This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Search Bar Hijacked, Now I Can't display Gmail Webpage

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi:

My son downloaded something that was trying to make him purchase anti-virus software. I forget the 'vendor' name. Fortunately, he came down and told me there was a problem. It wouldn't let him close that window.

I immediately ran Malwarebytes on his account and came back with around 800 infected files. I repaired them and then logged onto my account, ran Malwarebytes again the same thing.

I am running IE8.

Then, my Google search add-on was redirecting to Zala or Zaba search. So, I reinstalled the add-on and this solved that problem but now when I try to go to the gmail logon site I get the standard windows message: Internet explorer cannot display the webpage.

His browser would not even work so I deleted his whole account and backed up his documents

My browser works, although I do get the occasional suspicious redirect, but the biggest proglem is I am completely unable to access the gmail sign-in page.

The crazy thing about it is I can access gmail on the browser through IPShade. This is how I have been logging in.

I have run Malwarebytes, ad aware and SpyBot, and currently have a SystemCare subscription as well as a Corporate Norton Anti-Virus. They are not detecting anything.

So, a friend of mine got on and downloaded Chrome. Same problem. It wouldn't load gmail. He then downloaded firefox, same problem.

He then suggested HiJackThis and posting to a forum. When we ran HiJackThis, it said it could not access the hosts file but produced the following logfile.

Thanks in advance for any help! I am stumped…..

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:03:18 PM, on 2/15/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NortonAV\defwatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NortonAV\rtvscan.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\NortonAV\vptray.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Program Files\IObit\IObit Security 360\IS360tray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\IObit\IObit Security 360\is360.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Aaron\Desktop\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: 74.50.127.5 www.google.com
O1 - Hosts: 74.50.127.5 google.com
O1 - Hosts: 74.50.127.5 google.com.au
O1 - Hosts: 74.50.127.5 www.google.com.au
O1 - Hosts: 74.50.127.5 google.be
O1 - Hosts: 74.50.127.5 www.google.be
O1 - Hosts: 74.50.127.5 google.com.br
O1 - Hosts: 74.50.127.5 www.google.com.br
O1 - Hosts: 74.50.127.5 google.ca
O1 - Hosts: 74.50.127.5 www.google.ca
O1 - Hosts: 74.50.127.5 google.ch
O1 - Hosts: 74.50.127.5 www.google.ch
O1 - Hosts: 74.50.127.5 google.de
O1 - Hosts: 74.50.127.5 www.google.de
O1 - Hosts: 74.50.127.5 google.dk
O1 - Hosts: 74.50.127.5 www.google.dk
O1 - Hosts: 74.50.127.5 google.fr
O1 - Hosts: 74.50.127.5 www.google.fr
O1 - Hosts: 74.50.127.5 google.ie
O1 - Hosts: 74.50.127.5 www.google.ie
O1 - Hosts: 74.50.127.5 google.it
O1 - Hosts: 74.50.127.5 www.google.it
O1 - Hosts: 74.50.127.5 google.co.jp
O1 - Hosts: 74.50.127.5 www.google.co.jp
O1 - Hosts: 74.50.127.5 google.nl
O1 - Hosts: 74.50.127.5 www.google.nl
O1 - Hosts: 74.50.127.5 google.no
O1 - Hosts: 74.50.127.5 www.google.no
O1 - Hosts: 74.50.127.5 google.co.nz
O1 - Hosts: 74.50.127.5 www.google.co.nz
O1 - Hosts: 74.50.127.5 google.pl
O1 - Hosts: 74.50.127.5 www.google.pl
O1 - Hosts: 74.50.127.5 google.se
O1 - Hosts: 74.50.127.5 www.google.se
O1 - Hosts: 74.50.127.5 google.co.uk
O1 - Hosts: 74.50.127.5 www.google.co.uk
O1 - Hosts: 74.50.127.5 google.co.za
O1 - Hosts: 74.50.127.5 www.google.co.za
O1 - Hosts: 74.50.127.5 www.google-analytics.com
O1 - Hosts: 74.50.127.5 www.bing.com
O1 - Hosts: 74.50.127.5 search.yahoo.com
O1 - Hosts: 74.50.127.5 www.search.yahoo.com
O1 - Hosts: 74.50.127.5 uk.search.yahoo.com
O1 - Hosts: 74.50.127.5 ca.search.yahoo.com
O1 - Hosts: 74.50.127.5 fr.search.yahoo.com
O1 - Hosts: 74.50.127.5 au.search.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [vptray] C:\Program Files\NortonAV\vptray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
O4 - HKLM\..\Run: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [EPSON Stylus NX400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEGA.EXE /FU "C:\WINDOWS\TEMP\E_S98F.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [SmartRAM] "C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Aaron\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.22.17/ttinst.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-29-0.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NortonAV\defwatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NortonAV\rtvscan.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

–
End of file - 11599 bytes
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
Great. I really appreciate the help. As an aside, the friend who was helping me runs an internet business and he logged on remotely and looked at several things including settings that may have been hijacked in both my browser and internet connection and was unable to find anything. Some sites I visit by virtue of just searching on the google toolbar and clicking the link in google are redirected to surveys, etc. that weren't there before this happened, and when I nagivate back on the browser it takes me to the site. I am also unsure of the name of the 'search agent' it tried to redirect me to but it started with a 'z,' and was not zaba search as that is a program I use for locating people (I am a headhunter) so that is not the one. Looking forward to your next reply…..
Hi feelingmn,

Please open HijackThis.
  • Click Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if present):

    O1 - Hosts: 74.50.127.5 www.google.com
    O1 - Hosts: 74.50.127.5 google.com
    O1 - Hosts: 74.50.127.5 google.com.au
    O1 - Hosts: 74.50.127.5 www.google.com.au
    O1 - Hosts: 74.50.127.5 google.be
    O1 - Hosts: 74.50.127.5 www.google.be
    O1 - Hosts: 74.50.127.5 google.com.br
    O1 - Hosts: 74.50.127.5 www.google.com.br
    O1 - Hosts: 74.50.127.5 google.ca
    O1 - Hosts: 74.50.127.5 www.google.ca
    O1 - Hosts: 74.50.127.5 google.ch
    O1 - Hosts: 74.50.127.5 www.google.ch
    O1 - Hosts: 74.50.127.5 google.de
    O1 - Hosts: 74.50.127.5 www.google.de
    O1 - Hosts: 74.50.127.5 google.dk
    O1 - Hosts: 74.50.127.5 www.google.dk
    O1 - Hosts: 74.50.127.5 google.fr
    O1 - Hosts: 74.50.127.5 www.google.fr
    O1 - Hosts: 74.50.127.5 google.ie
    O1 - Hosts: 74.50.127.5 www.google.ie
    O1 - Hosts: 74.50.127.5 google.it
    O1 - Hosts: 74.50.127.5 www.google.it
    O1 - Hosts: 74.50.127.5 google.co.jp
    O1 - Hosts: 74.50.127.5 www.google.co.jp
    O1 - Hosts: 74.50.127.5 google.nl
    O1 - Hosts: 74.50.127.5 www.google.nl
    O1 - Hosts: 74.50.127.5 google.no
    O1 - Hosts: 74.50.127.5 www.google.no
    O1 - Hosts: 74.50.127.5 google.co.nz
    O1 - Hosts: 74.50.127.5 www.google.co.nz
    O1 - Hosts: 74.50.127.5 google.pl
    O1 - Hosts: 74.50.127.5 www.google.pl
    O1 - Hosts: 74.50.127.5 google.se
    O1 - Hosts: 74.50.127.5 www.google.se
    O1 - Hosts: 74.50.127.5 google.co.uk
    O1 - Hosts: 74.50.127.5 www.google.co.uk
    O1 - Hosts: 74.50.127.5 google.co.za
    O1 - Hosts: 74.50.127.5 www.google.co.za
    O1 - Hosts: 74.50.127.5 www.google-analytics.com
    O1 - Hosts: 74.50.127.5 www.bing.com
    O1 - Hosts: 74.50.127.5 search.yahoo.com
    O1 - Hosts: 74.50.127.5 www.search.yahoo.com
    O1 - Hosts: 74.50.127.5 uk.search.yahoo.com
    O1 - Hosts: 74.50.127.5 ca.search.yahoo.com
    O1 - Hosts: 74.50.127.5 fr.search.yahoo.com
    O1 - Hosts: 74.50.127.5 au.search.yahoo.com
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thanks, NT! FYI, the first time I diabled the Norton Corporate AV I got a blue problem detected screen that referenced NAVAP.sys and I had to reboot. The first time I ran GMER, I got the same screen and a STOP:0X0000007F message followed by a bunch of similar numbers and had to reboot again. Here is the first part of DDS, and I have attached the rest. DDS (Ver_10-12-12.01) - NTFSx86 Run by [removed] at 15:45:11.04 on Thu 02/17/2011 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.362 [GMT -6:00] AV: Smart Internet Protection 2011 *Enabled/Updated* {41F91A63-C116-4025-B743-9D487926244C} AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} FW: Smart Internet Protection 2011 *Enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\spoolsv.exe C:\Program Files\NortonAV\defwatch.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\IObit\IObit Security 360\IS360srv.exe C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\NortonAV\rtvscan.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\NortonAV\vptray.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe C:\Program Files\IObit\IObit Security 360\IS360tray.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\System32\alg.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\DellSupport\DSAgnt.exe C:\WINDOWS\system32\MsgSys.EXE C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Aaron\Desktop\wtt1.pif C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.foxnews.com/ uInternet Settings,ProxyOverride = BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter uRun: [EPSON Stylus NX400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiega.exe /fu "c:\windows\temp\E_S98F.tmp" /EF "HKCU" uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup uRun: [SmartRAM] "c:\program files\iobit\advanced systemcare 3\Sup_SmartRAM.exe" /m mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [vptray] c:\program files\nortonav\vptray.exe mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe mRun: [IObit Security 360] "c:\program files\iobit\iobit security 360\IS360tray.exe" /autostart mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - hxxp://a.download.toontown.com/sv1.0.22.17/ttinst.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - hxxp://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab Notify: igfxcui - igfxdev.dll Notify: LMIinit - LMIinit.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll IFEO: image file execution options - svchost.exe IFEO: OLT.exe - svchost.exe ============= SERVICES / DRIVERS =============== R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264] R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2011-2-14 312152] R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2010-12-8 374152] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-9-17 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-2-15 47640] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 NAVAPEL;NAVAPEL;c:\program files\nortonav\Navapel.sys [2001-9-24 9232] R2 Norton AntiVirus Server;Norton AntiVirus Client;c:\program files\nortonav\rtvscan.exe [2001-9-24 454656] S3 utmznjyy;AVZ Kernel Driver;\??\c:\windows\system32\drivers\utmznjyy.sys –> c:\windows\system32\drivers\utmznjyy.sys [?] S4 LMIRfsClientNP;LMIRfsClientNP; [x] =============== Created Last 30 ================ 2011-02-16 18:17:01 5890896 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{67569c14-137a-422a-b85e-9eb05a92e282}\mpengine.dll 2011-02-15 18:06:46 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-02-15 18:05:12 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\Sunbelt Software 2011-02-15 17:20:06 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\Mozilla 2011-02-15 17:11:35 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\Temp 2011-02-15 17:03:49 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\LogMeIn 2011-02-15 17:03:44 53632 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll 2011-02-15 17:03:44 29568 —-a-w- c:\windows\system32\LMIport.dll 2011-02-15 17:03:43 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2011-02-15 17:03:43 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys 2011-02-15 17:03:38 87424 —-a-w- c:\windows\system32\LMIinit.dll.000.bak 2011-02-15 17:03:38 87424 —-a-w- c:\windows\system32\LMIinit.dll 2011-02-15 17:03:34 ——– d—–w- c:\docume~1\alluse~1\applic~1\LogMeIn 2011-02-15 17:03:23 ——– d—–w- c:\program files\LogMeIn 2011-02-15 17:02:09 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\Deployment 2011-02-14 20:15:49 5890896 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2011-02-14 20:13:42 ——– d—–w- c:\program files\Microsoft Security Client 2011-02-14 00:32:23 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-02-14 00:32:23 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2011-02-13 00:42:56 ——– d-sh–w- c:\docume~1\alluse~1\applic~1\SIFXAXZBP 2011-02-13 00:42:34 ——– d-sh–w- c:\docume~1\alluse~1\applic~1\c5fc91 2011-01-21 14:44:37 439296 ——w- c:\windows\system32\dllcache\shimgvw.dll ==================== Find3M ==================== 2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll 2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll 2010-12-31 13:10:33 1854976 —-a-w- c:\windows\system32\win32k.sys 2010-12-22 12:34:28 301568 —-a-w- c:\windows\system32\kerberos.dll 2010-12-20 23:59:20 916480 —-a-w- c:\windows\system32\wininet.dll 2010-12-20 23:59:19 43520 —-a-w- c:\windows\system32\licmgr10.dll 2010-12-20 23:59:19 1469440 ——w- c:\windows\system32\inetcpl.cpl 2010-12-20 17:26:00 730112 —-a-w- c:\windows\system32\lsasrv.dll 2010-12-20 12:55:26 385024 —-a-w- c:\windows\system32\html.iec 2010-12-09 15:15:09 718336 —-a-w- c:\windows\system32\ntdll.dll 2010-12-09 14:30:22 33280 —-a-w- c:\windows\system32\csrsrv.dll 2010-12-09 13:42:26 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-12-09 13:07:07 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe ============= FINISH: 15:46:30.03 ===============
Hi feelingmn,

Thanks for posting the logs. Let's try to get to the bottom of your issues.

I need you to run Malwarebytes again.
  • Open Malwarebytes Anti-Malware
  • Click the Update tab, then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Then click the Scanner tab, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also please describe how your computer behaves at the moment.

===================================================

After running Malwarebytes, run DDS one more time and post the logs.

Thanks
Malwarebytes came back clear. I am also able to access gmail now, as my son pointed out to me (I was going to leave it be but he hopped on not knowing what was going on and told me). The computer seems to be running well. Logs posted below: DDS (Ver_10-12-12.01) - NTFSx86 Run by [removed] at 10:41:42.63 on Fri 02/18/2011 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.315 [GMT -6:00] AV: Smart Internet Protection 2011 *Enabled/Updated* {41F91A63-C116-4025-B743-9D487926244C} AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} FW: Smart Internet Protection 2011 *Enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\NortonAV\defwatch.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\IObit\IObit Security 360\IS360srv.exe C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\NortonAV\vptray.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe C:\Program Files\IObit\IObit Security 360\IS360tray.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\DellSupport\DSAgnt.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe C:\Program Files\NortonAV\rtvscan.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\MsgSys.EXE C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\IObit\IObit Security 360\is360.exe C:\PROGRA~1\Rhapsody\rhaphlpr.exe C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Documents and Settings\Aaron\Desktop\wtt1.pif C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.foxnews.com/ uInternet Settings,ProxyOverride = BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter uRun: [EPSON Stylus NX400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiega.exe /fu "c:\windows\temp\E_S98F.tmp" /EF "HKCU" uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup uRun: [SmartRAM] "c:\program files\iobit\advanced systemcare 3\Sup_SmartRAM.exe" /m mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [vptray] c:\program files\nortonav\vptray.exe mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe mRun: [IObit Security 360] "c:\program files\iobit\iobit security 360\IS360tray.exe" /autostart mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - hxxp://a.download.toontown.com/sv1.0.22.17/ttinst.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - hxxp://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab Notify: igfxcui - igfxdev.dll Notify: LMIinit - LMIinit.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll IFEO: image file execution options - svchost.exe IFEO: OLT.exe - svchost.exe ============= SERVICES / DRIVERS =============== R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-9-17 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-2-15 47640] R2 NAVAPEL;NAVAPEL;c:\program files\nortonav\Navapel.sys [2001-9-24 9232] S3 utmznjyy;AVZ Kernel Driver;\??\c:\windows\system32\drivers\utmznjyy.sys –> c:\windows\system32\drivers\utmznjyy.sys [?] S4 LMIRfsClientNP;LMIRfsClientNP; [x] =============== Created Last 30 ================ 2011-02-17 22:05:37 5890896 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{346cd043-e365-4aa1-9c3d-935731ffaa02}\mpengine.dll 2011-02-15 18:06:46 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-02-15 18:05:12 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\Sunbelt Software 2011-02-15 17:20:06 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\Mozilla 2011-02-15 17:11:35 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\Temp 2011-02-15 17:03:49 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\LogMeIn 2011-02-15 17:03:44 53632 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll 2011-02-15 17:03:44 29568 —-a-w- c:\windows\system32\LMIport.dll 2011-02-15 17:03:43 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2011-02-15 17:03:43 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys 2011-02-15 17:03:38 87424 —-a-w- c:\windows\system32\LMIinit.dll.000.bak 2011-02-15 17:03:38 87424 —-a-w- c:\windows\system32\LMIinit.dll 2011-02-15 17:03:34 ——– d—–w- c:\docume~1\alluse~1\applic~1\LogMeIn 2011-02-15 17:03:23 ——– d—–w- c:\program files\LogMeIn 2011-02-15 17:02:09 ——– d—–w- c:\docume~1\aaron\locals~1\applic~1\Deployment 2011-02-14 20:15:49 5890896 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2011-02-14 20:13:42 ——– d—–w- c:\program files\Microsoft Security Client 2011-02-14 00:32:23 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-02-14 00:32:23 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2011-02-13 00:42:56 ——– d-sh–w- c:\docume~1\alluse~1\applic~1\SIFXAXZBP 2011-02-13 00:42:34 ——– d-sh–w- c:\docume~1\alluse~1\applic~1\c5fc91 2011-01-21 14:44:37 439296 ——w- c:\windows\system32\dllcache\shimgvw.dll ==================== Find3M ==================== 2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll 2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll 2010-12-31 13:10:33 1854976 —-a-w- c:\windows\system32\win32k.sys 2010-12-22 12:34:28 301568 —-a-w- c:\windows\system32\kerberos.dll 2010-12-20 23:59:20 916480 —-a-w- c:\windows\system32\wininet.dll 2010-12-20 23:59:19 43520 —-a-w- c:\windows\system32\licmgr10.dll 2010-12-20 23:59:19 1469440 ——w- c:\windows\system32\inetcpl.cpl 2010-12-20 17:26:00 730112 —-a-w- c:\windows\system32\lsasrv.dll 2010-12-20 12:55:26 385024 —-a-w- c:\windows\system32\html.iec 2010-12-09 15:15:09 718336 —-a-w- c:\windows\system32\ntdll.dll 2010-12-09 14:30:22 33280 —-a-w- c:\windows\system32\csrsrv.dll 2010-12-09 13:42:26 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-12-09 13:07:07 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe ============= FINISH: 10:43:33.13 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-12-12.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 6/27/2006 10:00:04 AM System Uptime: 2/17/2011 3:54:31 PM (19 hours ago) Motherboard: Dell Inc. | | 0JC474 Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/800mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 107 GiB total, 81.279 GiB free. D: is FIXED (NTFS) - 37 GiB total, 37.172 GiB free. E: is CDROM () F: is Removable G: is Removable H: is Removable I: is Removable J: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1812: 11/21/2010 7:42:52 AM - System Checkpoint RP1813: 11/22/2010 8:42:50 AM - System Checkpoint RP1814: 11/23/2010 1:31:28 PM - System Checkpoint RP1815: 11/24/2010 2:07:31 PM - System Checkpoint RP1816: 11/25/2010 3:07:26 PM - System Checkpoint RP1817: 11/26/2010 4:07:25 PM - System Checkpoint RP1818: 11/27/2010 4:25:15 PM - System Checkpoint RP1819: 11/28/2010 5:09:37 PM - System Checkpoint RP1820: 11/29/2010 6:29:52 PM - System Checkpoint RP1821: 11/30/2010 7:01:50 PM - System Checkpoint RP1822: 12/1/2010 7:23:55 PM - System Checkpoint RP1823: 12/2/2010 7:59:20 PM - System Checkpoint RP1824: 12/3/2010 8:59:20 PM - System Checkpoint RP1825: 12/4/2010 9:25:10 PM - System Checkpoint RP1826: 12/5/2010 10:00:21 PM - System Checkpoint RP1827: 12/6/2010 10:18:58 PM - System Checkpoint RP1828: 12/7/2010 11:18:56 PM - System Checkpoint RP1829: 12/8/2010 11:19:58 PM - System Checkpoint RP1830: 12/10/2010 12:08:43 AM - System Checkpoint RP1831: 12/11/2010 1:08:41 AM - System Checkpoint RP1832: 12/12/2010 2:08:40 AM - System Checkpoint RP1833: 12/13/2010 3:08:37 AM - System Checkpoint RP1834: 12/14/2010 4:08:36 AM - System Checkpoint RP1835: 12/15/2010 5:08:33 AM - System Checkpoint RP1836: 12/16/2010 3:00:26 AM - Software Distribution Service 3.0 RP1837: 12/17/2010 3:37:04 AM - System Checkpoint RP1838: 12/18/2010 3:50:38 AM - System Checkpoint RP1839: 12/19/2010 4:26:36 AM - System Checkpoint RP1840: 12/20/2010 5:26:35 AM - System Checkpoint RP1841: 12/21/2010 6:26:29 AM - System Checkpoint RP1842: 12/22/2010 7:46:33 AM - System Checkpoint RP1843: 12/23/2010 8:21:17 AM - System Checkpoint RP1844: 12/24/2010 8:36:30 AM - System Checkpoint RP1845: 12/25/2010 8:37:33 AM - System Checkpoint RP1846: 12/26/2010 9:37:33 AM - System Checkpoint RP1847: 12/29/2010 11:48:26 PM - System Checkpoint RP1848: 12/31/2010 12:39:59 AM - System Checkpoint RP1849: 1/1/2011 5:41:14 PM - System Checkpoint RP1850: 1/2/2011 6:04:00 PM - System Checkpoint RP1851: 1/3/2011 6:09:24 PM - System Checkpoint RP1852: 1/4/2011 6:42:09 PM - System Checkpoint RP1853: 1/5/2011 7:23:33 PM - System Checkpoint RP1854: 1/6/2011 3:00:15 AM - Software Distribution Service 3.0 RP1855: 1/7/2011 3:32:41 AM - System Checkpoint RP1856: 1/8/2011 4:32:38 AM - System Checkpoint RP1857: 1/9/2011 5:32:35 AM - System Checkpoint RP1858: 1/10/2011 6:32:33 AM - System Checkpoint RP1859: 1/11/2011 7:32:32 AM - System Checkpoint RP1860: 1/12/2011 8:32:31 AM - System Checkpoint RP1861: 1/13/2011 3:00:16 AM - Software Distribution Service 3.0 RP1862: 1/14/2011 3:23:10 AM - System Checkpoint RP1863: 1/15/2011 4:23:10 AM - System Checkpoint RP1864: 1/16/2011 5:23:05 AM - System Checkpoint RP1865: 1/17/2011 6:23:04 AM - System Checkpoint RP1866: 1/18/2011 7:23:03 AM - System Checkpoint RP1867: 1/19/2011 7:38:49 AM - System Checkpoint RP1868: 1/20/2011 8:38:45 AM - System Checkpoint RP1869: 1/21/2011 10:58:51 AM - System Checkpoint RP1870: 1/22/2011 11:14:36 AM - System Checkpoint RP1871: 1/23/2011 11:58:01 AM - System Checkpoint RP1872: 1/24/2011 1:07:48 PM - System Checkpoint RP1873: 1/25/2011 2:24:31 PM - System Checkpoint RP1874: 1/26/2011 2:44:53 PM - System Checkpoint RP1875: 1/27/2011 3:48:33 PM - System Checkpoint RP1876: 1/28/2011 3:50:14 PM - System Checkpoint RP1877: 1/29/2011 3:51:18 PM - System Checkpoint RP1878: 1/30/2011 5:02:02 PM - System Checkpoint RP1879: 1/31/2011 7:42:42 PM - System Checkpoint RP1880: 2/1/2011 8:56:02 PM - System Checkpoint RP1881: 2/2/2011 10:13:45 PM - System Checkpoint RP1882: 2/3/2011 10:50:05 PM - System Checkpoint RP1883: 2/5/2011 1:00:06 PM - System Checkpoint RP1884: 2/6/2011 2:12:44 PM - System Checkpoint RP1885: 2/7/2011 2:58:58 PM - System Checkpoint RP1886: 2/8/2011 3:21:48 PM - System Checkpoint RP1887: 2/9/2011 3:55:17 PM - System Checkpoint RP1888: 2/10/2011 3:00:23 AM - Software Distribution Service 3.0 RP1889: 2/11/2011 3:24:56 AM - System Checkpoint RP1890: 2/12/2011 3:39:40 AM - System Checkpoint RP1891: 2/13/2011 4:21:36 AM - System Checkpoint RP1892: 2/14/2011 6:40:35 AM - System Checkpoint RP1893: 2/14/2011 2:15:07 PM - Software Distribution Service 3.0 RP1894: 2/15/2011 11:03:19 AM - Installed LogMeIn RP1895: 2/16/2011 3:00:19 AM - Software Distribution Service 3.0 RP1896: 2/16/2011 12:16:59 PM - Software Distribution Service 3.0 RP1897: 2/17/2011 1:23:11 PM - System Checkpoint RP1898: 2/17/2011 3:53:24 PM - Software Distribution Service 3.0 RP1899: 2/17/2011 4:05:19 PM - Software Distribution Service 3.0 ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Reader 8.2.6 Advanced SystemCare 3 AOLIcon Apple Software Update Compatibility Pack for the 2007 Office system Conexant D850 56K V.9x DFVc Modem Content Transfer Critical Update for Windows Media Player 11 (KB959772) Dell Driver Reset Tool Dell Support Center (Support Software) Dell System Restore DellSupport Digital Content Portal Digital Line Detect Documentation & Support Launcher EarthLink setup files EducateU ELIcon EPSON NX400 User's Guide EPSON Scan EPSON Stylus NX400 Series Printer Uninstall High Definition Audio Driver Package - KB835221 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers IObit Security 360 Java 2 Runtime Environment, SE v1.4.2_03 LiveUpdate 2.6 (Symantec Corporation) LogMeIn Malwarebytes' Anti-Malware MCU Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft .NET Framework 1.0 Hotfix (KB979904) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2416447) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft ActiveSync Microsoft Antimalware Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft IntelliPoint 6.2 Microsoft IntelliType Pro 6.2 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Office Basic Edition 2003 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Modem Helper MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6.0 Parser (KB933579) Musicmatch for Windows Media Player NetWaiting Norton AntiVirus Corporate Edition NWZ-S540 WALKMAN Guide PENTAX USB DISK Device QuickTime Rhapsody Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Smart Defrag Sonic Activation Module Sonic Encoders Spybot - Search & Destroy Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB971930) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebCyberCoach 3.2 Dell WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] Windows Media Player 11 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WinRAR archiver ==== Event Viewer Messages From Past Week ======== 2/14/2011 12:54:38 PM, error: Dhcp [1002] - The IP address lease 192.168.0.10 for the Network Card with network address 00167631977E has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message). 2/14/2011 11:08:45 AM, error: Service Control Manager [7000] - The MCSTRM service failed to start due to the following error: The system cannot find the file specified. 2/13/2011 7:01:10 PM, error: PlugPlayManager [11] - The device Root\LEGACY_NAVEX15\0000 disappeared from the system without first being prepared for removal. 2/13/2011 7:01:10 PM, error: NAVAP [20] - Unable to initialize the virus scanning engine database files. 2/12/2011 7:18:05 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IntelIde 2/12/2011 7:18:02 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 2/12/2011 6:56:14 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Norton AntiVirus Client service to connect. 2/12/2011 6:56:14 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the DefWatch service to connect. ==== End Of File ===========================
Hi feelingmn,

Thanks for the logs. Let's run ComboFix so we can dig a little deeper.

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it has even started to download

Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks
Quick question before I run ComboFix. When I launched the program it told me that Smart Internet Protection is running. I know this is malware but cannot find it anywhere and it is not being detected by malwarebytes or spybot so I am unable to remove it or stop it from running. I am fairly certain this is the program that my son downloaded that caused all these freakin' problems :smack: Is it OK to run CF under these circumstances or do we need to do something else first? I run SystemCare and I have noticed something is really hogging RAM right now, and if I reboot it returns to the usual level, but then slowly decreases again until I am running on less than 200MB. Let me know how you would like me to proceed. Thanks.
Hi NT. I ran CF and it picked some stuff up, I told it to repair them, then it rebooted and the screen came up and said, "please wait." I went outside to clear snow (I'm in MN and we are getting pounded) and when I came in about an hour later the screen was still up and it had not advanced so I closed it and am wondering what to do at this point? Let me know….. Thanks.
Hi feelingmn,

Try restarting your computer. After it restarts, browse to C:\combofix.txt and see if the log exists. If it does, please post it in your next reply.
This is all I was unable to find. Search for .txt yielded nothing. Looks like Smart Internet Protection is alive and well….. ComboFix 11-02-20.01 - Aaron 02/20/2011 18:15:07.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.648 [GMT -6:00] Running from: C:\Documents and Settings\[removed]\Desktop\jgh.exe AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} AV: Smart Internet Protection 2011 *Enabled/Updated* {41F91A63-C116-4025-B743-9D487926244C} FW: Smart Internet Protection 2011 *Enabled* {61C59ED0-C5FE-46E9-8DF7-73F08FCCB9D3} Let me know what you want me to do. Thanks.
Hi feelingmn, What RAM issue are you talking about? I need you to delete ComboFix, redownload it, and run it once more. Post the log in your next reply if it is successful.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI