This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browsers and malware

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have IE and Opera as browsers. About 2 weeks ago, Opera especially did not work well. I have Avast, Superantispyware,Malwarebytes, Comodo Firewall and Win Patrol on my computer. I called MS and they ran a scan and said my computer is okay. I also ran about 5 online scanners. I am not sure why Opera freezes every time I open it now. It seems like it takes much less memory than IE. I am not an expert or sure. Even if I open 30 tabs of Opera, it will take maybe 600MB of RAM. However, right now I have 9 tabs (one Window) of IE open and it is using 381, 157,20, 138, 228 MB of RAM according to Task Manager. That is over 900 MB of RAM. I have 1.5 GB of RAM capacity. I doubt if the other things I have running total even 500 MB. I like Opera much better. If I open more than one window of IE, my computer seems to slow down quite a bit and IE seems to like to open in windows and not tabs like Opera. Anyway, if someone can tell me how to resurrect Opera, I would appreciate it. My wife used it and then Comodo kept asking me to allow something to open. I forgot what. It seems like that is when the trouble started. That is why I thought it was malware.I think I am running IE 8 and I updated version of opera in Dec. IE is not working that well either but it is usable. Thanks GB
Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt
Thank you very much for helping me. Here is the file. GB DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 20:45:02.23 on Mon 02/28/2011 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.723 [GMT -9:00] AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} ============== Running Processes =============== C:\WIXP\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\WIXP\system32\svchost.exe -k netsvcs C:\Program Files\Sandboxie\SbieSvc.exe svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WIXP\system32\spoolsv.exe c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe C:\WIXP\System32\svchost.exe -k imgsvc C:\WIXP\Explorer.EXE C:\WIXP\system32\rundll32.exe svchost.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Sandboxie\SbieCtrl.exe C:\WIXP\system32\ctfmon.exe C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe C:\Program Files\McAfee Security Scan\2.0.189\SSScheduler.exe C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\OpenOffice.org 3\program\scalc.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe C:\WIXP\system32\taskmgr.exe C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://yahoo.com/ uSearch Bar = hxxp://www.google.com/ie uSearch Page = hxxp://www.google.com uSearchURL,(Default) = hxxp://www.google.com/search?q=%s uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: GigagetIEHelper Class: {111caa23-6f4f-42ac-8555-b48c1d87bbab} - c:\wixp\system32\gigagetbho_v10.dll BHO: RoboForm BHO: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERANTISPYWARE.EXE uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe" uRun: [ctfmon.exe] c:\wixp\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" mRun: [IgfxTray] c:\wixp\system32\igfxtray.exe mRun: [HotKeysCmds] c:\wixp\system32\hkcmd.exe mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRunOnce: [aswAhAScr.dll] "c:\program files\alwil software\avast5\aswregsvr.exe" "c:\program files\alwil software\avast5\AhAScr.dll" StartupFolder: c:\docume~1\owner~1.kha\startm~1\programs\startup\cnette~1.lnk - c:\documents and settings\owner.khalsa-family\application data\cbs interactive\cnet techtracker\TechTracker.exe StartupFolder: c:\docume~1\alluse~1.wix\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.189\SSScheduler.exe IE: &Download All by Gigaget - c:\program files\giganology\gigaget\getallurl.htm IE: &Download by Gigaget - c:\program files\giganology\gigaget\geturl.htm IE: Add to Google Photos Screensa&ver - c:\wixp\system32\GPhotos.scr/200 IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {21196042-830F-419f-A594-F9D456A6C29A} - {21196042-830F-419f-A594-F9D456A6C29A} c:\program files\timeleft3\tlintergie.html - c:\program files\timeleft3\tlintergie.html\inprocserver32 does not exist! IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll DPF: DirectAnimation Java Classes - file://c:\wixp\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\wixp\java\classes\xmldso.cab DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,6094/mcfscan.cab Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxsrvc.dll AppInit_DLLs: c:\wixp\system32\guard32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\wixp\system32\WPDShServiceObj.dll SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File ============= SERVICES / DRIVERS =============== R0 pavboot;pavboot;c:\wixp\system32\drivers\pavboot.sys [2011-2-17 28552] R1 aswSP;aswSP;c:\wixp\system32\drivers\aswSP.sys [2010-6-2 301528] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\wixp\system32\drivers\cmdGuard.sys [2010-9-10 239368] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\wixp\system32\drivers\cmdhlp.sys [2010-9-10 27576] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R1 SBRE;SBRE;c:\wixp\system32\drivers\SBREDrv.sys [2011-2-19 93872] R2 aswFsBlk;aswFsBlk;c:\wixp\system32\drivers\aswFsBlk.sys [2010-6-2 19544] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-30 40384] R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2010-9-10 1803224] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\mcsacore.exe [2010-1-23 88176] R2 portD;CMS PortIO Service;c:\wixp\system32\drivers\portd2k.sys [2010-1-13 7424] R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2010-10-17 124648] S1 aswSnx;aswSnx;c:\wixp\system32\drivers\aswSnx.sys [2011-2-24 371544] S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-23 135664] S3 BIOSCHK;BIOSCHK;\??\c:\docume~1\owner~1.kha\locals~1\temp\tii69d.tmp\disk1\bioschk.sys –> c:\docume~1\owner~1.kha\locals~1\temp\tii69d.tmp\disk1\BIOSCHK.SYS [?] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.189\McCHSvc.exe [2010-9-2 227232] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872] S4 0258871292614199mcinstcleanup;McAfee Application Installer Cleanup (0258871292614199);c:\wixp\temp\025887~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service –> c:\wixp\temp\025887~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?] =============== Created Last 30 ================ 2011-02-24 08:08 371,544 a——- c:\wixp\system32\drivers\aswSnx.sys 2011-02-22 13:39 1,089,593 -c—— c:\wixp\system32\dllcache\ntprint.cat 2011-02-22 03:08 –d—– c:\wixp\system32\XPSViewer 2011-02-22 03:05 89,088 -c—— c:\wixp\system32\dllcache\filterpipelineprintproc.dll 2011-02-22 03:05 117,760 ——– c:\wixp\system32\prntvpt.dll 2011-02-22 03:05 1,676,288 -c—— c:\wixp\system32\dllcache\xpssvcs.dll 2011-02-22 03:05 597,504 -c—— c:\wixp\system32\dllcache\printfilterpipelinesvc.exe 2011-02-22 03:05 575,488 -c—— c:\wixp\system32\dllcache\xpsshhdr.dll 2011-02-22 03:05 1,676,288 ——– c:\wixp\system32\xpssvcs.dll 2011-02-22 03:05 575,488 ——– c:\wixp\system32\xpsshhdr.dll 2011-02-22 03:05 –d—– C:\92bc20fcc047355f0049ae 2011-02-19 02:39 93,872 a——- c:\wixp\system32\drivers\SBREDrv.sys 2011-02-17 19:08 –d—– c:\wixp\system32\drivers\NSS 2011-02-17 19:08 –d—– c:\program files\Norton Security Scan 2011-02-17 19:08 –d—– c:\program files\NortonInstaller 2011-02-17 16:52 –d—– c:\docume~1\owner~1.kha\applic~1\f-secure 2011-02-17 16:52 –d—– c:\docume~1\alluse~1.wix\applic~1\F-Secure 2011-02-17 16:32 28,552 a——- c:\wixp\system32\drivers\pavboot.sys 2011-02-17 16:31 –d—– c:\program files\Panda Security 2011-02-17 16:29 –d—– c:\docume~1\alluse~1.wix\applic~1\CA 2011-02-15 12:17 –d—– c:\docume~1\owner~1.kha\applic~1\CBS Interactive 2011-02-11 15:15 –d—– c:\wixp\system32\wbem\Repository 2011-02-08 19:52 40,960 -c—— c:\wixp\system32\dllcache\ndproxy.sys 2011-02-08 19:49 45,568 -c—— c:\wixp\system32\dllcache\wab.exe ==================== Find3M ==================== 2011-02-23 06:04 40,648 a——- c:\wixp\avastSS.scr 2011-02-02 21:40 472,808 a——- c:\wixp\system32\deployJava1.dll 2011-01-21 12:59 285,480 a——- c:\wixp\system32\guard32.dll 2011-01-21 12:59 27,576 a——- c:\wixp\system32\drivers\cmdhlp.sys 2011-01-21 12:59 239,368 a——- c:\wixp\system32\drivers\cmdGuard.sys 2011-01-21 12:59 15,592 a——- c:\wixp\system32\drivers\cmderd.sys 2011-01-21 05:44 439,296 a——- c:\wixp\system32\shimgvw.dll 2011-01-07 05:09 290,048 a——- c:\wixp\system32\atmfd.dll 2010-12-31 04:10 1,854,976 a——- c:\wixp\system32\win32k.sys 2010-12-22 03:34 301,568 a——- c:\wixp\system32\kerberos.dll 2010-12-20 14:59 916,480 a——- c:\wixp\system32\wininet.dll 2010-12-20 14:59 43,520 a——- c:\wixp\system32\licmgr10.dll 2010-12-20 08:26 730,112 a——- c:\wixp\system32\lsasrv.dll 2010-12-09 06:15 718,336 a——- c:\wixp\system32\ntdll.dll 2010-12-09 05:30 33,280 a——- c:\wixp\system32\csrsrv.dll 2010-12-09 04:38 2,192,768 a——- c:\wixp\system32\ntoskrnl.exe 2010-12-09 04:07 2,069,376 a——- c:\wixp\system32\ntkrnlpa.exe 2010-12-01 18:35 4,280,320 a——- c:\wixp\system32\GPhotos.scr 2010-09-13 08:21 72,080 a——- c:\documents and settings\owner.khalsa-family\g2mdlhlpx.exe 2010-06-30 15:40 348 a——- c:\program files\rwbpg.txt 2010-11-01 10:10 16,384 a–sh— c:\wixp\system32\config\systemprofile\cookies\index.dat 2010-11-01 10:09 245,760 a–sh— c:\wixp\system32\config\systemprofile\ietldcache\index.dat 2010-11-01 10:09 32,768 a–sh— c:\wixp\system32\config\systemprofile\local settings\history\history.ie5\mshist012010110120101102\index.dat 2010-11-01 10:10 32,768 a–sh— c:\wixp\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat ============= FINISH: 20:46:48.71 ===============
That didn't show anything back.

Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have XP SP3, use the XP SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
I am using XP and not Vista or Win 7. I downloaded Combofix and got a message saying ? Windows cannot access the specified device, path or file. You may not have the appropriate permission to access the item. I think I downloaded Combofix this past summer and had no problem. Thanks GB
Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.




Also please describe how your computer behaves at the moment.
Download RogueKiller to your desktop

  • Quit all running programs
  • For Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
  • When prompted, type 1 and validate
  • The RKreport.txt shall be generated next to the executable.
  • If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply.
This scan found nothing. Comodo kept asking to be let in. I kept okaying it and RK would not work until I turned off the Comodo. I ws wonding if this is the same for ComboFix. Here's the log.

Thanks
GB

RogueKiller V4.1.0 by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRKgmailcom
Feedback:

http://www.sur-la-toile.com/discussion-193…llerD-Remontees

.html

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Owner [Admin rights]
Mode: Scan – Date : 03/05/2011 18:50:56

Bad processes: 1
[APPDT/TMP/DESKTOP] TechTracker.exe – c:\documents and

settings\owner.khalsa-family\application data\cbs interactive\cnet

techtracker\techtracker.exe -> KILLED

Registry Entries: 0

HOSTS File:
127.0.0.1 localhost


Finished
Sorry this took so long. I ran scans on two different nights only to find out the computer automatically restarted so I had to do the scans over again. Here is the latest ComFix scan log. I don;t know why the log says Comodo is enabled since I disabled it just before running the scan.



Thanks for helping,
GB

ComboFix 11-03-03.04 - Owner 03/09/2011 8:02.13.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.1102 [GMT -9:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((( Files Created from 2011-02-09 to 2011-03-09 )))))))))))))))))))))))))))))))
.

2011-03-09 00:25 . 2011-03-09 00:25 ——– d—–w- c:\wixp\LastGood
2011-03-06 00:36 . 2011-03-06 00:36 ——– dc-h–w- c:\documents and settings\All Users.WIXP\Application Data\{EFBAD1D6-DB32-4E45-ACA1-FB05458C6D20}
2011-03-06 00:34 . 2011-03-06 00:34 ——– d—–w- c:\program files\Radium Technologies
2011-03-06 00:34 . 2011-03-06 00:34 ——– d—–w- c:\documents and settings\All Users.WIXP\Application Data\Radium Technologies
2011-03-05 23:51 . 2011-03-05 23:51 ——– d—–w- c:\program files\Kerkia
2011-02-24 17:08 . 2011-02-23 14:56 371544 —-a-w- c:\wixp\system32\drivers\aswSnx.sys
2011-02-24 17:04 . 2011-02-24 17:04 ——– d—–w- c:\program files\Common Files\Java
2011-02-22 12:08 . 2011-02-22 12:08 ——– d—–w- c:\wixp\system32\XPSViewer
2011-02-22 12:06 . 2008-07-06 12:06 89088 —-a-w- c:\wixp\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-02-22 12:05 . 2008-07-06 12:06 89088 -c—-w- c:\wixp\system32\dllcache\filterpipelineprintproc.dll
2011-02-22 12:05 . 2008-07-06 12:06 117760 ——w- c:\wixp\system32\prntvpt.dll
2011-02-22 12:05 . 2008-07-06 12:06 575488 -c—-w- c:\wixp\system32\dllcache\xpsshhdr.dll
2011-02-22 12:05 . 2008-07-06 12:06 575488 ——w- c:\wixp\system32\xpsshhdr.dll
2011-02-22 12:05 . 2008-07-06 12:06 1676288 -c—-w- c:\wixp\system32\dllcache\xpssvcs.dll
2011-02-22 12:05 . 2008-07-06 12:06 1676288 ——w- c:\wixp\system32\xpssvcs.dll
2011-02-22 12:05 . 2008-07-06 10:50 597504 -c—-w- c:\wixp\system32\dllcache\printfilterpipelinesvc.exe
2011-02-22 12:05 . 2008-07-06 10:50 597504 ——w- c:\wixp\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-02-22 12:05 . 2011-02-22 12:06 ——– d—–w- C:\92bc20fcc047355f0049ae
2011-02-19 11:39 . 2009-08-05 23:58 93872 —-a-w- c:\wixp\system32\drivers\SBREDrv.sys
2011-02-18 04:08 . 2011-02-18 04:08 ——– d—–w- c:\wixp\system32\drivers\NSS
2011-02-18 04:08 . 2011-02-18 04:08 ——– d—–w- c:\program files\Norton Security Scan
2011-02-18 04:08 . 2011-02-18 04:08 ——– d—–w- c:\program files\NortonInstaller
2011-02-18 01:52 . 2011-02-18 01:52 ——– d—–w- c:\documents and settings\Owner.KHALSA-FAMILY\Application Data\f-secure
2011-02-18 01:52 . 2011-02-18 01:52 ——– d—–w- c:\documents and settings\All Users.WIXP\Application Data\F-Secure
2011-02-18 01:32 . 2009-06-30 19:37 28552 —-a-w- c:\wixp\system32\drivers\pavboot.sys
2011-02-18 01:31 . 2011-02-18 01:31 ——– d—–w- c:\program files\Panda Security
2011-02-18 01:29 . 2011-02-18 01:29 ——– d—–w- c:\documents and settings\All Users.WIXP\Application Data\CA
2011-02-16 23:19 . 2011-02-17 07:31 ——– d—–w- c:\wixp\BDOSCAN8
2011-02-15 21:17 . 2011-02-15 21:17 ——– d—–w- c:\documents and settings\Owner.KHALSA-FAMILY\Application Data\CBS Interactive
2011-02-12 00:28 . 2011-02-12 00:28 ——– d-sh–w- c:\documents and settings\Administrator.KHALSA-FAMILY\PrivacIE
2011-02-12 00:24 . 2011-02-12 00:24 ——– d-sh–w- c:\documents and settings\Administrator.KHALSA-FAMILY\IETldCache
2011-02-12 00:15 . 2011-02-12 00:15 ——– d—–w- c:\wixp\system32\wbem\Repository
2011-02-09 13:53 . 2011-02-09 13:53 270848 -c—-w- c:\wixp\system32\dllcache\sbe.dll
2011-02-09 13:53 . 2011-02-09 13:53 186880 -c—-w- c:\wixp\system32\dllcache\encdec.dll
2011-02-09 04:52 . 2010-11-02 15:17 40960 -c—-w- c:\wixp\system32\dllcache\ndproxy.sys
2011-02-09 04:49 . 2010-10-11 14:59 45568 -c—-w- c:\wixp\system32\dllcache\wab.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-23 15:04 . 2010-07-30 23:59 40648 —-a-w- c:\wixp\avastSS.scr
2011-02-23 15:04 . 2010-06-03 06:33 190016 —-a-w- c:\wixp\system32\aswBoot.exe
2011-02-23 14:56 . 2010-06-03 06:34 301528 —-a-w- c:\wixp\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2010-06-03 06:34 49240 —-a-w- c:\wixp\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2010-06-03 06:34 102232 —-a-w- c:\wixp\system32\drivers\aswmon2.sys
2011-02-23 14:55 . 2010-06-03 06:34 96344 —-a-w- c:\wixp\system32\drivers\aswmon.sys
2011-02-23 14:55 . 2010-06-03 06:34 25432 —-a-w- c:\wixp\system32\drivers\aswRdr.sys
2011-02-23 14:54 . 2010-06-03 06:34 30680 —-a-w- c:\wixp\system32\drivers\aavmker4.sys
2011-02-23 14:54 . 2010-06-03 06:34 19544 —-a-w- c:\wixp\system32\drivers\aswFsBlk.sys
2011-02-09 13:53 . 2002-09-03 16:57 270848 —-a-w- c:\wixp\system32\sbe.dll
2011-02-09 13:53 . 2002-09-03 16:32 186880 —-a-w- c:\wixp\system32\encdec.dll
2011-02-03 06:40 . 2010-04-26 04:47 472808 —-a-w- c:\wixp\system32\deployJava1.dll
2011-02-03 04:19 . 2010-06-07 23:16 73728 —-a-w- c:\wixp\system32\javacpl.cpl
2011-02-02 07:58 . 2009-12-22 01:28 2067456 —-a-w- c:\wixp\system32\mstscax.dll
2011-01-27 11:57 . 2009-12-22 01:28 677888 —-a-w- c:\wixp\system32\mstsc.exe
2011-01-21 21:59 . 2010-09-11 07:41 285480 —-a-w- c:\wixp\system32\guard32.dll
2011-01-21 21:59 . 2010-09-11 07:40 94784 —-a-w- c:\wixp\system32\drivers\inspect.sys
2011-01-21 21:59 . 2010-09-11 07:40 27576 —-a-w- c:\wixp\system32\drivers\cmdhlp.sys
2011-01-21 21:59 . 2010-09-11 07:40 239368 —-a-w- c:\wixp\system32\drivers\cmdGuard.sys
2011-01-21 21:59 . 2010-09-11 07:40 15592 —-a-w- c:\wixp\system32\drivers\cmderd.sys
2011-01-21 14:44 . 2002-09-03 16:59 439296 —-a-w- c:\wixp\system32\shimgvw.dll
2011-01-07 14:09 . 2002-09-03 16:27 290048 —-a-w- c:\wixp\system32\atmfd.dll
2010-12-31 13:10 . 2002-09-03 17:11 1854976 —-a-w- c:\wixp\system32\win32k.sys
2010-12-22 12:34 . 2002-09-03 16:39 301568 —-a-w- c:\wixp\system32\kerberos.dll
2010-12-21 03:09 . 2010-09-17 09:53 38224 —-a-w- c:\wixp\system32\drivers\mbamswissarmy.sys
2010-12-21 03:08 . 2010-09-17 09:53 20952 —-a-w- c:\wixp\system32\drivers\mbam.sys
2010-12-20 23:59 . 2002-09-03 17:12 916480 —-a-w- c:\wixp\system32\wininet.dll
2010-12-20 23:59 . 2002-09-03 16:39 43520 —-a-w- c:\wixp\system32\licmgr10.dll
2010-12-20 23:59 . 2002-09-03 16:35 1469440 ——w- c:\wixp\system32\inetcpl.cpl
2010-12-20 17:26 . 2002-09-03 16:39 730112 —-a-w- c:\wixp\system32\lsasrv.dll
2010-12-20 12:55 . 2009-12-22 11:33 385024 —-a-w- c:\wixp\system32\html.iec
.
.
((((((((((((((((((((((((((((( SnapShot@2011-03-07_12.03.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-08 12:20 . 2011-03-08 12:20 16384 c:\wixp\Temp\Perflib_Perfdata_184.dat
+ 2010-10-18 21:01 . 2011-03-08 12:03 49152 c:\wixp\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
- 2010-10-18 21:01 . 2011-02-10 03:00 49152 c:\wixp\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
- 2002-09-03 16:59 . 2008-04-14 00:12 135168 c:\wixp\system32\shsvcs.dll
+ 2002-09-03 16:59 . 2009-07-27 23:17 135168 c:\wixp\system32\shsvcs.dll
+ 2009-07-27 23:17 . 2009-07-27 23:17 135168 c:\wixp\system32\dllcache\shsvcs.dll
+ 2011-01-27 11:57 . 2011-01-27 11:57 677888 c:\wixp\system32\dllcache\lhmstsc.exe
+ 2011-02-02 07:58 . 2011-02-02 07:58 2067456 c:\wixp\system32\dllcache\lhmstscx.dll
+ 2010-10-29 19:43 . 2011-03-09 12:17 37943240 c:\wixp\system32\MRT.exe
+ 2011-03-08 12:01 . 2011-03-08 12:01 20308992 c:\wixp\Installer\3816a31.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE" [2011-02-24 2423752]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2010-10-17 404200]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-24 39408]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-02-07 107000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\wixp\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\wixp\system32\hkcmd.exe" [2004-02-10 118784]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-05-31 323976]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-21 2548552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]

c:\documents and settings\Owner.KHALSA-FAMILY\Start Menu\Programs\Startup\
CNET TechTracker.lnk - c:\documents and settings\Owner.KHALSA-FAMILY\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe [2010-12-2 2621952]

c:\documents and settings\All Users.WIXP\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.189\SSScheduler.exe [2010-9-2 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2010-01-26 02:20 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\wixp\system32\guard32.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WIXP^Start Menu^Programs^Startup^BounceBack Launcher.lnk]
backup=c:\wixp\pss\BounceBack Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner.KHALSA-FAMILY^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
backup=c:\wixp\pss\OpenOffice.org 3.2.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner.KHALSA-FAMILY^Start Menu^Programs^Startup^TimeLeft.lnk]
backup=c:\wixp\pss\TimeLeft.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Giganology\\Gigaget\\Gigaget.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 pavboot;pavboot;c:\wixp\system32\drivers\pavboot.sys [2/17/2011 4:32 PM 28552]
R1 aswSnx;aswSnx;c:\wixp\system32\drivers\aswSnx.sys [2/24/2011 8:08 AM 371544]
R1 aswSP;aswSP;c:\wixp\system32\drivers\aswSP.sys [6/2/2010 9:34 PM 301528]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\wixp\system32\drivers\cmdGuard.sys [9/10/2010 10:40 PM 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\wixp\system32\drivers\cmdhlp.sys [9/10/2010 10:40 PM 27576]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 9:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 9:41 AM 67656]
R1 SBRE;SBRE;c:\wixp\system32\drivers\SBREDrv.sys [2/19/2011 2:39 AM 93872]
R2 aswFsBlk;aswFsBlk;c:\wixp\system32\drivers\aswFsBlk.sys [6/2/2010 9:34 PM 19544]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [1/23/2010 11:42 PM 88176]
R2 portD;CMS PortIO Service;c:\wixp\system32\drivers\portd2k.sys [1/13/2010 1:43 PM 7424]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/23/2009 7:05 PM 135664]
S3 BIOSCHK;BIOSCHK;\??\c:\docume~1\OWNER~1.KHA\LOCALS~1\Temp\TII69D.tmp\disk1\BIOSCHK.SYS –> c:\docume~1\OWNER~1.KHA\LOCALS~1\Temp\TII69D.tmp\disk1\BIOSCHK.SYS [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.189\McCHSvc.exe [9/2/2010 11:18 AM 227232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 9:15 AM 12872]
S4 0258871292614199mcinstcleanup;McAfee Application Installer Cleanup (0258871292614199);c:\wixp\TEMP\025887~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service –> c:\wixp\TEMP\025887~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
.
Contents of the 'Scheduled Tasks' folder

2011-03-08 c:\wixp\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 04:05]

2011-03-09 c:\wixp\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 04:05]

2011-03-08 c:\wixp\Tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003Core.job
- c:\documents and settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-24 04:05]

2011-03-09 c:\wixp\Tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003UA.job
- c:\documents and settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-24 04:05]

2011-03-08 c:\wixp\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Engine\3.0.1.8\Nss.exe [2011-02-18 14:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download All by Gigaget - c:\program files\Giganology\Gigaget\getallurl.htm
IE: &Download by Gigaget - c:\program files\Giganology\Gigaget\geturl.htm
IE: Add to Google Photos Screensa&ver - c:\wixp\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: DirectAnimation Java Classes - file://c:\wixp\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\wixp\Java\classes\xmldso.cab
DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab
.
.
**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-09 08:20
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WIXP\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WIXP\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(580)
c:\wixp\system32\guard32.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\wixp\system32\WININET.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll

- - - - - - - > 'lsass.exe'(636)
c:\wixp\system32\guard32.dll

- - - - - - - > 'explorer.exe'(2612)
c:\wixp\system32\WININET.dll
c:\wixp\system32\guard32.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\wixp\system32\ieframe.dll
c:\wixp\system32\webcheck.dll
c:\wixp\system32\WPDShServiceObj.dll
c:\wixp\system32\PortableDeviceTypes.dll
c:\wixp\system32\PortableDeviceApi.dll
.
Completion time: 2011-03-09 08:26:27
ComboFix-quarantined-files.txt 2011-03-09 17:26
ComboFix2.txt 2011-03-08 08:03
ComboFix3.txt 2011-03-07 12:11
.
Pre-Run: 17,768,366,080 bytes free
Post-Run: 17,956,970,496 bytes free
.
- - End Of File - - CAB90A6EE89497C9EA2DEEC42BEC079F
PS. The computer does not seem to be running any faster since I originally inquired here. I still have to wait quite a few seconds between clicking different tabs or starting a new web page - maybe 30 sec. on avereage. Thanks GB
The following will implement some cleanup procedures as well as reset System Restore points:

For XP:
  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.

For Vista / Windows 7
  • Click START Search
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.

For the remaining issues I suggest you start a new topic in our Windows Forum and see if the Tech Team has any suggestions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI