-5fd1-48ad-b13c-5064736120b7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Soft32 Toolbar) - {D1FCE654-5FD1-48AD-B13C-5064736120B7} - C:\Program Files\Soft32\prxtbSoft.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [lxdqamon] C:\Program Files\Lexmark Z2400 Series\lxdqamon.exe ()
O4 - HKLM..\Run: [lxdqmon.exe] C:\Program Files\Lexmark Z2400 Series\lxdqmon.exe ()
O4 - HKLM..\Run: [PMX Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [YMailAdvisor] C:\Program Files\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Philips Device Manager.lnk = C:\Program Files\Philips\GoGear Mix Device Manager\main.exe (KeenHigh Tech.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DeviceEnum Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6886.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1227671349171 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\Hp\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/01 19:45:27 | 000,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/14 06:38:24 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/02/13 21:56:54 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/02/13 21:03:36 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/02/13 19:10:18 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/02/13 19:10:18 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/02/13 19:10:18 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/02/13 19:10:18 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/02/13 19:10:02 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/02/13 19:09:34 | 000,000,000 | —D | C] – C:\Qoobox
[2011/02/13 17:37:29 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/02/13 17:33:29 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/02/13 12:27:39 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/13 12:27:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/13 12:27:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/02/13 09:13:47 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/02/13 09:13:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\HiJackThis
[2011/02/13 09:09:14 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2011/02/13 09:09:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Soft32
[2011/02/13 09:04:15 | 000,000,000 | —D | C] – C:\Program Files\ConduitEngine
[2011/02/13 09:04:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\ConduitEngine
[2011/02/13 09:04:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Conduit
[2011/02/13 09:04:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp
[2011/02/13 09:04:11 | 000,000,000 | —D | C] – C:\Program Files\Soft32
[2011/02/13 09:02:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Soft32 Downloads
[2011/02/13 09:01:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2011/02/12 18:59:15 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2011/02/10 11:08:26 | 001,366,104 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe
[2011/01/22 11:27:41 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/01/22 11:27:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/01/22 11:26:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/01/22 11:09:31 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/01/21 07:44:37 | 000,439,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[2009/10/15 20:32:46 | 000,409,600 | —- | C] ( ) – C:\WINDOWS\System32\lxdqcoin.dll
[2007/11/28 14:19:08 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdqpmui.dll
[2007/11/28 14:16:04 | 001,101,824 | —- | C] ( ) – C:\WINDOWS\System32\lxdqserv.dll
[2007/11/28 14:13:38 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxdqlmpm.dll
[2007/11/28 14:13:30 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdqiesc.dll
[2007/11/28 14:13:22 | 000,376,832 | —- | C] ( ) – C:\WINDOWS\System32\lxdqcomm.dll
[2007/11/28 14:12:26 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdqhbn3.dll
[2007/11/28 14:12:08 | 000,843,776 | —- | C] ( ) – C:\WINDOWS\System32\lxdqusb1.dll
[2007/11/28 14:11:48 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdqcomc.dll
[2007/11/28 14:10:52 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdqprox.dll
[2007/11/28 14:09:32 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\lxdqhcp.dll
[2007/11/28 14:09:18 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdqinpa.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/14 06:38:25 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/02/13 21:54:44 | 002,672,312 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\esetsmartinstaller_enu.exe
[2011/02/13 21:26:12 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/02/13 21:24:36 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/13 21:24:28 | 2011,213,824 | -HS- | M] () – C:\hiberfil.sys
[2011/02/13 21:03:42 | 000,000,316 | RHS- | M] () – C:\boot.ini
[2011/02/13 20:25:41 | 000,136,464 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/13 20:23:02 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/13 19:16:03 | 000,000,316 | —- | M] () – C:\Boot.bak
[2011/02/13 18:58:20 | 004,267,704 | R— | M] () – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2011/02/13 17:26:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/13 17:18:48 | 001,366,104 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe
[2011/02/13 16:34:11 | 000,002,463 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2011/02/13 07:51:25 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/03 09:38:33 | 000,011,776 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/24 12:37:32 | 000,000,298 | —- | M] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2011/01/21 07:44:37 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2011/01/21 07:44:37 | 000,439,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[2011/01/15 09:29:31 | 000,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/13 21:54:18 | 002,672,312 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\esetsmartinstaller_enu.exe
[2011/02/13 19:16:03 | 000,000,316 | —- | C] () – C:\Boot.bak
[2011/02/13 19:15:59 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/02/13 19:10:18 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/02/13 19:10:18 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/02/13 19:10:18 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/02/13 19:10:18 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/02/13 19:10:18 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/02/13 18:58:20 | 004,267,704 | R— | C] () – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2011/02/13 09:13:47 | 000,002,463 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2011/02/12 10:47:52 | 2011,213,824 | -HS- | C] () – C:\hiberfil.sys
[2011/01/26 19:27:05 | 004,154,392 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\102_3008.MOV
[2011/01/26 19:10:10 | 079,390,015 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\102_2708.MOV
[2010/09/19 12:07:05 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\lxdqrwrd.ini
[2010/09/19 12:07:00 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\LXDQinst.dll
[2009/09/01 14:33:34 | 000,010,288 | —- | C] () – C:\WINDOWS\hpdj3500.ini
[2009/07/14 08:02:58 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdqgrd.dll
[2008/06/01 19:45:27 | 000,000,022 | —- | C] () – C:\WINDOWS\VFO.INI
[2008/03/31 18:47:44 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdqvs.dll
[2008/01/23 19:58:27 | 000,011,776 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/15 19:47:04 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/01/14 21:40:31 | 000,000,134 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2008/01/14 21:40:29 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2008/01/14 21:37:53 | 000,000,103 | —- | C] () – C:\WINDOWS\System32\hptrace.ini
[2008/01/14 21:34:26 | 000,013,099 | —- | C] () – C:\WINDOWS\hpdj5800.ini
[2008/01/06 20:45:11 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2008/01/06 09:36:30 | 000,131,014 | —- | C] () – C:\WINDOWS\System32\DellPM.ini
[2008/01/02 16:53:50 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/01/02 16:53:49 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/01/02 07:28:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2005/08/09 15:13:31 | 000,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/09 15:13:31 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/08/09 15:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.









Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.









Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI