This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC acting strange?

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys. Recently my computer has been acting a bit strange, running slow, and occcasionally not loading webpages correctly. I ran scans with both MBAM and AVAST AV which both came up with nothing. I decided to do an ESET online scan which came up with this C:\Users\Chrissy\Downloads\registrybooster.exe a variant of Win32/RegistryBooster application deleted - quarantined I was wondering if anybody could enlighten me on what exactly this was, and if it may have been the cause of the problems I have been having. I have also run a DDS scan to be sure there is nothing lurking deep within lol. As always, thankyou in advance for your time and trouble Chrissy. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 18:36:52.76 on Sat 09/04/2011 Internet Explorer: 8.0.6001.19019 BrowserJavaVersion: 1.6.0_24 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.2036.923 [GMT 8:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Program Files\AVAST Software\Avast\afwServ.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Dell\DellDock\DellDock.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Windows\ehome\ehmsas.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Secunia\PSI\psi.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Users\Chrissy\Downloads\dds(1).scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearch Page = uStart Page = hxxp://ninemsn.com.au/ uSearch Bar = Preserve uWindow Title = Internet Explorer provided by Dell uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://au.search.yahoo.com/search?fr=mcafee&p;=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [iLike] c:\program files\ilike\1.2.18\ilikesidebar.exe /checkforupdate uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [Nero MediaHome 4] "c:\program files\nero\nero mediahome 4\NeroMediaHome.exe" /AUTORUN mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background StartupFolder: c:\users\chrissy\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe StartupFolder: c:\users\chrissy\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\chrissy\appdata\roaming\dropbox\bin\Dropbox.exe StartupFolder: c:\users\chrissy\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll LSP: c:\windows\system32\wpclsp.dll Trusted Zone: internet Trusted Zone: mcafee.com DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/mjss/MJSS.cab109791.cab DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\users\chrissy\appdata\roaming\mozilla\firefox\profiles\109c60ll.default\ FF - prefs.js: browser.search.selectedEngine - Secure Search FF - prefs.js: browser.startup.homepage - hxxp://ninemsn.com.au FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?fr=mcafee&p;= FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60129.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\chrissy\appdata\local\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [2011-3-14 12112] R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [2011-3-14 192728] R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [2011-3-14 101976] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-14 371544] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-3-14 301528] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-3-14 19544] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-3-14 53592] R2 avast! Firewall;avast! Firewall;c:\program files\avast software\avast\afwServ.exe [2011-3-14 121000] R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-5-2 161048] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504] R2 NeroMediaHomeService.4;Nero MediaHome 4 Service;c:\program files\nero\nero mediahome 4\NMMediaServerService.exe [2009-6-23 259368] R2 SeaPort;SeaPort;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-2-25 249648] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2010-9-21 1710464] R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-7-7 14904] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-5 135664] S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-2-28 183560] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-24 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-10-21 30192] S3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2010-11-18 21744] S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2005-10-27 30464] S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2005-10-27 12672] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] =============== Created Last 30 ================ 2011-03-24 04:02 –d—– c:\program files\Microsoft 2011-03-23 10:59 1,068,544 a——- c:\windows\system32\DWrite.dll 2011-03-23 10:59 797,696 a——- c:\windows\system32\FntCache.dll 2011-03-23 10:59 288,768 a——- c:\windows\system32\XpsGdiConverter.dll 2011-03-17 20:51 216,906,079 a——- c:\windows\MEMORY.DMP 2011-03-14 21:25 101,976 a——- c:\windows\system32\drivers\aswFW.sys 2011-03-14 21:24 192,728 a——- c:\windows\system32\drivers\aswNdis2.sys 2011-03-14 21:24 371,544 a——- c:\windows\system32\drivers\aswSnx.sys 2011-03-14 21:24 53,592 a——- c:\windows\system32\drivers\aswMonFlt.sys 2011-03-14 21:23 12,112 a——- c:\windows\system32\drivers\aswNdis.sys 2011-03-14 21:23 40,648 a——- c:\windows\avastSS.scr 2011-03-14 21:23 –d—– c:\programdata\AVAST Software 2011-03-14 21:23 –d—– c:\program files\AVAST Software 2011-03-14 21:23 –d—– c:\progra~2\AVAST Software 2011-03-11 09:12 –d—– c:\program files\iPod 2011-03-11 09:12 –d—– c:\program files\iTunes ==================== Find3M ==================== 2011-04-01 07:56 117 a——- c:\users\chrissy\jagex_runescape_preferences2.dat 2011-04-01 07:56 46 a——- c:\users\chrissy\jagex_runescape_preferences.dat 2011-03-14 21:25 143,360 a——- c:\windows\inf\infstrng.dat 2011-03-14 21:25 51,200 a——- c:\windows\inf\infpub.dat 2011-03-14 21:25 143,360 a——- c:\windows\inf\infstor.dat 2011-03-14 11:13 18,086 a——- c:\users\chrissy\appdata\roaming\wklnhst.dat 2011-02-24 08:05 472,808 a——- c:\windows\system32\deployJava1.dll 2011-02-02 18:11 222,080 ——– c:\windows\system32\MpSigStub.exe 2011-01-21 00:08 478,720 a——- c:\windows\system32\dxgi.dll 2011-01-21 00:08 1,029,120 a——- c:\windows\system32\d3d10.dll 2011-01-21 00:08 219,648 a——- c:\windows\system32\d3d10_1core.dll 2011-01-21 00:08 189,952 a——- c:\windows\system32\d3d10core.dll 2011-01-21 00:08 160,768 a——- c:\windows\system32\d3d10_1.dll 2011-01-21 00:07 37,376 a——- c:\windows\system32\cdd.dll 2011-01-21 00:07 258,048 a——- c:\windows\system32\winspool.drv 2011-01-21 00:07 586,240 a——- c:\windows\system32\stobject.dll 2011-01-21 00:06 2,873,344 a——- c:\windows\system32\mf.dll 2011-01-21 00:06 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-21 00:04 209,920 a——- c:\windows\system32\mfplat.dll 2011-01-21 00:04 98,816 a——- c:\windows\system32\mfps.dll 2011-01-20 22:28 1,554,432 a——- c:\windows\system32\xpsservices.dll 2011-01-20 22:27 876,032 a——- c:\windows\system32\XpsPrint.dll 2011-01-20 22:26 667,648 a——- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 22:25 847,360 a——- c:\windows\system32\OpcServices.dll 2011-01-20 22:24 135,680 a——- c:\windows\system32\XpsRasterService.dll 2011-01-20 22:15 979,456 a——- c:\windows\system32\MFH264Dec.dll 2011-01-20 22:14 357,376 a——- c:\windows\system32\MFHEAACdec.dll 2011-01-20 22:14 302,592 a——- c:\windows\system32\mfmp4src.dll 2011-01-20 22:14 261,632 a——- c:\windows\system32\mfreadwrite.dll 2011-01-20 22:12 1,172,480 a——- c:\windows\system32\d3d10warp.dll 2011-01-20 22:11 486,400 a——- c:\windows\system32\d3d10level9.dll 2011-01-20 21:47 683,008 a——- c:\windows\system32\d2d1.dll 2010-10-04 19:05 50 a——- c:\users\chrissy\jagex__preferences3.dat 2009-11-30 04:19 665,600 a——- c:\windows\inf\drvindex.dat 2008-01-21 10:43 174 a–sh— c:\program files\desktop.ini 2007-07-25 14:02 836,608 a——- c:\program files\Pivot 3.0 Beta.exe 2006-11-02 20:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 20:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 20:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 20:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 17:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 17:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 17:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 17:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2010-08-29 20:35 262,144 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat ============= FINISH: 18:37:33.27 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 21/10/2008 11:27:54 AM System Uptime: 4/03/2011 3:20:44 PM (867 hours ago) Motherboard: Dell Inc. | | 0RY007 Processor: Intel® Pentium® Dual CPU E2180 @ 2.00GHz | Socket 775 | 2000/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 139 GiB total, 83.198 GiB free. D: is FIXED (NTFS) - 10 GiB total, 5.118 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1105: 20/03/2011 12:08:01 AM - Scheduled Checkpoint RP1106: 22/03/2011 3:06:14 PM - Windows Update RP1107: 24/03/2011 4:00:16 AM - Windows Update RP1108: 25/03/2011 12:00:04 AM - Scheduled Checkpoint RP1109: 25/03/2011 4:00:14 AM - Windows Update RP1110: 25/03/2011 10:33:44 PM - Windows Update RP1111: 27/03/2011 1:00:53 AM - Scheduled Checkpoint RP1112: 29/03/2011 6:08:38 AM - Scheduled Checkpoint RP1113: 30/03/2011 12:07:24 AM - Windows Update RP1114: 31/03/2011 4:00:11 AM - Windows Update RP1115: 2/04/2011 2:01:21 AM - Windows Update RP1116: 3/04/2011 5:44:54 PM - Scheduled Checkpoint RP1117: 5/04/2011 3:44:28 PM - Windows Update RP1118: 8/04/2011 3:44:29 PM - Windows Update ==== Installed Programs ====================== 101 Kid's Brainy Games Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.4.3 Adobe Shockwave Player 11.5 Advertising Center Apple Application Support Apple Mobile Device Support Apple Software Update avast! Internet Security BigPond Broadband ADSL Bing Bar Bonjour Browser Address Error Redirector Compatibility Pack for the 2007 Office system Conexant D850 PCI V.92 Modem D3DX10 Dell-eBay Dell Dock Dell Getting Started Guide Dell Support Center Digital Line Detect Driver Updater Pro Dropbox e-tax 2010 EDocs ERUNT 1.1j Google Desktop Google Toolbar for Internet Explorer Google Update Helper GoToAssist 8.0.0.514 Highlight Viewer (Windows Live Toolbar) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel® PRO Network Connections 12.1.11.0 iTunes Java Auto Updater Java™ 6 Update 24 Junk Mail filter update Kid's Maths Quest LG PC Suite LG USB Modem driver Malwarebytes' Anti-Malware Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works MobileMe Control Panel Modem Diagnostic Tool Mozilla Firefox 4.0 (x86 en-GB) MSVCRT Nero ControlCenter Nero Installer Nero MediaHome 4 Nero MediaHome 4 Essentials Nero MediaHome 4 Help Nero Online Upgrade NetWaiting OGA Notifier 2.0.0048.0 PokerStars QuickTime Realtek High Definition Audio Driver Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager Safari Secunia PSI Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Segoe UI Smart Menus (Windows Live Toolbar) Tony Hawk's Pro Skater 3® Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Windows Driver Package - Atheros Communications Inc. (arusb_lh) Net (09/25/2008 3.1.0.101) Windows Driver Package - NETGEAR Inc. (RTLWUSB) Net (03/27/2006 5.1213.06.0327) Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live Favorites for Windows Live Toolbar Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Messenger Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live Toolbar Extension (Windows Live Toolbar) Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Yahoo! BrowserPlus 2.9.8 ==== End Of File =========================== Im not sure if the problems are still persisting since running the ESET scan as the symptoms were only happening occasionally and I havnt used the PC much since then. Another important thing I forgot to mention was it crashed suddenly a few weeks back and closed itself down, apparently due to a bluescreen error???? It has only done this once. EDIT: I just realised after reading my log that windows defender was still activated even though I turned it off when I installed AVAST AV 3 weeks ago. I have disabled it again, but could this have been what has been causing these problems? (eg 2 AV's running at the same time). EDIT: Still experiencing occasional problems such as slow loading, and non loading webpages.
Hi again chrissy72,

Registry Booster isn't so much malware as it is snake oil. However, I doubt that it is the cause of your problems.

I really not seeing anything… but let's give comboFix a pass through just to see what it shows.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 11-04-11.04 - Chrissy 12/04/2011 23:35:25.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.2036.945 [GMT 8:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\PCDr\5744\Downloads\2da1393a-9d2c-436b-a660-c3dd133e9836.dll
c:\programdata\PCDr\5744\Downloads\48edbc2f-6595-43d2-a911-c3713e9b499f.dll
c:\programdata\PCDr\5744\Downloads\5275e755-7d9f-4ddb-a61e-645d687f55e1.dll
c:\programdata\PCDr\5744\Downloads\86fa80c6-799b-4d0b-a3f5-f7886c10db2c.dll
c:\programdata\PCDr\5744\Downloads\f6b10855-5837-4857-9c20-c7b6a6dc2589.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-12 to 2011-04-12 )))))))))))))))))))))))))))))))
.
.
2011-04-12 15:43 . 2011-04-12 15:43 ——– d—–w- c:\users\NeroMediaHomeUser.4\AppData\Local\temp
2011-04-12 15:43 . 2011-04-12 15:43 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-04-08 07:46 . 2011-03-15 04:05 6792528 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1A56CD6C-84A0-450F-8224-167013D8618C}\mpengine.dll
2011-04-06 14:45 . 2011-04-06 14:46 ——– d—–w- c:\users\Chrissy\AppData\Local\{653E0CC7-01FB-4B7A-8DFF-5D69B0F68516}
2011-04-03 07:22 . 2011-04-03 07:22 ——– d—–w- c:\users\Chrissy\AppData\Local\{5411368F-3255-455F-BE04-1EE2B5894A2D}
2011-03-24 00:36 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-03-24 00:36 . 2011-03-18 17:57 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-03-24 00:36 . 2011-03-18 17:57 728024 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-03-24 00:36 . 2011-03-18 17:57 1975768 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-03-24 00:36 . 2011-03-18 17:57 1893336 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-03-24 00:36 . 2011-03-18 17:57 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-03-24 00:36 . 2011-03-18 17:57 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-03-24 00:36 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-03-23 20:02 . 2011-03-23 20:02 ——– d—–w- c:\program files\Microsoft
2011-03-23 02:59 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-23 02:59 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-23 02:59 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-03-14 13:26 . 2011-02-23 14:54 19544 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-03-14 13:26 . 2011-02-23 14:56 301528 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-03-14 13:25 . 2011-02-23 14:57 101976 —-a-w- c:\windows\system32\drivers\aswFW.sys
2011-03-14 13:24 . 2011-02-23 14:56 192728 —-a-w- c:\windows\system32\drivers\aswNdis2.sys
2011-03-14 13:24 . 2011-02-23 14:55 25432 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-03-14 13:24 . 2011-02-23 14:55 49240 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-03-14 13:24 . 2011-02-23 14:56 371544 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-03-14 13:24 . 2011-02-23 14:55 53592 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-03-14 13:23 . 2011-02-23 13:34 12112 —-a-w- c:\windows\system32\drivers\aswNdis.sys
2011-03-14 13:23 . 2011-02-23 15:04 40648 —-a-w- c:\windows\avastSS.scr
2011-03-14 13:23 . 2011-02-23 15:04 190016 —-a-w- c:\windows\system32\aswBoot.exe
2011-03-14 13:23 . 2011-03-14 13:23 ——– d—–w- c:\programdata\AVAST Software
2011-03-14 13:23 . 2011-03-14 13:23 ——– d—–w- c:\program files\AVAST Software
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-14 12:30 . 2010-06-24 03:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-09 21:33 . 2011-03-09 21:33 341256 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-02-24 00:05 . 2010-04-18 15:56 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-02 10:11 . 2009-10-02 18:10 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:37 . 2011-02-09 03:19 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-02-09 03:19 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-02-09 03:19 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-09 03:19 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08 . 2011-02-09 03:19 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-02-09 03:19 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07 . 2011-02-09 03:19 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-02-09 03:19 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-02-09 03:19 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-02-09 03:19 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-02-09 03:19 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-02-09 03:19 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-02-09 03:19 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-02-09 03:19 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-02-09 03:19 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-02-09 03:19 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-02-09 03:19 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-02-09 03:19 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-09 03:19 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-09 03:19 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-09 03:19 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:14 . 2011-02-09 03:19 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:12 . 2011-02-09 03:19 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-02-09 03:19 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-02-09 03:19 683008 —-a-w- c:\windows\system32\d2d1.dll
2007-07-25 06:02 . 2009-05-10 12:22 836608 —-a-w- c:\program files\Pivot 3.0 Beta.exe
2011-03-18 17:57 . 2011-03-24 00:36 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-06-21 15:58 . 2010-06-21 15:58 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-09 4240760]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-20 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 4452352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-22 133656]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-21 30192]
"Nero MediaHome 4"="c:\program files\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2009-06-23 4891944]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-09 4240760]
.
c:\users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]
Dropbox.lnk - c:\users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-10-21 50688]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-20 19:47 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2011-02-23 121000]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-21 30192]
R3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2005-10-26 30464]
R3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2005-10-26 12672]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2011-02-23 12112]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-05-02 161048]
S3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2010-11-18 21744]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-07-07 14904]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - PCDSRVC{E9D79540-57D5953E-06020101}_0
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 23:48]
.
2011-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 23:48]
.
2011-04-03 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-11-18 15:13]
.
2011-04-10 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-11-18 15:13]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ninemsn.com.au/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://au.search.yahoo.com/search?fr=mcafee&p=%s
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\users\Chrissy\AppData\Roaming\Mozilla\Firefox\Profiles\109c60ll.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://ninemsn.com.au
FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?fr=mcafee&p=
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKCU-Run-iLike - c:\program files\iLike\1.2.18\ilikesidebar.exe
HKLM-Run-dellsupportcenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-12 23:43
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr = "c:\program files\Windows Live\Messenger\msnmsgr.exe" /background??s
.
scanning hidden files …
.
.
C:\## aswSnx private storage
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-04-12 23:46:06
ComboFix-quarantined-files.txt 2011-04-12 15:46
.
Pre-Run: 89,765,859,328 bytes free
Post-Run: 89,629,237,248 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 19B6CAE7A5113256AC1131D9A5BABE61
chrissy72,

Just a little tweaking:

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    Trusted Zone: internet
    Trusted Zone: mcafee.com
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Thankyou TomK. :D
Here is the log.

ComboFix 11-04-12.01 - Chrissy 13/04/2011 6:50.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.2036.1016 [GMT 8:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\Chrissy\Desktop\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\PCDr\5744\Downloads\2da1393a-9d2c-436b-a660-c3dd133e9836.dll
c:\programdata\PCDr\5744\Downloads\48edbc2f-6595-43d2-a911-c3713e9b499f.dll
c:\programdata\PCDr\5744\Downloads\61963b16-da7a-4faf-ba6b-14eb102d0df8.dll
c:\programdata\PCDr\5744\Downloads\86fa80c6-799b-4d0b-a3f5-f7886c10db2c.dll
c:\programdata\PCDr\5744\Downloads\f6b10855-5837-4857-9c20-c7b6a6dc2589.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-12 to 2011-04-12 )))))))))))))))))))))))))))))))
.
.
2011-04-12 22:56 . 2011-04-12 22:56 ——– d—–w- c:\users\NeroMediaHomeUser.4\AppData\Local\temp
2011-04-12 22:56 . 2011-04-12 22:56 ——– d—–w- c:\users\Jeana\AppData\Local\temp
2011-04-12 22:56 . 2011-04-12 22:56 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-04-12 15:55 . 2011-04-12 15:56 ——– d—–w- c:\users\Chrissy\AppData\Local\{0E0423FA-EF75-4BC7-83F1-99F4B33BB1EC}
2011-04-08 07:46 . 2011-03-15 04:05 6792528 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1A56CD6C-84A0-450F-8224-167013D8618C}\mpengine.dll
2011-04-06 14:45 . 2011-04-06 14:46 ——– d—–w- c:\users\Chrissy\AppData\Local\{653E0CC7-01FB-4B7A-8DFF-5D69B0F68516}
2011-04-03 07:22 . 2011-04-03 07:22 ——– d—–w- c:\users\Chrissy\AppData\Local\{5411368F-3255-455F-BE04-1EE2B5894A2D}
2011-03-24 00:36 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-03-24 00:36 . 2011-03-18 17:57 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-03-24 00:36 . 2011-03-18 17:57 728024 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-03-24 00:36 . 2011-03-18 17:57 1975768 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-03-24 00:36 . 2011-03-18 17:57 1893336 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-03-24 00:36 . 2011-03-18 17:57 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-03-24 00:36 . 2011-03-18 17:57 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-03-24 00:36 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-03-23 20:02 . 2011-03-23 20:02 ——– d—–w- c:\program files\Microsoft
2011-03-23 02:59 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-23 02:59 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-23 02:59 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-03-14 13:26 . 2011-02-23 14:54 19544 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-03-14 13:26 . 2011-02-23 14:56 301528 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-03-14 13:25 . 2011-02-23 14:57 101976 —-a-w- c:\windows\system32\drivers\aswFW.sys
2011-03-14 13:24 . 2011-02-23 14:56 192728 —-a-w- c:\windows\system32\drivers\aswNdis2.sys
2011-03-14 13:24 . 2011-02-23 14:55 25432 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-03-14 13:24 . 2011-02-23 14:55 49240 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-03-14 13:24 . 2011-02-23 14:56 371544 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-03-14 13:24 . 2011-02-23 14:55 53592 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-03-14 13:23 . 2011-02-23 13:34 12112 —-a-w- c:\windows\system32\drivers\aswNdis.sys
2011-03-14 13:23 . 2011-02-23 15:04 40648 —-a-w- c:\windows\avastSS.scr
2011-03-14 13:23 . 2011-02-23 15:04 190016 —-a-w- c:\windows\system32\aswBoot.exe
2011-03-14 13:23 . 2011-03-14 13:23 ——– d—–w- c:\programdata\AVAST Software
2011-03-14 13:23 . 2011-03-14 13:23 ——– d—–w- c:\program files\AVAST Software
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-14 12:30 . 2010-06-24 03:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-09 21:33 . 2011-03-09 21:33 341256 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-02-24 00:05 . 2010-04-18 15:56 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-02 10:11 . 2009-10-02 18:10 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:37 . 2011-02-09 03:19 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-02-09 03:19 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-02-09 03:19 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-09 03:19 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08 . 2011-02-09 03:19 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-02-09 03:19 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07 . 2011-02-09 03:19 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-02-09 03:19 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-02-09 03:19 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-02-09 03:19 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-02-09 03:19 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-02-09 03:19 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-02-09 03:19 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-02-09 03:19 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-02-09 03:19 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-02-09 03:19 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-02-09 03:19 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-02-09 03:19 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-09 03:19 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-09 03:19 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-09 03:19 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:14 . 2011-02-09 03:19 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:12 . 2011-02-09 03:19 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-02-09 03:19 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-02-09 03:19 683008 —-a-w- c:\windows\system32\d2d1.dll
2007-07-25 06:02 . 2009-05-10 12:22 836608 —-a-w- c:\program files\Pivot 3.0 Beta.exe
2011-03-18 17:57 . 2011-03-24 00:36 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-06-21 15:58 . 2010-06-21 15:58 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-09 4240760]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-20 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 4452352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-22 133656]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-21 30192]
"Nero MediaHome 4"="c:\program files\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2009-06-23 4891944]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-09 4240760]
.
c:\users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]
Dropbox.lnk - c:\users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-10-21 50688]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-20 19:47 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2011-02-23 121000]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-21 30192]
R3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2005-10-26 30464]
R3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2005-10-26 12672]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2011-02-23 12112]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-05-02 161048]
S3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2010-11-18 21744]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-07-07 14904]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 23:48]
.
2011-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 23:48]
.
2011-04-03 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-11-18 15:13]
.
2011-04-12 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-11-18 15:13]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ninemsn.com.au/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://au.search.yahoo.com/search?fr=mcafee&p;=%s
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath - c:\users\Chrissy\AppData\Roaming\Mozilla\Firefox\Profiles\109c60ll.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://ninemsn.com.au
FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?fr=mcafee&p;=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-13 06:57
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr = "c:\program files\Windows Live\Messenger\msnmsgr.exe" /background??s
.
scanning hidden files …
.
.
C:\## aswSnx private storage
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-04-13 06:59:56
ComboFix-quarantined-files.txt 2011-04-12 22:59
ComboFix2.txt 2011-04-12 15:46
.
Pre-Run: 89,803,075,584 bytes free
Post-Run: 89,771,479,040 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - EEFEB5CD1565A533823BD25F5FA6A66C
I havnt had any problems lately with pages not loading, apart from being slow at times, it seems to take a lot longer than usual for them to close down too. A friend has told me that this could be due to having so much unnecessary "junk" at startup? But I have no idea what exactly I should be getting rid of. Once Ive gotten the all clear from you I will ask the techies what I should be getting rid of, if that may be the cause of my problems. Oh and I forgot to mention that since doing that second combofix, my internet icon in my system tray is showing that I am not connected to the internet even though I am lol :scratch:
chrissy72, Here are the things that I'd get rid of (or at least consider): Bing toolbar or Google toolbar (or both) Google toolbar notifier Google browser helper redirector Sweet IM toolbar Microsoft Media Center Tray bar iLike sidebar EULALauncher (related to Google toolbar) Pokerstars If there are any of these that you don't want (not all of them will be in your uninstall list) let me know and I'll help you "nuke" them.
Out of that list, I would like to keep pokerstars as I play there occasionally, but apart from that , the rest can go. I found and uninstalled Bing bar, but was unable to find the rest. Also, I just went to a page and although it looked as though it was properly loaded, the little loading icon kept spinning around for about 10 minutes? Oh and my internet icon in the system tray is still showing up as disconnected even tho the internet is connected?
chrissy72,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
    uRun: [iLike] c:\program files\ilike\1.2.18\ilikesidebar.exe /checkforupdate
    mRun: [ECenter]
    mRun: [RtHDVCpl]
    mRun: [Adobe Reader Speed Launcher]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then give this a try:

Click on Start, then Programs\Accessories and right click on Command Prompt, select "Run as Administrator" to open a command prompt.

Type netsh winsock reset catalog then press enter

Type netsh int ipv4 reset reset.log then press enter

type netsh int ipv6 reset reset.log then press enter

type Exit then press enter

Reboot the machine.

Does your internet icon read correct now?
Thankyou TomK.

ComboFix 11-04-13.02 - Chrissy 14/04/2011 8:54.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.2036.1054 [GMT 8:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\Chrissy\Desktop\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\dell\bae\BAE.dll
c:\program files\google\google toolbar\GoogleToolbar_32.dll
c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll
c:\programdata\PCDr\5744\Downloads\38db339b-86cf-40c4-86da-57495513b374.dll
c:\programdata\PCDr\5744\Downloads\70b66070-48fe-4fad-ac33-5f17042d5ee7.dll
c:\programdata\PCDr\5744\Downloads\890823c6-b297-4c5e-8839-80468e0508dc.dll
c:\programdata\PCDr\5744\Downloads\b0ad9f03-890a-4558-bcd7-38c10ea44def.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-14 to 2011-04-14 )))))))))))))))))))))))))))))))
.
.
2011-04-14 01:00 . 2011-04-14 01:03 ——– d—–w- c:\users\NeroMediaHomeUser.4\AppData\Local\temp
2011-04-14 01:00 . 2011-04-14 01:00 ——– d—–w- c:\users\Jeana\AppData\Local\temp
2011-04-14 01:00 . 2011-04-14 01:00 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-04-12 15:55 . 2011-04-12 15:56 ——– d—–w- c:\users\Chrissy\AppData\Local\{0E0423FA-EF75-4BC7-83F1-99F4B33BB1EC}
2011-04-08 07:46 . 2011-03-15 04:05 6792528 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1A56CD6C-84A0-450F-8224-167013D8618C}\mpengine.dll
2011-04-06 14:45 . 2011-04-06 14:46 ——– d—–w- c:\users\Chrissy\AppData\Local\{653E0CC7-01FB-4B7A-8DFF-5D69B0F68516}
2011-04-03 07:22 . 2011-04-03 07:22 ——– d—–w- c:\users\Chrissy\AppData\Local\{5411368F-3255-455F-BE04-1EE2B5894A2D}
2011-03-24 00:36 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-03-24 00:36 . 2011-03-18 17:57 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-03-24 00:36 . 2011-03-18 17:57 728024 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-03-24 00:36 . 2011-03-18 17:57 1975768 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-03-24 00:36 . 2011-03-18 17:57 1893336 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-03-24 00:36 . 2011-03-18 17:57 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-03-24 00:36 . 2011-03-18 17:57 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-03-24 00:36 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-03-23 20:02 . 2011-04-13 07:54 ——– d—–w- c:\program files\Microsoft
2011-03-23 02:59 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-23 02:59 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-23 02:59 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-14 12:30 . 2010-06-24 03:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-09 21:33 . 2011-03-09 21:33 341256 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-02-24 00:05 . 2010-04-18 15:56 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-23 15:04 . 2011-03-14 13:23 40648 —-a-w- c:\windows\avastSS.scr
2011-02-23 15:04 . 2011-03-14 13:23 190016 —-a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:57 . 2011-03-14 13:25 101976 —-a-w- c:\windows\system32\drivers\aswFW.sys
2011-02-23 14:56 . 2011-03-14 13:24 371544 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-02-23 14:56 . 2011-03-14 13:26 301528 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:56 . 2011-03-14 13:24 192728 —-a-w- c:\windows\system32\drivers\aswNdis2.sys
2011-02-23 14:55 . 2011-03-14 13:24 49240 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2011-03-14 13:24 25432 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:55 . 2011-03-14 13:24 53592 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-02-23 14:54 . 2011-03-14 13:26 19544 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-23 13:34 . 2011-03-14 13:23 12112 —-a-w- c:\windows\system32\drivers\aswNdis.sys
2011-02-02 10:11 . 2009-10-02 18:10 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:37 . 2011-02-09 03:19 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-02-09 03:19 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-02-09 03:19 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-09 03:19 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08 . 2011-02-09 03:19 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-02-09 03:19 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07 . 2011-02-09 03:19 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-02-09 03:19 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-02-09 03:19 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-02-09 03:19 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-02-09 03:19 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-02-09 03:19 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-02-09 03:19 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-02-09 03:19 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-02-09 03:19 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-02-09 03:19 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-02-09 03:19 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-02-09 03:19 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-09 03:19 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-09 03:19 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-09 03:19 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:14 . 2011-02-09 03:19 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:12 . 2011-02-09 03:19 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-02-09 03:19 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-02-09 03:19 683008 —-a-w- c:\windows\system32\d2d1.dll
2007-07-25 06:02 . 2009-05-10 12:22 836608 —-a-w- c:\program files\Pivot 3.0 Beta.exe
2011-03-18 17:57 . 2011-03-24 00:36 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-06-21 15:58 . 2010-06-21 15:58 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-09 4240760]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-20 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-22 133656]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-21 30192]
"Nero MediaHome 4"="c:\program files\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2009-06-23 4891944]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-09 4240760]
.
c:\users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]
Dropbox.lnk - c:\users\Chrissy\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-10-21 50688]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-20 19:47 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 135664]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-21 30192]
R3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2010-11-18 21744]
R3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2005-10-26 30464]
R3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2005-10-26 12672]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2011-02-23 12112]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2011-02-23 121000]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-05-02 161048]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-07-07 14904]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 23:48]
.
2011-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 23:48]
.
2011-04-03 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-11-18 15:13]
.
2011-04-13 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-11-18 15:13]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ninemsn.com.au/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://au.search.yahoo.com/search?fr=mcafee&p;=%s
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath - c:\users\Chrissy\AppData\Roaming\Mozilla\Firefox\Profiles\109c60ll.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://ninemsn.com.au
FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?fr=mcafee&p;=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-14 09:04
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr = "c:\program files\Windows Live\Messenger\msnmsgr.exe" /background??s
.
scanning hidden files …
.
.
C:\## aswSnx private storage
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(3776)
c:\users\Chrissy\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Secunia\PSI\psi.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Nero\Nero MediaHome 4\NMMediaServerService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-04-14 09:09:07 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-14 01:09
ComboFix2.txt 2011-04-12 22:59
ComboFix3.txt 2011-04-12 15:46
.
Pre-Run: 89,576,890,368 bytes free
Post-Run: 89,419,882,496 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 781E19FF9667848A963C79F8A4D7F5BD

When combofix rebooted my computer, it seemed to fix my internet icon problem.
Just one more question, which I think I know the answer but I will ask anyways lol. I have been trialing the AVAST AV and my trial ends today. The thing is, my credit card was cancelled due to it having been comprimised last week and I should be receiving my new card in the mail today or tomorrow, but until then I cant purchase to keep it activated. Should I be downloading the free one just for today even if I wont be using the pc whilst I am at work, or just turn back on my windows defender and then reactivate my AVAST subscription when my card arrives? I dont think the defender protects you against viruses does it?
Thankyou once again for all your help. :notworthy:
chrissy72,

When your AVAST expires.. it won't quit working… it just won't update new definitions. For one day - I wouldn't change anything. If you were talking a month… my answer would be different. However… I'm cheap (and broke) so I run the free version. I have computers with AVAST, Avira, and MSSE. Each have worked for me… and all are free.

Let's clean you up and let you on your way:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Thanks again TomK I have been tossing up as to just going with the free version (as I too am broke lol) or for $40 going with the full version due to it having the extra security for online banking? I do all my banking online (bills etc) due to time restrictions in my busy life, but it does worry me at times as I cant afford for something to go wrong. Im just not sure if its really necessary for the extra security feature, I mean, if its worth paying teh money for, or if the free version is adequate. Your opinion would be much appreciated. Ok, shall do my housekeeping (virtual and real lol) when I get home from work tonight. I dont want to seem like I am repeating myself but THANKYOU THANKYOU THANKYOU! :rofl: Chrissy.
chrissy72, Unfortunately… I'm not a dependable resource for advising you on the "worth" of purchasing the paid version. I suggest that you post a query in the software forum and see if you can get someone to answer whom knows what they're talking about.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI