This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unable to defrag after porn infection

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My girl friend's son (22year old) uses his mother's laptop to surf for porn when his mom is out of town. He called me last week asking for help. The laptop was unresponsive in that it would not run any programs. It would boot, but thats about it. I used spybot S&D, Malwarebytes, and MS Essentials to clean most of the damage. Spybot removed 14 threats, Malwarebytes another 5, and Essentials found 2. It is running much better now but I think there still may be something hiding as I can not defrag the HDD. Using Piriform's Defraggler there are still a few System Volume Information files that refuse to be unfragmented. If I use the Vista system defrag, that leaves the HDD more fragmented than before I start. Here are the reports from DDS DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 11:15:59.60 on Tue 03/15/2011 Internet Explorer: 8.0.6001.19019 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1982.1293 [GMT -4:00] AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF} SP: Microsoft Security Essentials *disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDE} SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\SearchIndexer.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\System32\rundll32.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\System32\wpcumi.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Windows\system32\taskmgr.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\michelle\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ mDefault_Page_URL = hxxp://www.yahoo.com uURLSearchHooks: H - No File mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTo1.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Yahooo Search Protection: {25bc7718-0bfa-40ea-b381-4b2d9732d686} - c:\program files\yahoo!\search protection\ysp.dll BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngin0.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office12\GRA8E1~1.DLL BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTo1.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTo1.dll TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngin0.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {B9D63C58-90CC-428B-8D3B-CBB88EB07E7E} - No File mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: c:\windows\system32\wpclsp.dll DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} - hxxp://www.worldwinner.com/games/v50/pool/pool.cab DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} - hxxp://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~4\office12\GR99D3~1.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office12\GRA8E1~1.DLL ============= SERVICES / DRIVERS =============== R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-3-14 16184] R1 MpKsl5b6438fd;MpKsl5b6438fd;c:\programdata\microsoft\microsoft antimalware\definition updates\{c295a736-91a2-4620-94ff-c91b9de22c62}\MpKsl5b6438fd.sys [2011-3-15 28752] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-3-3 21504] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 43392] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-30 136176] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-11-21 1153368] S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [2008-7-7 20480] S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2008-5-9 174336] S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\verizo~1\vzacce~1\SMSIVZAM5.SYS [2009-3-20 32408] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] =============== Created Last 30 ================ 2011-03-15 03:10 –d—– c:\program files\Windows Portable Devices 2011-03-15 03:09 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2011-03-15 03:04 92,672 a——- c:\windows\system32\UIAnimation.dll 2011-03-15 03:04 1,164,800 a——- c:\windows\system32\UIRibbonRes.dll 2011-03-15 03:04 3,023,360 a——- c:\windows\system32\UIRibbon.dll 2011-03-15 03:02 555,520 a——- c:\windows\system32\UIAutomationCore.dll 2011-03-15 03:02 234,496 a——- c:\windows\system32\oleacc.dll 2011-03-15 03:02 4,096 a——- c:\windows\system32\oleaccrc.dll 2011-03-14 19:59 231,424 a——- c:\windows\system32\msshsq.dll 2011-03-14 15:18 29,520 a——- c:\windows\system32\SmartDefragBootTime.exe 2011-03-14 15:18 16,184 a——- c:\windows\system32\drivers\SmartDefragDriver.sys 2011-03-14 15:18 –d—– c:\users\michelle\appdata\roaming\IObit 2011-03-14 15:17 –d—– c:\program files\IObit 2011-03-14 14:45 –d—– c:\windows\system32\eu-ES 2011-03-14 14:45 –d—– c:\windows\system32\ca-ES 2011-03-14 14:45 –d—– c:\windows\system32\vi-VN 2011-03-14 14:44 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2011-03-14 14:13 –d—– c:\windows\system32\EventProviders 2011-03-14 09:53 –d—– c:\users\michelle\appdata\roaming\Malwarebytes 2011-03-14 09:53 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2011-03-14 09:53 –d—– c:\programdata\Malwarebytes 2011-03-14 09:53 –d—– c:\progra~2\Malwarebytes 2011-03-14 09:53 20,952 a——- c:\windows\system32\drivers\mbam.sys 2011-03-14 09:53 –d—– c:\program files\Malwarebytes' Anti-Malware 2011-03-13 19:24 1,687 a——- C:\fraglist.luar 2011-03-13 19:21 –d—– c:\windows\UltraDefrag 2011-03-13 19:14 420,352 a——- c:\windows\system32\vbscript.dll 2011-03-13 19:14 429,056 a——- c:\windows\system32\EncDec.dll 2011-03-13 19:14 322,560 a——- c:\windows\system32\sbe.dll 2011-03-13 19:14 177,664 a——- c:\windows\system32\mpg2splt.ax 2011-03-13 19:14 153,088 a——- c:\windows\system32\sbeio.dll 2011-03-13 19:14 2,067,968 a——- c:\windows\system32\mstscax.dll 2011-03-13 19:14 677,888 a——- c:\windows\system32\mstsc.exe 2011-03-13 19:14 63,488 a——- c:\windows\system32\tscupgrd.exe 2011-03-08 16:29 156,160 a——- c:\windows\system32\msls31.dll 2011-03-04 18:54 –d—– c:\program files\Defraggler 2011-03-04 04:22 18,904 a——- c:\windows\system32\StructuredQuerySchemaTrivial.bin 2011-03-04 04:22 11,967,524 a——- c:\windows\system32\korwbrkr.lex 2011-03-04 04:10 1,589,248 a——- c:\windows\system32\msjet40.dll 2011-03-04 04:09 2,167,808 a——- c:\windows\system32\mmcndmgr.dll 2011-03-04 04:08 1,580,544 a——- c:\windows\system32\wpccpl.dll 2011-03-04 04:07 744,448 a——- c:\windows\system32\wbem\wbemcore.dll 2011-03-04 04:07 614,912 a——- c:\windows\system32\wbem\fastprox.dll 2011-03-04 04:07 265,728 a——- c:\windows\system32\wbem\repdrvfs.dll 2011-03-04 04:07 265,728 a——- c:\windows\system32\wbem\esscli.dll 2011-03-04 04:07 189,440 a——- c:\windows\system32\wbem\mofd.dll 2011-03-04 04:07 83,968 a——- c:\windows\system32\wbem\wmiutils.dll 2011-03-04 04:07 30,208 a——- c:\windows\system32\wbem\wbemprox.dll 2011-03-04 04:07 705,536 a——- c:\windows\system32\SmiEngine.dll 2011-03-04 04:07 218,624 a——- c:\windows\system32\wdscore.dll 2011-03-04 04:07 130,560 a——- c:\windows\system32\PkgMgr.exe 2011-03-04 04:06 247,808 a——- c:\windows\system32\drvstore.dll 2011-03-04 04:04 2,048 a——- c:\windows\system32\winrsmgr.dll 2011-03-04 00:13 8,147,456 a——- c:\windows\system32\wmploc.DLL 2011-03-04 00:11 67,072 a——- c:\windows\system32\asycfilt.dll 2011-03-04 00:10 601,600 a——- c:\windows\system32\schedsvc.dll 2011-03-04 00:10 352,768 a——- c:\windows\system32\taskschd.dll 2011-03-04 00:10 345,600 a——- c:\windows\system32\wmicmiplugin.dll 2011-03-04 00:10 270,336 a——- c:\windows\system32\taskcomp.dll 2011-03-04 00:10 171,520 a——- c:\windows\system32\taskeng.exe 2011-03-04 00:10 81,920 a——- c:\windows\system32\consent.exe 2011-03-04 00:10 1,248,768 a——- c:\windows\system32\msxml3.dll 2011-03-04 00:10 2,048 a——- c:\windows\system32\tzres.dll 2011-03-04 00:10 292,352 a——- c:\windows\system32\atmfd.dll 2011-03-04 00:10 72,704 a——- c:\windows\system32\fontsub.dll 2011-03-04 00:10 34,304 a——- c:\windows\system32\atmlib.dll 2011-03-04 00:09 905,088 a——- c:\windows\system32\drivers\tcpip.sys 2011-03-04 00:00 739,328 a——- c:\windows\system32\inetcomm.dll 2011-03-03 23:59 531,968 a——- c:\windows\system32\comctl32.dll 2011-03-03 00:52 705,536 a——- c:\windows\system32\imagesp1.dll 2011-03-03 00:52 116,736 a——- c:\windows\system32\sstpsvc.dll 2011-03-03 00:52 1,675,264 a——- c:\windows\system32\xpssvcs.dll 2011-03-03 00:52 8,322,048 a——- c:\windows\system32\spwizimg.dll 2011-03-03 00:52 58,880 a——- c:\windows\bfsvc.exe 2011-03-03 00:52 41,472 a——- c:\windows\system32\lpremove.exe 2011-03-03 00:52 193,024 a——- c:\windows\system32\recdisc.exe 2011-03-03 00:50 805,888 a——- c:\windows\system32\cdosys.dll 2011-03-03 00:49 296,960 a——- c:\windows\system32\Wpc.dll 2011-03-03 00:48 192,000 a——- c:\windows\system32\p2phost.exe 2011-03-03 00:47 18,944 a——- c:\windows\system32\drivers\usbprint.sys 2011-03-03 00:46 102,400 a——- c:\windows\system32\wbem\mofinstall.dll 2011-03-03 00:46 357,888 a——- c:\windows\system32\wbemcomn.dll 2011-03-03 00:46 129,536 a——- c:\windows\system32\sqmapi.dll 2011-03-03 00:46 139,264 a——- c:\windows\system32\SmiInstaller.dll 2011-03-03 00:45 305,152 a——- c:\windows\system32\msdelta.dll 2011-03-03 00:45 258,560 a——- c:\windows\system32\dpx.dll 2011-03-03 00:45 35,328 a——- c:\windows\system32\mspatcha.dll 2011-03-02 23:44 –d—– C:\PerfLogs 2011-03-02 23:00 –d—– C:\42a7b66586575c331c484d 2011-03-02 22:41 –d—– c:\windows\pss 2011-03-02 22:32 –d—– c:\program files\CCleaner 2011-03-02 20:14 –d—– C:\a0d77c7ee108415b4c 2011-02-28 12:36 –d—– c:\programdata\eBaLdCb01804 2011-02-28 12:36 –d—– c:\progra~2\eBaLdCb01804 2011-02-13 14:28 –d—– c:\program files\Verizon Wireless ==================== Find3M ==================== 2011-03-15 03:10 665,600 a——- c:\windows\inf\drvindex.dat 2011-03-15 03:10 143,360 a——- c:\windows\inf\infstrng.dat 2011-03-15 03:10 86,016 a——- c:\windows\inf\infstor.dat 2011-03-15 03:10 51,200 a——- c:\windows\inf\infpub.dat 2011-03-04 18:39 27,620 a——- c:\users\michelle\appdata\roaming\nvModes.dat 2011-03-03 14:10 174 a–sh— c:\program files\desktop.ini 2011-03-03 01:15 101,888 a——- c:\windows\system32\ifxcardm.dll 2011-03-03 01:15 82,432 a——- c:\windows\system32\axaltocm.dll 2011-01-20 12:37 638,336 a——- c:\windows\system32\drivers\dxgkrnl.sys 2011-01-20 12:08 478,720 a——- c:\windows\system32\dxgi.dll 2011-01-20 12:08 1,029,120 a——- c:\windows\system32\d3d10.dll 2011-01-20 12:08 219,648 a——- c:\windows\system32\d3d10_1core.dll 2011-01-20 12:08 189,952 a——- c:\windows\system32\d3d10core.dll 2011-01-20 12:08 160,768 a——- c:\windows\system32\d3d10_1.dll 2011-01-20 12:07 37,376 a——- c:\windows\system32\cdd.dll 2011-01-20 12:07 258,048 a——- c:\windows\system32\winspool.drv 2011-01-20 12:07 586,240 a——- c:\windows\system32\stobject.dll 2011-01-20 12:06 2,873,344 a——- c:\windows\system32\mf.dll 2011-01-20 12:06 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-20 12:04 209,920 a——- c:\windows\system32\mfplat.dll 2011-01-20 12:04 98,816 a——- c:\windows\system32\mfps.dll 2011-01-20 10:28 1,554,432 a——- c:\windows\system32\xpsservices.dll 2011-01-20 10:27 876,032 a——- c:\windows\system32\XpsPrint.dll 2011-01-20 10:26 667,648 a——- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 10:25 847,360 a——- c:\windows\system32\OpcServices.dll 2011-01-20 10:24 288,768 a——- c:\windows\system32\XpsGdiConverter.dll 2011-01-20 10:24 135,680 a——- c:\windows\system32\XpsRasterService.dll 2011-01-20 10:15 979,456 a——- c:\windows\system32\MFH264Dec.dll 2011-01-20 10:14 357,376 a——- c:\windows\system32\MFHEAACdec.dll 2011-01-20 10:14 302,592 a——- c:\windows\system32\mfmp4src.dll 2011-01-20 10:14 261,632 a——- c:\windows\system32\mfreadwrite.dll 2011-01-20 10:12 1,172,480 a——- c:\windows\system32\d3d10warp.dll 2011-01-20 10:11 486,400 a——- c:\windows\system32\d3d10level9.dll 2011-01-20 09:47 683,008 a——- c:\windows\system32\d2d1.dll 2011-01-20 09:44 1,068,544 a——- c:\windows\system32\DWrite.dll 2011-01-20 09:44 797,184 a——- c:\windows\system32\FntCache.dll 2011-01-02 07:14 29,184 a——- c:\windows\system32\udefrag.exe 2011-01-02 07:14 6,144 a——- c:\windows\system32\hibernate4win.exe 2011-01-02 07:14 9,728 a——- c:\windows\system32\bootexctrl.exe 2011-01-02 07:14 31,744 a——- c:\windows\system32\udefrag.dll 2011-01-02 07:14 55,808 a——- c:\windows\system32\zenwinx.dll 2011-01-02 07:13 91,648 a——- c:\windows\system32\defrag_native.exe 2010-12-31 09:57 2,039,808 a——- c:\windows\system32\win32k.sys 2010-12-28 11:55 413,696 a——- c:\windows\system32\odbc32.dll 2010-12-18 02:27 916,480 a——- c:\windows\system32\wininet.dll 2010-12-18 02:22 43,520 a——- c:\windows\system32\licmgr10.dll 2010-12-18 02:22 109,056 a——- c:\windows\system32\iesysprep.dll 2010-12-18 02:22 71,680 a——- c:\windows\system32\iesetup.dll 2010-12-18 00:48 133,632 a——- c:\windows\system32\ieUnatt.exe 2010-11-30 21:38 56 a—h— c:\programdata\ezsidmv.dat 2010-11-30 21:38 56 a—h— c:\progra~2\ezsidmv.dat 2010-11-21 14:11 262,144 a——- c:\progra~2\ntuser.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 11:20:32.14 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 9/28/2007 4:14:25 AM System Uptime: 3/15/2011 10:58:13 AM (1 hours ago) Motherboard: Quanta | | 30CF Processor: AMD Athlon™ 64 X2 Dual-Core Processor TK-55 | Socket S1 | 1800/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 178 GiB total, 118.427 GiB free. D: is FIXED (NTFS) - 8 GiB total, 1.368 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== ==== Installed Programs ====================== µTorrent Activation Assistant for the 2007 Microsoft Office suites ActiveCheck component for HP Active Support Library Adobe Flash Player 10 ActiveX Adobe Reader 8 AOL Uninstaller (Choose which Products to Remove) Canon iP2600 series Canon iP2600 series User Registration Canon My Printer Canon Utilities Easy-PhotoPrint EX Canon Utilities Solution Menu CCleaner Conduit Engine Conexant HD Audio Defraggler Driver Detective ESU for Microsoft Vista Full Tilt Poker Google Chrome Google Toolbar for Internet Explorer Google Update Helper HDAUDIO Soft Data Fax Modem with SmartCP Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Active Support Library HP Active Support Library 32 bit components HP Customer Experience Enhancements HP Doc Viewer HP Easy Setup - Frontend HP Help and Support HP Photosmart Essential 2.0 HP Photosmart Essential2.5 HP Quick Launch Buttons 6.20 B1 HP QuickPlay 3.2 HP Total Care Advisor HP Update HP User Guides 0057 HP Wireless Assistant HPAsset component for HP Active Support Library HPNetworkAssistant Java™ SE Runtime Environment 6 LightScribe 1.6.43.1 Malwarebytes' Anti-Malware Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Antimalware Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Mobile Broadband Generic Drivers MSCU for Microsoft Vista MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) muvee autoProducer 6.0 NVIDIA Drivers PSSWCORE Rhapsody Player Engine Roxio Activation Module Roxio Creator Audio Roxio Creator Basic v9 Roxio Creator Copy Roxio Creator Data Roxio Creator EasyArchive Roxio Creator Tools Roxio Express Labeler 3 Roxio MyDVD Basic v9 RTC Client API v1.2 Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Skype Toolbars Skype™ 5.0 Smart Defrag 2 SmartAudio Spybot - Search & Destroy Synaptics Pointing Device Driver Ultra Defragmenter Update for Microsoft .NET Framework 3.5 SP1 (KB963707) uTorrentBar Toolbar Viewpoint Media Player VLC media player 1.0.1 Vongo VZAccess Manager Yahoo! BrowserPlus 2.9.8 Yahoo! Messenger Yahoo! Search Protection Yahoo! Software Update Yahoo! Toolbar Yahoo! Toolbar for Internet Explorer ==== End Of File ===========================
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
===================================================

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your  Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.

    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: 
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————

  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
I was able to turn off the real time protection from MS Essentials, but not turn it off completely. Here is the combofix report. ComboFix 11-03-16.01 - michelle 03/16/2011 14:37:47.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1982.1230 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\RelevantKnowledge c:\program files\RelevantKnowledge\chrome.manifest c:\program files\RelevantKnowledge\components\rlxg.dll c:\program files\RelevantKnowledge\install.rdf c:\program files\RelevantKnowledge\ncncf.dat c:\program files\RelevantKnowledge\nscf.dat c:\program files\RelevantKnowledge\rlls.dll c:\program files\RelevantKnowledge\rlls64.dll c:\program files\RelevantKnowledge\rloci.bin c:\program files\RelevantKnowledge\rlph.dll c:\program files\RelevantKnowledge\rlservice.exe c:\program files\RelevantKnowledge\rlvknlg.exe c:\program files\RelevantKnowledge\rlvknlg64.exe c:\program files\RelevantKnowledge\rlxf.dll c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\About RelevantKnowledge.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Privacy Policy and User License Agreement.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Support.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Uninstall Instructions.lnk c:\programdata\ntuser.dat . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_RelevantKnowledge . . ((((((((((((((((((((((((( Files Created from 2011-02-16 to 2011-03-16 ))))))))))))))))))))))))))))))) . . 2011-03-16 01:58 . 2007-03-27 19:52 20480 —-a-w- c:\windows\system32\psf.exe 2011-03-16 01:58 . 2007-03-27 19:51 24576 —-a-w- c:\windows\system32\mvistasf.exe 2011-03-16 01:58 . 2008-04-30 22:40 208994 —-a-w- c:\windows\system32\xpsf.exe 2011-03-16 01:58 . 2008-04-30 22:40 151648 —-a-w- c:\windows\system32\xpsf2.exe 2011-03-16 01:58 . 2004-04-12 21:26 151634 —-a-w- c:\windows\system32\sson.exe 2011-03-16 01:58 . 2011-03-16 01:58 ——– d—–w- c:\program files\SpeeDefrag 2011-03-16 00:49 . 2011-02-11 06:54 5943120 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E42392B3-2BEC-4F62-A3BB-BCF79F71737A}\mpengine.dll 2011-03-15 07:10 . 2011-03-15 07:10 ——– d—–w- c:\program files\Windows Portable Devices 2011-03-15 07:04 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll 2011-03-15 07:04 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll 2011-03-15 07:04 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll 2011-03-15 07:02 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll 2011-03-15 07:02 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll 2011-03-15 07:02 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll 2011-03-14 23:59 . 2010-05-04 19:13 231424 —-a-w- c:\windows\system32\msshsq.dll 2011-03-14 19:18 . 2011-03-14 19:18 ——– d—–w- c:\users\michelle\AppData\Roaming\IObit 2011-03-14 19:18 . 2011-02-23 20:52 16184 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys 2011-03-14 19:18 . 2011-02-23 20:52 29520 —-a-w- c:\windows\system32\SmartDefragBootTime.exe 2011-03-14 19:17 . 2011-03-14 19:17 ——– d—–w- c:\program files\IObit 2011-03-14 18:45 . 2011-03-14 18:46 ——– d—–w- c:\windows\system32\ca-ES 2011-03-14 18:45 . 2011-03-14 18:46 ——– d—–w- c:\windows\system32\eu-ES 2011-03-14 18:45 . 2011-03-14 18:46 ——– d—–w- c:\windows\system32\vi-VN 2011-03-14 18:13 . 2011-03-14 18:13 ——– d—–w- c:\windows\system32\EventProviders 2011-03-14 13:53 . 2011-03-14 13:53 ——– d—–w- c:\users\michelle\AppData\Roaming\Malwarebytes 2011-03-14 13:53 . 2010-12-20 22:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-03-14 13:53 . 2011-03-14 13:53 ——– d—–w- c:\programdata\Malwarebytes 2011-03-14 13:53 . 2010-12-20 22:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-03-14 13:53 . 2011-03-14 13:53 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-03-13 23:21 . 2011-03-13 23:21 ——– d—–w- c:\windows\UltraDefrag 2011-03-13 23:14 . 2010-03-05 14:01 420352 —-a-w- c:\windows\system32\vbscript.dll 2011-03-13 23:14 . 2010-12-29 18:28 322560 —-a-w- c:\windows\system32\sbe.dll 2011-03-13 23:14 . 2010-12-29 18:28 153088 —-a-w- c:\windows\system32\sbeio.dll 2011-03-13 23:14 . 2010-12-29 18:28 429056 —-a-w- c:\windows\system32\EncDec.dll 2011-03-13 23:14 . 2010-12-29 18:26 177664 —-a-w- c:\windows\system32\mpg2splt.ax 2011-03-13 23:14 . 2010-12-17 15:45 2067968 —-a-w- c:\windows\system32\mstscax.dll 2011-03-13 23:14 . 2010-12-17 13:54 677888 —-a-w- c:\windows\system32\mstsc.exe 2011-03-13 23:14 . 2009-04-11 06:28 63488 —-a-w- c:\windows\system32\tscupgrd.exe 2011-03-08 20:31 . 2010-10-19 04:27 7680 —-a-w- c:\program files\Internet Explorer\iecompat.dll 2011-03-04 22:54 . 2011-03-04 22:54 ——– d—–w- c:\program files\Defraggler 2011-03-04 08:22 . 2008-05-27 04:59 18904 —-a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin 2011-03-04 08:10 . 2009-04-11 06:28 1589248 —-a-w- c:\windows\system32\msjet40.dll 2011-03-04 08:09 . 2009-04-11 06:28 311808 —-a-w- c:\windows\system32\swprv.dll 2011-03-04 08:08 . 2009-04-11 06:28 342528 —-a-w- c:\windows\system32\zipfldr.dll 2011-03-04 08:07 . 2009-04-11 06:28 83968 —-a-w- c:\windows\system32\wbem\wmiutils.dll 2011-03-04 08:07 . 2009-04-11 06:28 744448 —-a-w- c:\windows\system32\wbem\wbemcore.dll 2011-03-04 08:07 . 2009-04-11 06:28 30208 —-a-w- c:\windows\system32\wbem\wbemprox.dll 2011-03-04 08:07 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\repdrvfs.dll 2011-03-04 08:07 . 2009-04-11 06:28 189440 —-a-w- c:\windows\system32\wbem\mofd.dll 2011-03-04 08:07 . 2009-04-11 06:28 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll 2011-03-04 08:07 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\esscli.dll 2011-03-04 08:07 . 2009-04-11 06:28 705536 —-a-w- c:\windows\system32\SmiEngine.dll 2011-03-04 08:07 . 2009-04-11 06:28 218624 —-a-w- c:\windows\system32\wdscore.dll 2011-03-04 08:07 . 2009-04-11 06:27 130560 —-a-w- c:\windows\system32\PkgMgr.exe 2011-03-04 08:06 . 2009-04-11 06:28 247808 —-a-w- c:\windows\system32\drvstore.dll 2011-03-04 08:04 . 2009-10-09 21:56 2048 —-a-w- c:\windows\system32\winrsmgr.dll 2011-03-04 04:13 . 2010-09-13 13:56 168960 —-a-w- c:\program files\Windows Media Player\wmplayer.exe 2011-03-04 04:13 . 2010-09-13 13:56 8147456 —-a-w- c:\windows\system32\wmploc.DLL 2011-03-04 04:11 . 2010-04-05 17:01 67072 —-a-w- c:\windows\system32\asycfilt.dll 2011-03-04 04:10 . 2010-11-04 18:55 352768 —-a-w- c:\windows\system32\taskschd.dll 2011-03-04 04:10 . 2010-11-04 18:55 601600 —-a-w- c:\windows\system32\schedsvc.dll 2011-03-04 04:10 . 2010-11-04 18:56 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll 2011-03-04 04:10 . 2010-11-04 18:55 270336 —-a-w- c:\windows\system32\taskcomp.dll 2011-03-04 04:10 . 2010-11-04 16:34 171520 —-a-w- c:\windows\system32\taskeng.exe 2011-03-04 04:10 . 2010-10-18 13:37 81920 —-a-w- c:\windows\system32\consent.exe 2011-03-04 04:10 . 2010-06-11 16:15 1248768 —-a-w- c:\windows\system32\msxml3.dll 2011-03-04 04:10 . 2010-10-28 13:20 2048 —-a-w- c:\windows\system32\tzres.dll 2011-03-04 04:10 . 2011-01-08 06:28 292352 —-a-w- c:\windows\system32\atmfd.dll 2011-03-04 04:10 . 2010-06-16 15:30 72704 —-a-w- c:\windows\system32\fontsub.dll 2011-03-04 04:10 . 2011-01-08 08:47 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-03-04 04:09 . 2010-06-16 16:04 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-03-04 04:00 . 2010-05-27 20:08 739328 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-04 03:59 . 2010-08-31 15:44 531968 —-a-w- c:\windows\system32\comctl32.dll 2011-03-03 04:52 . 2008-01-19 07:29 705536 —-a-w- c:\windows\system32\imagesp1.dll 2011-03-03 04:52 . 2008-01-19 07:36 116736 —-a-w- c:\windows\system32\sstpsvc.dll 2011-03-03 04:52 . 2008-01-19 07:38 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe 2011-03-03 04:52 . 2008-01-19 07:37 1675264 —-a-w- c:\windows\system32\xpssvcs.dll 2011-03-03 04:52 . 2008-01-19 07:38 671288 —-a-w- c:\program files\Windows Defender\MpRtMon.dll 2011-03-03 04:52 . 2008-01-19 07:33 41472 —-a-w- c:\windows\system32\lpremove.exe 2011-03-03 04:52 . 2008-01-19 07:33 58880 —-a-w- c:\windows\bfsvc.exe 2011-03-03 04:52 . 2008-01-19 05:31 8322048 —-a-w- c:\windows\system32\spwizimg.dll 2011-03-03 04:52 . 2008-01-19 07:33 193024 —-a-w- c:\windows\system32\recdisc.exe 2011-03-03 04:50 . 2008-01-19 07:38 90680 —-a-w- c:\program files\Windows Defender\MpOAV.dll 2011-03-03 04:49 . 2008-01-19 07:35 8203264 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwusa.dll 2011-03-03 04:48 . 2008-01-19 07:33 25088 —-a-w- c:\windows\system32\userinit.exe 2011-03-03 04:47 . 2008-01-19 07:36 8704 —-a-w- c:\windows\system32\rdpcfgex.dll 2011-03-03 04:46 . 2008-01-19 07:34 102400 —-a-w- c:\windows\system32\wbem\mofinstall.dll 2011-03-03 04:46 . 2008-01-19 07:36 357888 —-a-w- c:\windows\system32\wbemcomn.dll 2011-03-03 04:46 . 2008-01-19 07:36 129536 —-a-w- c:\windows\system32\sqmapi.dll 2011-03-03 04:46 . 2008-01-19 07:36 139264 —-a-w- c:\windows\system32\SmiInstaller.dll 2011-03-03 04:45 . 2008-01-19 07:35 35328 —-a-w- c:\windows\system32\mspatcha.dll 2011-03-03 04:45 . 2008-01-19 07:34 305152 —-a-w- c:\windows\system32\msdelta.dll 2011-03-03 04:45 . 2008-01-19 07:34 258560 —-a-w- c:\windows\system32\dpx.dll 2011-03-03 03:44 . 2011-03-03 03:44 ——– d—–w- C:\PerfLogs 2011-03-03 03:00 . 2011-03-03 07:14 ——– d—–w- C:\42a7b66586575c331c484d 2011-03-03 02:32 . 2011-03-03 02:32 ——– d—–w- c:\program files\CCleaner 2011-03-03 00:14 . 2011-03-03 00:14 ——– d—–w- C:\a0d77c7ee108415b4c 2011-02-28 16:36 . 2011-03-13 23:48 ——– d—–w- c:\programdata\eBaLdCb01804 . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-03 05:15 . 2006-11-02 10:32 101888 —-a-w- c:\windows\system32\ifxcardm.dll 2011-03-03 05:15 . 2006-11-02 10:32 82432 —-a-w- c:\windows\system32\axaltocm.dll 2011-02-11 06:54 . 2010-11-22 21:09 5943120 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-01-13 09:41 . 2011-01-30 22:05 5890896 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll 2011-01-02 11:14 . 2011-01-02 11:14 29184 —-a-w- c:\windows\system32\udefrag.exe 2011-01-02 11:14 . 2011-01-02 11:14 6144 —-a-w- c:\windows\system32\hibernate4win.exe 2011-01-02 11:14 . 2011-01-02 11:14 9728 —-a-w- c:\windows\system32\bootexctrl.exe 2011-01-02 11:14 . 2011-01-02 11:14 31744 —-a-w- c:\windows\system32\udefrag.dll 2011-01-02 11:14 . 2011-01-02 11:14 55808 —-a-w- c:\windows\system32\zenwinx.dll 2011-01-02 11:13 . 2011-01-02 11:13 91648 —-a-w- c:\windows\system32\defrag_native.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2011-01-11 21:55 3911776 —-a-w- c:\program files\ConduitEngine\ConduitEngin0.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] 2011-01-11 21:55 3911776 —-a-w- c:\program files\uTorrentBar\tbuTo1.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2011-01-11 3911776] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2011-01-11 3911776] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2011-01-11 3911776] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2011-01-11 3911776] . [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-09 8433664] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-09 81920] "WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Vongo Tray.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Vongo Tray.lnk backup=c:\windows\pss\Vongo Tray.lnk.CommonStartup backupExtension=.CommonStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [X] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start] 2006-11-10 12:12 50736 —-a-w- c:\program files\AOL 9.0\aol.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter] 2007-09-14 01:50 1603152 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu] 2007-10-26 01:10 652624 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe] 2008-01-19 07:33 125952 —-a-w- c:\windows\ehome\ehtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2006-10-27 05:47 31016 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] 2006-09-26 00:52 50736 —-a-w- c:\program files\Common Files\aol\1290613481\ee\aolsoftware.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler] 2007-03-12 18:54 50696 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2005-02-17 06:11 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launcher] 2006-11-08 00:39 44128 —-a-w- c:\windows\SMINST\Launcher.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel] 2007-04-19 20:26 484904 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)] 2010-06-01 15:17 5252408 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc] 2007-07-09 02:57 86016 —-a-w- c:\windows\System32\nvsvc.dll . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService] 2007-04-24 01:11 176128 —-a-w- c:\program files\HP\QuickPlay\QPService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar] 2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2010-10-11 21:49 14940040 —-a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] 2009-03-05 20:07 2260480 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2007-08-04 11:36 77824 —-a-w- c:\program files\Java\jre1.6.0\bin\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2010-12-01 01:37 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] 2007-01-13 03:36 827392 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R1 MpKsl1eec5296;MpKsl1eec5296;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FCADBE9C-B2BB-4A3C-BA58-67E5AD2C7BC1}\MpKsl1eec5296.sys [x] R1 MpKsl7598c270;MpKsl7598c270;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DF13F61D-71CA-4902-9C99-F7267E65491D}\MpKsl7598c270.sys [x] R1 MpKsl83dadb68;MpKsl83dadb68;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FCADBE9C-B2BB-4A3C-BA58-67E5AD2C7BC1}\MpKsl83dadb68.sys [x] R1 MpKsle0628ed7;MpKsle0628ed7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C37CACAF-7AB9-4E14-8107-A4C1FA6CCBD6}\MpKsle0628ed7.sys [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 136176] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392] R3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\DRIVERS\NwUsbCdFil.sys [2008-07-07 20480] R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2008-05-09 174336] R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [2009-03-21 32408] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2007-04-19 20:23 452136 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2011-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 01:36] . 2011-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 01:36] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html LSP: c:\windows\system32\wpclsp.dll . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e} - (no file) WebBrowser-{B9D63C58-90CC-428B-8D3B-CBB88EB07E7E} - (no file) HKLM-Run-QlbCtrl - %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe HKLM-Run-hpWirelessAssistant - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe HKLM-Run-WAWifiMessage - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe MSConfigStartUp-eBaLdCb01804 - c:\programdata\eBaLdCb01804\eBaLdCb01804.exe AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:\program files\RelevantKnowledge\rlvknlg.exe . . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe . ************************************************************************** . Completion time: 2011-03-16 14:54:37 - machine was rebooted ComboFix-quarantined-files.txt 2011-03-16 18:54 . Pre-Run: 140,046,798,848 bytes free Post-Run: 139,603,480,576 bytes free . - - End Of File - - AD660F20088EA22C165D0884EA57E2FD
Hi sLeven7,

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

DirLook::
c:\programdata\eBaLdCb01804
C:\a0d77c7ee108415b4c
C:\42a7b66586575c331c484d
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste

===================================================

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.

How is your computer running now?
It is running better today than it has in a while. Here is the scan report and second combo report.

C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlls.dll.vir a variant of Win32/Adware.RK application
C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlservice.exe.vir probably a variant of Win32/Adware.RK.AD application
C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlvknlg.exe.vir probably a variant of Win32/Genetik trojan


ComboFix 11-03-16.01 - michelle 03/16/2011 16:48:52.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1982.1232 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\michelle\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
.
.
((((((((((((((((((((((((( Files Created from 2011-02-16 to 2011-03-16 )))))))))))))))))))))))))))))))
.
.
2011-03-16 20:57 . 2011-03-16 20:57 ——– d—–w- c:\users\michelle\AppData\Local\temp
2011-03-16 20:57 . 2011-03-16 20:57 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-03-16 19:22 . 2011-03-16 19:22 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{788DAF20-8616-472F-A4CD-E1A4A9EA88B7}\MpKslb5702754.sys
2011-03-16 19:22 . 2011-02-11 06:54 5943120 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{788DAF20-8616-472F-A4CD-E1A4A9EA88B7}\mpengine.dll
2011-03-16 01:58 . 2007-03-27 19:52 20480 —-a-w- c:\windows\system32\psf.exe
2011-03-16 01:58 . 2007-03-27 19:51 24576 —-a-w- c:\windows\system32\mvistasf.exe
2011-03-16 01:58 . 2008-04-30 22:40 208994 —-a-w- c:\windows\system32\xpsf.exe
2011-03-16 01:58 . 2008-04-30 22:40 151648 —-a-w- c:\windows\system32\xpsf2.exe
2011-03-16 01:58 . 2004-04-12 21:26 151634 —-a-w- c:\windows\system32\sson.exe
2011-03-16 01:58 . 2011-03-16 01:58 ——– d—–w- c:\program files\SpeeDefrag
2011-03-15 07:10 . 2011-03-15 07:10 ——– d—–w- c:\program files\Windows Portable Devices
2011-03-15 07:04 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2011-03-15 07:04 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2011-03-15 07:04 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2011-03-15 07:02 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-03-15 07:02 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll
2011-03-15 07:02 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-03-14 23:59 . 2010-05-04 19:13 231424 —-a-w- c:\windows\system32\msshsq.dll
2011-03-14 19:18 . 2011-03-14 19:18 ——– d—–w- c:\users\michelle\AppData\Roaming\IObit
2011-03-14 19:18 . 2011-02-23 20:52 16184 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-03-14 19:18 . 2011-02-23 20:52 29520 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-03-14 19:17 . 2011-03-14 19:17 ——– d—–w- c:\program files\IObit
2011-03-14 18:45 . 2011-03-14 18:46 ——– d—–w- c:\windows\system32\ca-ES
2011-03-14 18:45 . 2011-03-14 18:46 ——– d—–w- c:\windows\system32\eu-ES
2011-03-14 18:45 . 2011-03-14 18:46 ——– d—–w- c:\windows\system32\vi-VN
2011-03-14 18:13 . 2011-03-14 18:13 ——– d—–w- c:\windows\system32\EventProviders
2011-03-14 13:53 . 2011-03-14 13:53 ——– d—–w- c:\users\michelle\AppData\Roaming\Malwarebytes
2011-03-14 13:53 . 2010-12-20 22:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-14 13:53 . 2011-03-14 13:53 ——– d—–w- c:\programdata\Malwarebytes
2011-03-14 13:53 . 2010-12-20 22:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-03-14 13:53 . 2011-03-14 13:53 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-03-13 23:21 . 2011-03-13 23:21 ——– d—–w- c:\windows\UltraDefrag
2011-03-13 23:14 . 2010-03-05 14:01 420352 —-a-w- c:\windows\system32\vbscript.dll
2011-03-13 23:14 . 2010-12-29 18:28 322560 —-a-w- c:\windows\system32\sbe.dll
2011-03-13 23:14 . 2010-12-29 18:28 153088 —-a-w- c:\windows\system32\sbeio.dll
2011-03-13 23:14 . 2010-12-29 18:28 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-03-13 23:14 . 2010-12-29 18:26 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2011-03-13 23:14 . 2010-12-17 15:45 2067968 —-a-w- c:\windows\system32\mstscax.dll
2011-03-13 23:14 . 2010-12-17 13:54 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-03-13 23:14 . 2009-04-11 06:28 63488 —-a-w- c:\windows\system32\tscupgrd.exe
2011-03-08 20:31 . 2010-10-19 04:27 7680 —-a-w- c:\program files\Internet Explorer\iecompat.dll
2011-03-04 22:54 . 2011-03-16 20:10 ——– d—–w- c:\program files\Defraggler
2011-03-04 08:22 . 2008-05-27 04:59 18904 —-a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2011-03-04 08:10 . 2009-04-11 06:28 1589248 —-a-w- c:\windows\system32\msjet40.dll
2011-03-04 08:09 . 2009-04-11 06:28 311808 —-a-w- c:\windows\system32\swprv.dll
2011-03-04 08:08 . 2009-04-11 06:28 342528 —-a-w- c:\windows\system32\zipfldr.dll
2011-03-04 08:07 . 2009-04-11 06:28 83968 —-a-w- c:\windows\system32\wbem\wmiutils.dll
2011-03-04 08:07 . 2009-04-11 06:28 744448 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2011-03-04 08:07 . 2009-04-11 06:28 30208 —-a-w- c:\windows\system32\wbem\wbemprox.dll
2011-03-04 08:07 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\repdrvfs.dll
2011-03-04 08:07 . 2009-04-11 06:28 189440 —-a-w- c:\windows\system32\wbem\mofd.dll
2011-03-04 08:07 . 2009-04-11 06:28 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll
2011-03-04 08:07 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\esscli.dll
2011-03-04 08:07 . 2009-04-11 06:28 705536 —-a-w- c:\windows\system32\SmiEngine.dll
2011-03-04 08:07 . 2009-04-11 06:28 218624 —-a-w- c:\windows\system32\wdscore.dll
2011-03-04 08:07 . 2009-04-11 06:27 130560 —-a-w- c:\windows\system32\PkgMgr.exe
2011-03-04 08:06 . 2009-04-11 06:28 247808 —-a-w- c:\windows\system32\drvstore.dll
2011-03-04 08:04 . 2009-10-09 21:56 2048 —-a-w- c:\windows\system32\winrsmgr.dll
2011-03-04 04:13 . 2010-09-13 13:56 168960 —-a-w- c:\program files\Windows Media Player\wmplayer.exe
2011-03-04 04:13 . 2010-09-13 13:56 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2011-03-04 04:11 . 2010-04-05 17:01 67072 —-a-w- c:\windows\system32\asycfilt.dll
2011-03-04 04:10 . 2010-11-04 18:55 352768 —-a-w- c:\windows\system32\taskschd.dll
2011-03-04 04:10 . 2010-11-04 18:55 601600 —-a-w- c:\windows\system32\schedsvc.dll
2011-03-04 04:10 . 2010-11-04 18:56 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll
2011-03-04 04:10 . 2010-11-04 18:55 270336 —-a-w- c:\windows\system32\taskcomp.dll
2011-03-04 04:10 . 2010-11-04 16:34 171520 —-a-w- c:\windows\system32\taskeng.exe
2011-03-04 04:10 . 2010-10-18 13:37 81920 —-a-w- c:\windows\system32\consent.exe
2011-03-04 04:10 . 2010-06-11 16:15 1248768 —-a-w- c:\windows\system32\msxml3.dll
2011-03-04 04:10 . 2010-10-28 13:20 2048 —-a-w- c:\windows\system32\tzres.dll
2011-03-04 04:10 . 2011-01-08 06:28 292352 —-a-w- c:\windows\system32\atmfd.dll
2011-03-04 04:10 . 2010-06-16 15:30 72704 —-a-w- c:\windows\system32\fontsub.dll
2011-03-04 04:10 . 2011-01-08 08:47 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-03-04 04:09 . 2010-06-16 16:04 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-03-04 04:00 . 2010-05-27 20:08 739328 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 03:59 . 2010-08-31 15:44 531968 —-a-w- c:\windows\system32\comctl32.dll
2011-03-03 04:52 . 2008-01-19 07:29 705536 —-a-w- c:\windows\system32\imagesp1.dll
2011-03-03 04:52 . 2008-01-19 07:36 116736 —-a-w- c:\windows\system32\sstpsvc.dll
2011-03-03 04:52 . 2008-01-19 07:38 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
2011-03-03 04:52 . 2008-01-19 07:37 1675264 —-a-w- c:\windows\system32\xpssvcs.dll
2011-03-03 04:52 . 2008-01-19 07:38 671288 —-a-w- c:\program files\Windows Defender\MpRtMon.dll
2011-03-03 04:52 . 2008-01-19 07:33 41472 —-a-w- c:\windows\system32\lpremove.exe
2011-03-03 04:52 . 2008-01-19 07:33 58880 —-a-w- c:\windows\bfsvc.exe
2011-03-03 04:52 . 2008-01-19 05:31 8322048 —-a-w- c:\windows\system32\spwizimg.dll
2011-03-03 04:52 . 2008-01-19 07:33 193024 —-a-w- c:\windows\system32\recdisc.exe
2011-03-03 04:50 . 2008-01-19 07:38 90680 —-a-w- c:\program files\Windows Defender\MpOAV.dll
2011-03-03 04:49 . 2008-01-19 07:35 8203264 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwusa.dll
2011-03-03 04:48 . 2008-01-19 07:33 25088 —-a-w- c:\windows\system32\userinit.exe
2011-03-03 04:47 . 2008-01-19 07:36 8704 —-a-w- c:\windows\system32\rdpcfgex.dll
2011-03-03 04:46 . 2008-01-19 07:34 102400 —-a-w- c:\windows\system32\wbem\mofinstall.dll
2011-03-03 04:46 . 2008-01-19 07:36 357888 —-a-w- c:\windows\system32\wbemcomn.dll
2011-03-03 04:46 . 2008-01-19 07:36 129536 —-a-w- c:\windows\system32\sqmapi.dll
2011-03-03 04:46 . 2008-01-19 07:36 139264 —-a-w- c:\windows\system32\SmiInstaller.dll
2011-03-03 04:45 . 2008-01-19 07:35 35328 —-a-w- c:\windows\system32\mspatcha.dll
2011-03-03 04:45 . 2008-01-19 07:34 305152 —-a-w- c:\windows\system32\msdelta.dll
2011-03-03 04:45 . 2008-01-19 07:34 258560 —-a-w- c:\windows\system32\dpx.dll
2011-03-03 03:44 . 2011-03-03 03:44 ——– d—–w- C:\PerfLogs
2011-03-03 03:00 . 2011-03-03 07:14 ——– d—–w- C:\42a7b66586575c331c484d
2011-03-03 02:32 . 2011-03-03 02:32 ——– d—–w- c:\program files\CCleaner
2011-03-03 00:14 . 2011-03-03 00:14 ——– d—–w- C:\a0d77c7ee108415b4c
2011-02-28 16:36 . 2011-03-13 23:48 ——– d—–w- c:\programdata\eBaLdCb01804
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-03 05:15 . 2006-11-02 10:32 101888 —-a-w- c:\windows\system32\ifxcardm.dll
2011-03-03 05:15 . 2006-11-02 10:32 82432 —-a-w- c:\windows\system32\axaltocm.dll
2011-02-11 06:54 . 2010-11-22 21:09 5943120 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-01-13 09:41 . 2011-01-30 22:05 5890896 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-01-02 11:14 . 2011-01-02 11:14 29184 —-a-w- c:\windows\system32\udefrag.exe
2011-01-02 11:14 . 2011-01-02 11:14 6144 —-a-w- c:\windows\system32\hibernate4win.exe
2011-01-02 11:14 . 2011-01-02 11:14 9728 —-a-w- c:\windows\system32\bootexctrl.exe
2011-01-02 11:14 . 2011-01-02 11:14 31744 —-a-w- c:\windows\system32\udefrag.dll
2011-01-02 11:14 . 2011-01-02 11:14 55808 —-a-w- c:\windows\system32\zenwinx.dll
2011-01-02 11:13 . 2011-01-02 11:13 91648 —-a-w- c:\windows\system32\defrag_native.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\42a7b66586575c331c484d —-
.
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\zh-hk\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\zh-tw\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\tr-tr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\uk-ua\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\zh-cn\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\sv-se\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\th-th\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\sk-sk\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\sl-si\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\sr-latn-cs\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\pt-pt\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\ro-ro\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\ru-ru\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\pl-pl\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\pt-br\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\lv-lv\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\nb-no\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\nl-nl\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\ja-jp\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\ko-kr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\lt-lt\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\hr-hr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\hu-hu\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\it-it\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\fi-fi\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\fr-fr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\he-il\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\es-es\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\et-ee\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\de-de\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\el-gr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\en-us\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\da-dk\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\cs-cz\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 131072 —-a-w- c:\42a7b66586575c331c484d\ar-sa\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\bg-bg\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 152576 —-a-w- c:\42a7b66586575c331c484d\spwizui.dll
2011-03-03 03:00 . 2011-03-03 03:00 50688 —-a-w- c:\42a7b66586575c331c484d\spclite.exe
.
—- Directory of C:\a0d77c7ee108415b4c —-
.
2011-03-03 00:14 . 2011-03-03 00:14 131072 —-a-w- c:\a0d77c7ee108415b4c\ar-sa\spwizui.dll.mui
2011-03-03 00:14 . 2011-03-03 00:14 20480 —-a-w- c:\a0d77c7ee108415b4c\bg-bg\spwizui.dll.mui
2011-03-03 00:14 . 2011-03-03 00:14 20480 —-a-w- c:\a0d77c7ee108415b4c\cs-cz\spwizui.dll.mui
2011-03-03 00:14 . 2011-03-03 00:14 152576 —-a-w- c:\a0d77c7ee108415b4c\spwizui.dll
2011-03-03 00:14 . 2011-03-03 00:14 50688 —-a-w- c:\a0d77c7ee108415b4c\spclite.exe
.
—- Directory of c:\programdata\eBaLdCb01804 —-
.
2011-02-28 16:36 . 2011-03-03 01:54 98 —-a-w- c:\programdata\eBaLdCb01804\eBaLdCb01804
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-11 21:55 3911776 —-a-w- c:\program files\ConduitEngine\ConduitEngin0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-01-11 21:55 3911776 —-a-w- c:\program files\uTorrentBar\tbuTo1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2011-01-11 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2011-01-11 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2011-01-11 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2011-01-11 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-09 8433664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-09 81920]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Vongo Tray.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Vongo Tray.lnk
backup=c:\windows\pss\Vongo Tray.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2006-11-10 12:12 50736 —-a-w- c:\program files\AOL 9.0\aol.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-09-14 01:50 1603152 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-10-26 01:10 652624 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 05:47 31016 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-09-26 00:52 50736 —-a-w- c:\program files\Common Files\aol\1290613481\ee\aolsoftware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2007-03-12 18:54 50696 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-17 06:11 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launcher]
2006-11-08 00:39 44128 —-a-w- c:\windows\SMINST\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-04-19 20:26 484904 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-06-01 15:17 5252408 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2007-07-09 02:57 86016 —-a-w- c:\windows\System32\nvsvc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-04-24 01:11 176128 —-a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 21:49 14940040 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-08-04 11:36 77824 —-a-w- c:\program files\Java\jre1.6.0\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-12-01 01:37 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-01-13 03:36 827392 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R1 MpKsl1eec5296;MpKsl1eec5296;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FCADBE9C-B2BB-4A3C-BA58-67E5AD2C7BC1}\MpKsl1eec5296.sys [x]
R1 MpKsl7598c270;MpKsl7598c270;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DF13F61D-71CA-4902-9C99-F7267E65491D}\MpKsl7598c270.sys [x]
R1 MpKsl83dadb68;MpKsl83dadb68;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FCADBE9C-B2BB-4A3C-BA58-67E5AD2C7BC1}\MpKsl83dadb68.sys [x]
R1 MpKsle0628ed7;MpKsle0628ed7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C37CACAF-7AB9-4E14-8107-A4C1FA6CCBD6}\MpKsle0628ed7.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 136176]
R3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\DRIVERS\NwUsbCdFil.sys [2008-07-07 20480]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2008-05-09 174336]
R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [2009-03-21 32408]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
S1 MpKslb5702754;MpKslb5702754;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{788DAF20-8616-472F-A4CD-E1A4A9EA88B7}\MpKslb5702754.sys [2011-03-16 28752]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLB5702754
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 20:23 452136 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 01:36]
.
2011-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 01:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-16 16:57
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-03-16 16:59:31
ComboFix-quarantined-files.txt 2011-03-16 20:59
ComboFix2.txt 2011-03-16 18:54
.
Pre-Run: 138,023,337,984 bytes free
Post-Run: 137,982,808,064 bytes free
.
- - End Of File - - C5F4AA25F78F85FEED3A31B758600706
It is running better today than it has in a while. Here is the scan report and second combo report.

C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlls.dll.vir a variant of Win32/Adware.RK application
C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlservice.exe.vir probably a variant of Win32/Adware.RK.AD application
C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlvknlg.exe.vir probably a variant of Win32/Genetik trojan


ComboFix 11-03-16.01 - michelle 03/16/2011 16:48:52.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1982.1232 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\michelle\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
.
.
((((((((((((((((((((((((( Files Created from 2011-02-16 to 2011-03-16 )))))))))))))))))))))))))))))))
.
.
2011-03-16 20:57 . 2011-03-16 20:57 ——– d—–w- c:\users\michelle\AppData\Local\temp
2011-03-16 20:57 . 2011-03-16 20:57 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-03-16 19:22 . 2011-03-16 19:22 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{788DAF20-8616-472F-A4CD-E1A4A9EA88B7}\MpKslb5702754.sys
2011-03-16 19:22 . 2011-02-11 06:54 5943120 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{788DAF20-8616-472F-A4CD-E1A4A9EA88B7}\mpengine.dll
2011-03-16 01:58 . 2007-03-27 19:52 20480 —-a-w- c:\windows\system32\psf.exe
2011-03-16 01:58 . 2007-03-27 19:51 24576 —-a-w- c:\windows\system32\mvistasf.exe
2011-03-16 01:58 . 2008-04-30 22:40 208994 —-a-w- c:\windows\system32\xpsf.exe
2011-03-16 01:58 . 2008-04-30 22:40 151648 —-a-w- c:\windows\system32\xpsf2.exe
2011-03-16 01:58 . 2004-04-12 21:26 151634 —-a-w- c:\windows\system32\sson.exe
2011-03-16 01:58 . 2011-03-16 01:58 ——– d—–w- c:\program files\SpeeDefrag
2011-03-15 07:10 . 2011-03-15 07:10 ——– d—–w- c:\program files\Windows Portable Devices
2011-03-15 07:04 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2011-03-15 07:04 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2011-03-15 07:04 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2011-03-15 07:02 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-03-15 07:02 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll
2011-03-15 07:02 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-03-14 23:59 . 2010-05-04 19:13 231424 —-a-w- c:\windows\system32\msshsq.dll
2011-03-14 19:18 . 2011-03-14 19:18 ——– d—–w- c:\users\michelle\AppData\Roaming\IObit
2011-03-14 19:18 . 2011-02-23 20:52 16184 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-03-14 19:18 . 2011-02-23 20:52 29520 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-03-14 19:17 . 2011-03-14 19:17 ——– d—–w- c:\program files\IObit
2011-03-14 18:45 . 2011-03-14 18:46 ——– d—–w- c:\windows\system32\ca-ES
2011-03-14 18:45 . 2011-03-14 18:46 ——– d—–w- c:\windows\system32\eu-ES
2011-03-14 18:45 . 2011-03-14 18:46 ——– d—–w- c:\windows\system32\vi-VN
2011-03-14 18:13 . 2011-03-14 18:13 ——– d—–w- c:\windows\system32\EventProviders
2011-03-14 13:53 . 2011-03-14 13:53 ——– d—–w- c:\users\michelle\AppData\Roaming\Malwarebytes
2011-03-14 13:53 . 2010-12-20 22:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-14 13:53 . 2011-03-14 13:53 ——– d—–w- c:\programdata\Malwarebytes
2011-03-14 13:53 . 2010-12-20 22:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-03-14 13:53 . 2011-03-14 13:53 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-03-13 23:21 . 2011-03-13 23:21 ——– d—–w- c:\windows\UltraDefrag
2011-03-13 23:14 . 2010-03-05 14:01 420352 —-a-w- c:\windows\system32\vbscript.dll
2011-03-13 23:14 . 2010-12-29 18:28 322560 —-a-w- c:\windows\system32\sbe.dll
2011-03-13 23:14 . 2010-12-29 18:28 153088 —-a-w- c:\windows\system32\sbeio.dll
2011-03-13 23:14 . 2010-12-29 18:28 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-03-13 23:14 . 2010-12-29 18:26 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2011-03-13 23:14 . 2010-12-17 15:45 2067968 —-a-w- c:\windows\system32\mstscax.dll
2011-03-13 23:14 . 2010-12-17 13:54 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-03-13 23:14 . 2009-04-11 06:28 63488 —-a-w- c:\windows\system32\tscupgrd.exe
2011-03-08 20:31 . 2010-10-19 04:27 7680 —-a-w- c:\program files\Internet Explorer\iecompat.dll
2011-03-04 22:54 . 2011-03-16 20:10 ——– d—–w- c:\program files\Defraggler
2011-03-04 08:22 . 2008-05-27 04:59 18904 —-a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2011-03-04 08:10 . 2009-04-11 06:28 1589248 —-a-w- c:\windows\system32\msjet40.dll
2011-03-04 08:09 . 2009-04-11 06:28 311808 —-a-w- c:\windows\system32\swprv.dll
2011-03-04 08:08 . 2009-04-11 06:28 342528 —-a-w- c:\windows\system32\zipfldr.dll
2011-03-04 08:07 . 2009-04-11 06:28 83968 —-a-w- c:\windows\system32\wbem\wmiutils.dll
2011-03-04 08:07 . 2009-04-11 06:28 744448 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2011-03-04 08:07 . 2009-04-11 06:28 30208 —-a-w- c:\windows\system32\wbem\wbemprox.dll
2011-03-04 08:07 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\repdrvfs.dll
2011-03-04 08:07 . 2009-04-11 06:28 189440 —-a-w- c:\windows\system32\wbem\mofd.dll
2011-03-04 08:07 . 2009-04-11 06:28 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll
2011-03-04 08:07 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\esscli.dll
2011-03-04 08:07 . 2009-04-11 06:28 705536 —-a-w- c:\windows\system32\SmiEngine.dll
2011-03-04 08:07 . 2009-04-11 06:28 218624 —-a-w- c:\windows\system32\wdscore.dll
2011-03-04 08:07 . 2009-04-11 06:27 130560 —-a-w- c:\windows\system32\PkgMgr.exe
2011-03-04 08:06 . 2009-04-11 06:28 247808 —-a-w- c:\windows\system32\drvstore.dll
2011-03-04 08:04 . 2009-10-09 21:56 2048 —-a-w- c:\windows\system32\winrsmgr.dll
2011-03-04 04:13 . 2010-09-13 13:56 168960 —-a-w- c:\program files\Windows Media Player\wmplayer.exe
2011-03-04 04:13 . 2010-09-13 13:56 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2011-03-04 04:11 . 2010-04-05 17:01 67072 —-a-w- c:\windows\system32\asycfilt.dll
2011-03-04 04:10 . 2010-11-04 18:55 352768 —-a-w- c:\windows\system32\taskschd.dll
2011-03-04 04:10 . 2010-11-04 18:55 601600 —-a-w- c:\windows\system32\schedsvc.dll
2011-03-04 04:10 . 2010-11-04 18:56 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll
2011-03-04 04:10 . 2010-11-04 18:55 270336 —-a-w- c:\windows\system32\taskcomp.dll
2011-03-04 04:10 . 2010-11-04 16:34 171520 —-a-w- c:\windows\system32\taskeng.exe
2011-03-04 04:10 . 2010-10-18 13:37 81920 —-a-w- c:\windows\system32\consent.exe
2011-03-04 04:10 . 2010-06-11 16:15 1248768 —-a-w- c:\windows\system32\msxml3.dll
2011-03-04 04:10 . 2010-10-28 13:20 2048 —-a-w- c:\windows\system32\tzres.dll
2011-03-04 04:10 . 2011-01-08 06:28 292352 —-a-w- c:\windows\system32\atmfd.dll
2011-03-04 04:10 . 2010-06-16 15:30 72704 —-a-w- c:\windows\system32\fontsub.dll
2011-03-04 04:10 . 2011-01-08 08:47 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-03-04 04:09 . 2010-06-16 16:04 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-03-04 04:00 . 2010-05-27 20:08 739328 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 03:59 . 2010-08-31 15:44 531968 —-a-w- c:\windows\system32\comctl32.dll
2011-03-03 04:52 . 2008-01-19 07:29 705536 —-a-w- c:\windows\system32\imagesp1.dll
2011-03-03 04:52 . 2008-01-19 07:36 116736 —-a-w- c:\windows\system32\sstpsvc.dll
2011-03-03 04:52 . 2008-01-19 07:38 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
2011-03-03 04:52 . 2008-01-19 07:37 1675264 —-a-w- c:\windows\system32\xpssvcs.dll
2011-03-03 04:52 . 2008-01-19 07:38 671288 —-a-w- c:\program files\Windows Defender\MpRtMon.dll
2011-03-03 04:52 . 2008-01-19 07:33 41472 —-a-w- c:\windows\system32\lpremove.exe
2011-03-03 04:52 . 2008-01-19 07:33 58880 —-a-w- c:\windows\bfsvc.exe
2011-03-03 04:52 . 2008-01-19 05:31 8322048 —-a-w- c:\windows\system32\spwizimg.dll
2011-03-03 04:52 . 2008-01-19 07:33 193024 —-a-w- c:\windows\system32\recdisc.exe
2011-03-03 04:50 . 2008-01-19 07:38 90680 —-a-w- c:\program files\Windows Defender\MpOAV.dll
2011-03-03 04:49 . 2008-01-19 07:35 8203264 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwusa.dll
2011-03-03 04:48 . 2008-01-19 07:33 25088 —-a-w- c:\windows\system32\userinit.exe
2011-03-03 04:47 . 2008-01-19 07:36 8704 —-a-w- c:\windows\system32\rdpcfgex.dll
2011-03-03 04:46 . 2008-01-19 07:34 102400 —-a-w- c:\windows\system32\wbem\mofinstall.dll
2011-03-03 04:46 . 2008-01-19 07:36 357888 —-a-w- c:\windows\system32\wbemcomn.dll
2011-03-03 04:46 . 2008-01-19 07:36 129536 —-a-w- c:\windows\system32\sqmapi.dll
2011-03-03 04:46 . 2008-01-19 07:36 139264 —-a-w- c:\windows\system32\SmiInstaller.dll
2011-03-03 04:45 . 2008-01-19 07:35 35328 —-a-w- c:\windows\system32\mspatcha.dll
2011-03-03 04:45 . 2008-01-19 07:34 305152 —-a-w- c:\windows\system32\msdelta.dll
2011-03-03 04:45 . 2008-01-19 07:34 258560 —-a-w- c:\windows\system32\dpx.dll
2011-03-03 03:44 . 2011-03-03 03:44 ——– d—–w- C:\PerfLogs
2011-03-03 03:00 . 2011-03-03 07:14 ——– d—–w- C:\42a7b66586575c331c484d
2011-03-03 02:32 . 2011-03-03 02:32 ——– d—–w- c:\program files\CCleaner
2011-03-03 00:14 . 2011-03-03 00:14 ——– d—–w- C:\a0d77c7ee108415b4c
2011-02-28 16:36 . 2011-03-13 23:48 ——– d—–w- c:\programdata\eBaLdCb01804
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-03 05:15 . 2006-11-02 10:32 101888 —-a-w- c:\windows\system32\ifxcardm.dll
2011-03-03 05:15 . 2006-11-02 10:32 82432 —-a-w- c:\windows\system32\axaltocm.dll
2011-02-11 06:54 . 2010-11-22 21:09 5943120 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-01-13 09:41 . 2011-01-30 22:05 5890896 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-01-02 11:14 . 2011-01-02 11:14 29184 —-a-w- c:\windows\system32\udefrag.exe
2011-01-02 11:14 . 2011-01-02 11:14 6144 —-a-w- c:\windows\system32\hibernate4win.exe
2011-01-02 11:14 . 2011-01-02 11:14 9728 —-a-w- c:\windows\system32\bootexctrl.exe
2011-01-02 11:14 . 2011-01-02 11:14 31744 —-a-w- c:\windows\system32\udefrag.dll
2011-01-02 11:14 . 2011-01-02 11:14 55808 —-a-w- c:\windows\system32\zenwinx.dll
2011-01-02 11:13 . 2011-01-02 11:13 91648 —-a-w- c:\windows\system32\defrag_native.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\42a7b66586575c331c484d —-
.
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\zh-hk\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\zh-tw\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\tr-tr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\uk-ua\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\zh-cn\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\sv-se\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\th-th\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\sk-sk\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\sl-si\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\sr-latn-cs\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\pt-pt\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\ro-ro\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\ru-ru\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\pl-pl\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\pt-br\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\lv-lv\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\nb-no\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\nl-nl\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\ja-jp\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\ko-kr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\lt-lt\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\hr-hr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\hu-hu\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\it-it\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\fi-fi\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\fr-fr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 16384 —-a-w- c:\42a7b66586575c331c484d\he-il\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\es-es\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\et-ee\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\de-de\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\el-gr\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\en-us\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\da-dk\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\cs-cz\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 131072 —-a-w- c:\42a7b66586575c331c484d\ar-sa\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 20480 —-a-w- c:\42a7b66586575c331c484d\bg-bg\spwizui.dll.mui
2011-03-03 03:00 . 2011-03-03 03:00 152576 —-a-w- c:\42a7b66586575c331c484d\spwizui.dll
2011-03-03 03:00 . 2011-03-03 03:00 50688 —-a-w- c:\42a7b66586575c331c484d\spclite.exe
.
—- Directory of C:\a0d77c7ee108415b4c —-
.
2011-03-03 00:14 . 2011-03-03 00:14 131072 —-a-w- c:\a0d77c7ee108415b4c\ar-sa\spwizui.dll.mui
2011-03-03 00:14 . 2011-03-03 00:14 20480 —-a-w- c:\a0d77c7ee108415b4c\bg-bg\spwizui.dll.mui
2011-03-03 00:14 . 2011-03-03 00:14 20480 —-a-w- c:\a0d77c7ee108415b4c\cs-cz\spwizui.dll.mui
2011-03-03 00:14 . 2011-03-03 00:14 152576 —-a-w- c:\a0d77c7ee108415b4c\spwizui.dll
2011-03-03 00:14 . 2011-03-03 00:14 50688 —-a-w- c:\a0d77c7ee108415b4c\spclite.exe
.
—- Directory of c:\programdata\eBaLdCb01804 —-
.
2011-02-28 16:36 . 2011-03-03 01:54 98 —-a-w- c:\programdata\eBaLdCb01804\eBaLdCb01804
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-11 21:55 3911776 —-a-w- c:\program files\ConduitEngine\ConduitEngin0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-01-11 21:55 3911776 —-a-w- c:\program files\uTorrentBar\tbuTo1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2011-01-11 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2011-01-11 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2011-01-11 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2011-01-11 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-09 8433664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-09 81920]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Vongo Tray.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Vongo Tray.lnk
backup=c:\windows\pss\Vongo Tray.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2006-11-10 12:12 50736 —-a-w- c:\program files\AOL 9.0\aol.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-09-14 01:50 1603152 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-10-26 01:10 652624 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 05:47 31016 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-09-26 00:52 50736 —-a-w- c:\program files\Common Files\aol\1290613481\ee\aolsoftware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2007-03-12 18:54 50696 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-17 06:11 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launcher]
2006-11-08 00:39 44128 —-a-w- c:\windows\SMINST\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-04-19 20:26 484904 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-06-01 15:17 5252408 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2007-07-09 02:57 86016 —-a-w- c:\windows\System32\nvsvc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-04-24 01:11 176128 —-a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 21:49 14940040 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-08-04 11:36 77824 —-a-w- c:\program files\Java\jre1.6.0\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-12-01 01:37 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-01-13 03:36 827392 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R1 MpKsl1eec5296;MpKsl1eec5296;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FCADBE9C-B2BB-4A3C-BA58-67E5AD2C7BC1}\MpKsl1eec5296.sys [x]
R1 MpKsl7598c270;MpKsl7598c270;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DF13F61D-71CA-4902-9C99-F7267E65491D}\MpKsl7598c270.sys [x]
R1 MpKsl83dadb68;MpKsl83dadb68;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FCADBE9C-B2BB-4A3C-BA58-67E5AD2C7BC1}\MpKsl83dadb68.sys [x]
R1 MpKsle0628ed7;MpKsle0628ed7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C37CACAF-7AB9-4E14-8107-A4C1FA6CCBD6}\MpKsle0628ed7.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 136176]
R3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\DRIVERS\NwUsbCdFil.sys [2008-07-07 20480]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2008-05-09 174336]
R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [2009-03-21 32408]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
S1 MpKslb5702754;MpKslb5702754;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{788DAF20-8616-472F-A4CD-E1A4A9EA88B7}\MpKslb5702754.sys [2011-03-16 28752]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLB5702754
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 20:23 452136 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 01:36]
.
2011-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 01:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-16 16:57
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-03-16 16:59:31
ComboFix-quarantined-files.txt 2011-03-16 20:59
ComboFix2.txt 2011-03-16 18:54
.
Pre-Run: 138,023,337,984 bytes free
Post-Run: 137,982,808,064 bytes free
.
- - End Of File - - C5F4AA25F78F85FEED3A31B758600706
Hi sLeven7

Great! :)

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: c:\programdata\eBaLdCb01804\eBaLdCb01804
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: eBaLdCb01804 Submission date: 2011-03-16 23:45:10 (UTC) Current status: finished Result: 0/ 43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.03.17.00 2011.03.16 - AntiVir 7.11.4.235 2011.03.16 - Antiy-AVL 2.0.3.7 2011.03.16 - Avast 4.8.1351.0 2011.03.16 - Avast5 5.0.677.0 2011.03.16 - AVG 10.0.0.1190 2011.03.16 - BitDefender 7.2 2011.03.16 - CAT-QuickHeal 11.00 2011.03.16 - ClamAV 0.96.4.0 2011.03.16 - Commtouch 5.2.11.5 2011.03.16 - Comodo 8006 2011.03.16 - DrWeb 5.0.2.03300 2011.03.17 - Emsisoft 5.1.0.2 2011.03.16 - eSafe 7.0.17.0 2011.03.16 - eTrust-Vet 36.1.8219 2011.03.16 - F-Prot 4.6.2.117 2011.03.16 - F-Secure 9.0.16440.0 2011.03.16 - Fortinet 4.2.254.0 2011.03.16 - GData 21 2011.03.16 - Ikarus T3.1.1.97.0 2011.03.16 - Jiangmin 13.0.900 2011.03.16 - K7AntiVirus 9.93.4128 2011.03.16 - Kaspersky 7.0.0.125 2011.03.17 - McAfee 5.400.0.1158 2011.03.16 - McAfee-GW-Edition 2010.1C 2011.03.16 - Microsoft 1.6603 2011.03.16 - NOD32 5960 2011.03.16 - Norman 6.07.03 2011.03.16 - nProtect 2011-02-10.01 2011.02.15 - Panda 10.0.3.5 2011.03.16 - PCTools 7.0.3.5 2011.03.11 - Prevx 3.0 2011.03.17 - Rising 23.49.02.06 2011.03.16 - Sophos 4.63.0 2011.03.16 - SUPERAntiSpyware 4.40.0.1006 2011.03.16 - Symantec 20101.3.0.103 2011.03.16 - TheHacker 6.7.0.1.150 2011.03.16 - TrendMicro 9.200.0.1012 2011.03.16 - TrendMicro-HouseCall 9.200.0.1012 2011.03.17 - VBA32 3.12.14.3 2011.03.16 - VIPRE 8726 2011.03.16 - ViRobot 2011.3.16.4360 2011.03.16 - VirusBuster 13.6.252.0 2011.03.16 - Additional informationShow all MD5 : ae178af15631d076baff267c4d917256 SHA1 : 1d6b87ce25fac089f898a704d86a2266b465c9fc SHA256: 7d6fd9d0d7523e6597bc18b332175fbd3046cd026bca556382e02583a0f37ee0 ssdeep: 3:6vwkLmhNhuR5WThQVsEVQamM:6vyNhq5WTmVsEVQaP File size : 98 bytes First seen: 2011-03-16 23:45:10 Last seen : 2011-03-16 23:45:10 TrID: Unknown! sigcheck: publisher….: n/a copyright….: n/a product……: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments…..: n/a signers……: - signing date.: - verified…..: Unsigned VT Community
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: eBaLdCb01804 Submission date: 2011-03-16 23:45:10 (UTC) Current status: finished Result: 0/ 43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.03.17.00 2011.03.16 - AntiVir 7.11.4.235 2011.03.16 - Antiy-AVL 2.0.3.7 2011.03.16 - Avast 4.8.1351.0 2011.03.16 - Avast5 5.0.677.0 2011.03.16 - AVG 10.0.0.1190 2011.03.16 - BitDefender 7.2 2011.03.16 - CAT-QuickHeal 11.00 2011.03.16 - ClamAV 0.96.4.0 2011.03.16 - Commtouch 5.2.11.5 2011.03.16 - Comodo 8006 2011.03.16 - DrWeb 5.0.2.03300 2011.03.17 - Emsisoft 5.1.0.2 2011.03.16 - eSafe 7.0.17.0 2011.03.16 - eTrust-Vet 36.1.8219 2011.03.16 - F-Prot 4.6.2.117 2011.03.16 - F-Secure 9.0.16440.0 2011.03.16 - Fortinet 4.2.254.0 2011.03.16 - GData 21 2011.03.16 - Ikarus T3.1.1.97.0 2011.03.16 - Jiangmin 13.0.900 2011.03.16 - K7AntiVirus 9.93.4128 2011.03.16 - Kaspersky 7.0.0.125 2011.03.17 - McAfee 5.400.0.1158 2011.03.16 - McAfee-GW-Edition 2010.1C 2011.03.16 - Microsoft 1.6603 2011.03.16 - NOD32 5960 2011.03.16 - Norman 6.07.03 2011.03.16 - nProtect 2011-02-10.01 2011.02.15 - Panda 10.0.3.5 2011.03.16 - PCTools 7.0.3.5 2011.03.11 - Prevx 3.0 2011.03.17 - Rising 23.49.02.06 2011.03.16 - Sophos 4.63.0 2011.03.16 - SUPERAntiSpyware 4.40.0.1006 2011.03.16 - Symantec 20101.3.0.103 2011.03.16 - TheHacker 6.7.0.1.150 2011.03.16 - TrendMicro 9.200.0.1012 2011.03.16 - TrendMicro-HouseCall 9.200.0.1012 2011.03.17 - VBA32 3.12.14.3 2011.03.16 - VIPRE 8726 2011.03.16 - ViRobot 2011.3.16.4360 2011.03.16 - VirusBuster 13.6.252.0 2011.03.16 - Additional informationShow all MD5 : ae178af15631d076baff267c4d917256 SHA1 : 1d6b87ce25fac089f898a704d86a2266b465c9fc SHA256: 7d6fd9d0d7523e6597bc18b332175fbd3046cd026bca556382e02583a0f37ee0 ssdeep: 3:6vwkLmhNhuR5WThQVsEVQamM:6vyNhq5WTmVsEVQaP File size : 98 bytes First seen: 2011-03-16 23:45:10 Last seen : 2011-03-16 23:45:10 TrID: Unknown! sigcheck: publisher….: n/a copyright….: n/a product……: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments…..: n/a signers……: - signing date.: - verified…..: Unsigned VT Community
sLeven7,

Did you run ESET?

If not, follow these instructions:

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
This is all eset gave me C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlls.dll.vir a variant of Win32/Adware.RK application C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlservice.exe.vir probably a variant of Win32/Adware.RK.AD application C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlvknlg.exe.vir probably a variant of Win32/Genetik trojan
Hi sLeven7,

:smack: Sorry, I missed that.

Well, your computer appears to be clean! :) Are you still having any issues defragmenting?

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

===================================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 23.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u23-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.

===================================================

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • Click Start > Run
  • Type Inetcpl.cpl and click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected and Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to Prompt, and ("Initialize and Script ActiveX controls not marked as safe") to Disable.
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update   regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
The computer is running much better than it was. My girl friend's job calls her of of town on a regular basis so I was unable to take the very last steps you suggested. I will do the updates as soon as she returns. Thank you for the help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI