This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

File associations broken in User account

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Foolishly Deleted VTS.exe in Safe Mode from my RecycleBin on 4/7/11 . Should have used a Forum or anti-spyware procedure for removing it.
I cannot installing Service Pack2 for Windows Vista, Windows Live Essentials,Microsoft SilverLight and Microsoft Security Essentials - KB2267621
http://go.microsoft.com/fwlink/?LinkId=155239
Webroot Spysweeper is not working but has WRTray and WRFrame in Task Manager and blinks up on the screen every 20 seconds.

Here is my HiJackThis file:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:41:33 PM, on 5/6/2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.19048)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Logitech\Logitech Vid\Vid.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\OnlyWire\OnlyWireWindows.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\java.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files\Microsoft\BingBar\BingBar.exe
C:\Program Files\Microsoft\BingBar\BingApp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\Program Files\Webroot\Security\Current\Framework\WRFrame.exe
C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.websucess4you.biz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.websucess4you.biz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: AutoSurfer Pro - {8666B42E-FBEB-40F2-8AAB-D8F8DBD0CAEA} - C:\Program Files\Auto Surfer Pro\autosurferex.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: &RoboForm; - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: AutoSurfer Pro - {8666B42E-FBEB-40f2-8AAB-D8F8DBD0CAEA} - C:\Program Files\Auto Surfer Pro\autosurferex.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] "C:\Windows\system32\WLTRAY.exe"
O4 - HKLM\..\Run: [WinPatrol] "C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe" -expressboot
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SigmatelSysTrayApp] "C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Pareto_Update] "C:\Program Files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe"
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\Vid.exe" -bootmode
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Advanced SystemCare 4] "C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe"
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: OnlyWire.LNK = ?
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: AutoSurfer Pro Button - {85A5E317-3DD7-415a-9403-B9F61453B7E5} - C:\Program Files\Auto Surfer Pro\autosurferex.dll
O9 - Extra 'Tools' menuitem: AutoSurfer Pro - {85A5E317-3DD7-415a-9403-B9F61453B7E5} - C:\Program Files\Auto Surfer Pro\autosurferex.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: RosettaStoneLtdController - Rosetta Stone Ltd. - C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VIWFA - VIA Technologies, Inc. - (no file)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Unknown owner - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (file missing)
O23 - Service: Webroot Client Service (WRConsumerService) - Unknown owner - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 9984 bytes


Here is my OTL.exe file:

OTL logfile created on: 5/6/2011 2:24:01 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\H39e1t7w\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: | Country: | Language: | Date Format:

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 39.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 45.82 Gb Total Space | 4.64 Gb Free Space | 10.12% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.00 Gb Free Space | 60.04% Space Free | Partition Type: NTFS
Drive E: | 109.90 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: H39E1T7W-PC | User Name: H39e1t7w | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/06 14:18:39 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\H39e1t7w\Downloads\OTL.exe
PRC - [2011/04/21 16:54:40 | 000,402,832 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
PRC - [2011/04/21 16:54:38 | 003,366,800 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe
PRC - [2011/04/21 16:54:38 | 000,801,680 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
PRC - [2011/04/21 16:54:38 | 000,352,656 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2011/04/12 09:18:33 | 000,107,000 | —- | M] (Siber Systems) – C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2011/04/11 10:04:10 | 003,466,584 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360.exe
PRC - [2011/02/28 19:44:14 | 000,391,432 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\BingBar.exe
PRC - [2011/02/28 19:44:14 | 000,259,336 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\BingApp.exe
PRC - [2011/02/25 11:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/02/04 10:22:43 | 000,624,552 | —- | M] () – C:\Program Files\OnlyWire\OnlyWireWindows.exe
PRC - [2011/01/13 12:41:30 | 000,912,344 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/08/05 13:10:04 | 001,118,552 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\a_hijackscan.exe
PRC - [2010/06/11 18:14:24 | 001,280,344 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360tray.exe
PRC - [2010/06/11 18:14:22 | 000,312,152 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360srv.exe
PRC - [2009/10/14 13:36:56 | 002,793,304 | —- | M] () – C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/10/14 13:34:18 | 000,560,472 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/09/29 09:17:50 | 000,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2009/07/16 15:35:42 | 005,458,704 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Logitech Vid\Vid.exe
PRC - [2009/05/21 12:13:58 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/03/23 14:07:24 | 001,830,128 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2009/03/10 23:12:02 | 000,321,616 | —- | M] (Microsoft Corporation) – C:\Windows\SoftwareDistribution\Download\Install\CheckSURPackage.EXE
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/02/11 22:41:06 | 000,783,328 | —- | M] (Microsoft Corporation) – d:\091ae3f794a073b42c7b\checksur.exe
PRC - [2009/02/11 22:41:06 | 000,049,136 | —- | M] () – d:\091ae3f794a073b42c7b\checksurlauncher.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/12/16 00:15:41 | 000,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\javaw.exe
PRC - [2008/12/16 00:15:40 | 000,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
PRC - [2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/10/09 11:52:54 | 000,333,120 | —- | M] (BillP Studios) – C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2008/09/16 12:02:42 | 000,352,312 | —- | M] (Rosetta Stone Ltd.) – C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe
PRC - [2008/09/16 12:02:42 | 000,013,368 | —- | M] (Rosetta Stone Ltd.) – C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdServer.exe
PRC - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/24 13:26:18 | 000,202,560 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
PRC - [2008/02/15 18:25:34 | 000,102,400 | —- | M] (IDT, Inc.) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe
PRC - [2008/02/15 18:23:20 | 000,405,504 | —- | M] (IDT, Inc.) – C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
PRC - [2008/01/19 03:38:38 | 001,008,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/19 03:33:11 | 000,498,176 | —- | M] (Microsoft Corporation) – C:\Windows\HelpPane.exe
PRC - [2008/01/19 03:33:04 | 000,318,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cmd.exe
PRC - [2007/12/26 20:13:51 | 000,396,288 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
PRC - [2006/11/16 19:18:48 | 001,066,528 | —- | M] (Dell Inc) – C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2006/11/12 03:19:46 | 000,446,976 | —- | M] (Gteko Ltd.) – C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2006/04/28 10:14:44 | 000,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2005/06/02 15:54:34 | 000,086,606 | —- | M] (Canon Inc.) – C:\Program Files\Canon\CAL\CALMAIN.exe


========== Modules (SafeList) ==========

MOD - [2011/05/06 14:18:39 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\H39e1t7w\Downloads\OTL.exe
MOD - [2010/08/31 11:39:57 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (WRConsumerService)
SRV - File not found [Auto | Stopped] – – (WebrootSpySweeperService)
SRV - File not found [On_Demand | Stopped] – – (VIWFA)
SRV - File not found [On_Demand | Stopped] – – (LGPPPDX)
SRV - File not found [Auto | Stopped] – – (CLTNetCnService)
SRV - [2011/04/21 16:54:38 | 000,352,656 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/02/28 19:44:14 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 11:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2010/09/01 15:51:28 | 000,066,112 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll – (nosGetPlusHelper) getPlus®
SRV - [2010/06/11 18:14:22 | 000,312,152 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\IObit Security 360\is360srv.exe – (IS360service)
SRV - [2009/10/07 01:47:34 | 000,154,136 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2009/09/29 09:17:50 | 000,013,088 | —- | M] (Intuit Inc.) [Auto | Running] – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/09/16 12:02:42 | 000,352,312 | —- | M] (Rosetta Stone Ltd.) [Auto | Running] – C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe – (RosettaStoneLtdController)
SRV - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/04/24 13:26:18 | 000,202,560 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe – (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2)
SRV - [2008/02/15 18:25:34 | 000,102,400 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe – (STacSV)
SRV - [2008/01/19 03:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2006/11/07 14:27:02 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2005/06/02 15:54:34 | 000,086,606 | —- | M] (Canon Inc.) [Auto | Running] – C:\Program Files\Canon\CAL\CALMAIN.exe – (CCALib8)


========== Driver Services (SafeList) ==========

DRV - [2011/03/16 19:00:08 | 000,032,672 | —- | M] (IObit Information Technology) [File_System | Auto | Running] – C:\Program Files\IObit\Protected Folder\pffilter.sys – (PfFilter)
DRV - [2011/02/15 14:36:38 | 000,182,056 | —- | M] (Webroot Software, Inc. (www.webroot.com)) [Kernel | Boot | Running] – C:\Windows\SYSTEM32\Drivers\SSIDRV.SYS – (SSIDRV)
DRV - [2011/02/15 14:36:38 | 000,024,496 | —- | M] (Webroot Software, Inc. (www.webroot.com)) [Kernel | Boot | Running] – C:\Windows\SYSTEM32\Drivers\SSHRMD.SYS – (SSHRMD)
DRV - [2010/11/09 11:45:09 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2009/10/07 01:46:36 | 000,025,752 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2009/09/16 10:22:48 | 000,214,664 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\mfehidk.sys – (mfehidk)
DRV - [2009/09/16 10:22:48 | 000,079,816 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2009/09/16 10:22:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 10:22:48 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - [2009/09/16 10:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mferkdk.sys – (mferkdk)
DRV - [2009/04/30 22:55:58 | 002,687,512 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\LV302V32.SYS – (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2009/04/30 19:01:34 | 000,265,496 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lvrs.sys – (LVRS)
DRV - [2009/04/30 18:55:32 | 000,013,976 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lv302af.sys – (pepifilter)
DRV - [2009/03/23 14:07:28 | 000,007,408 | R— | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Running] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2009/03/23 14:07:26 | 000,072,944 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2009/03/23 14:07:26 | 000,009,968 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2008/11/05 23:20:24 | 000,048,128 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2008/02/15 18:27:02 | 000,330,752 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2008/01/04 20:34:36 | 000,023,920 | —- | M] (Webroot Software Inc (www.webroot.com)) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sskbfd.sys – (SSKBFD)
DRV - [2007/10/11 21:40:14 | 000,010,632 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\amdide.sys – (amdide)
DRV - [2007/04/27 16:25:28 | 000,038,432 | —- | M] (Paragon Software Group) [Kernel | Boot | Running] – C:\Windows\system32\drivers\hotcore3.sys – (hotcore3)
DRV - [2007/04/12 17:46:36 | 000,034,136 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2007/02/08 20:05:30 | 000,028,120 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2007/02/08 20:05:30 | 000,012,856 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2007/01/30 13:23:30 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2006/11/25 01:46:38 | 002,085,888 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/11/25 01:46:38 | 002,085,888 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (atikmdag)
DRV - [2006/11/21 04:25:44 | 000,045,568 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\bcm4sbxp.sys – (bcm4sbxp)
DRV - [2006/11/20 15:13:58 | 000,043,520 | —- | M] (REDC) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2006/11/20 15:13:58 | 000,037,376 | —- | M] (REDC) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2006/11/02 03:30:55 | 000,200,704 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®
DRV - [2006/10/30 11:22:26 | 000,008,192 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\AtiPcie.sys – (AtiPcie) ATI PCI Express (3GIO)
DRV - [2006/10/26 16:22:02 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/10/26 16:21:34 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/10/26 16:21:34 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/10/26 16:21:32 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/10/26 16:21:30 | 000,026,296 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/10/26 16:21:28 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/10/26 16:21:26 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/10/26 16:21:24 | 000,104,536 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/08/17 16:43:52 | 000,007,424 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\Program Files\DellSupport\Drivers\dsunidrv.sys – (dsunidrv)
DRV - [2003/09/19 15:47:24 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\pfc.sys – (pfc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.websucess4you.biz

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.websucess4you.biz
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://securityresponse.symantec.com/avcenter/fix_homepage/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2011/04/12 09:21:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/13 12:41:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/13 12:41:37 | 000,000,000 | —D | M]

[2008/09/13 15:46:02 | 000,000,000 | —D | M] (No name found) – C:\Users\H39e1t7w\AppData\Roaming\mozilla\Extensions
[2011/05/05 23:52:07 | 000,000,000 | —D | M] (No name found) – C:\Users\H39e1t7w\AppData\Roaming\mozilla\Firefox\Profiles\f071cevy.default\extensions
[2011/04/28 10:30:14 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\H39e1t7w\AppData\Roaming\mozilla\Firefox\Profiles\f071cevy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/06 14:22:14 | 000,000,000 | —D | M] (FoxLingo) – C:\Users\H39e1t7w\AppData\Roaming\mozilla\Firefox\Profiles\f071cevy.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2010/11/19 02:14:46 | 000,000,000 | —D | M] (Search Toolbar) – C:\Users\H39e1t7w\AppData\Roaming\mozilla\Firefox\Profiles\f071cevy.default\extensions\[removed]
[2011/04/08 13:10:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2011/04/08 18:29:07 | 000,293,853 | —- | M]) - C:\Windows\System32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 babe.the-killer.bz
O1 - Hosts: 127.0.0.1 www.babe.the-killer.bz
O1 - Hosts: 127.0.0.1 babe.k-lined.com
O1 - Hosts: 127.0.0.1 www.babe.k-lined.com
O1 - Hosts: 127.0.0.1 did.i-used.cc
O1 - Hosts: 127.0.0.1 www.did.i-used.cc
O1 - Hosts: 127.0.0.1 coolwwwsearch.com
O1 - Hosts: 127.0.0.1 www.coolwwwsearch.com
O1 - Hosts: 127.0.0.1 coolwebsearch.com
O1 - Hosts: 127.0.0.1 www.coolwebsearch.com
O1 - Hosts: 127.0.0.1 hi.studioaperto.net
O1 - Hosts: 127.0.0.1 www.hi.studioaperto.net
O1 - Hosts: 127.0.0.1 wazzupnet.com
O1 - Hosts: 127.0.0.1 www.wazzupnet.com
O1 - Hosts: 127.0.0.1 gueb.com
O1 - Hosts: 127.0.0.1 www.gueb.com
O1 - Hosts: 127.0.0.1 kabex.com
O1 - Hosts: 127.0.0.1 www.kabex.com
O1 - Hosts: 127.0.0.1 hityou.com
O1 - Hosts: 127.0.0.1 www.hityou.com
O1 - Hosts: 127.0.0.1 miosearch.com
O1 - Hosts: 127.0.0.1 www.miosearch.com
O1 - Hosts: 127.0.0.1 213.131.225.2
O1 - Hosts: 127.0.0.1 blue-elefant.com
O1 - Hosts: 10172 more lines…
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (AutoSurfer Pro) - {8666B42E-FBEB-40F2-8AAB-D8F8DBD0CAEA} - C:\Program Files\Auto Surfer Pro\autosurferex.dll (TODO: )
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (AutoSurfer Pro) - {8666B42E-FBEB-40f2-8AAB-D8F8DBD0CAEA} - C:\Program Files\Auto Surfer Pro\autosurferex.dll (TODO: )
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files\Logitech\Logitech Vid\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [Pareto_Update] C:\Program Files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe ()
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: AutoSurfer Pro Button - {85A5E317-3DD7-415a-9403-B9F61453B7E5} - C:\Program Files\Auto Surfer Pro\autosurferex.dll (TODO: )
O9 - Extra 'Tools' menuitem : AutoSurfer Pro - {85A5E317-3DD7-415a-9403-B9F61453B7E5} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper: C:\Users\M26-3r8u5-3a7\Pictures\Thumbnail-Ukraine-2006\DSCN1210-30.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O30 - LSA: Authentication Packages - (ows\s) - File not found
O30 - LSA: Security Packages - (3886-1732322343-1000) - File not found
O30 - LSA: Security Packages - (&) - File not found
O30 - LSA: Security Packages - (洨) - File not found
O30 - LSA: Security Packages - (@) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/31 01:51:09 | 000,000,124 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{77956b11-19bf-11dc-a943-0019b96b3089}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/06 13:05:07 | 000,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2011/05/06 11:52:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/05/06 11:52:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Folder
[2011/05/06 11:51:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Security 360
[2011/05/06 11:51:09 | 000,000,000 | —D | C] – C:\Users\H39e1t7w\AppData\Roaming\IObit
[2011/05/06 11:51:06 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/05/06 11:51:02 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/05/05 23:59:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/04/27 23:04:24 | 000,000,000 | —D | C] – C:\Users\H39e1t7w\z) excess number of ntuser_dat files
[2011/04/26 19:01:02 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/04/16 23:34:44 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/04/16 23:34:42 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/04/16 23:33:58 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/04/16 23:33:57 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/04/16 23:33:57 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/04/16 23:33:55 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/04/16 23:33:54 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/04/16 23:33:54 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/04/16 23:33:54 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/04/16 23:33:53 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/04/16 23:33:53 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/04/16 23:33:52 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/04/16 23:33:52 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/04/16 23:33:52 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/04/16 23:33:52 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/04/16 23:33:52 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/04/16 23:33:52 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/04/16 23:33:51 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/04/16 23:33:18 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/04/16 23:32:19 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2011/04/16 23:32:13 | 001,161,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2011/04/16 23:31:48 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2011/04/16 23:31:26 | 002,040,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/04/16 23:30:57 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/04/16 23:30:56 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/04/13 22:37:25 | 000,000,000 | —D | C] – C:\Users\H39e1t7w\AppData\Local\Microsoft Games
[2011/04/13 21:14:08 | 000,000,000 | —D | C] – C:\Users\H39e1t7w\Desktop\SOS
[2011/04/12 09:32:24 | 000,000,000 | —D | C] – C:\Users\H39e1t7w\AppData\Roaming\RoboForm
[2011/04/12 09:21:13 | 000,000,000 | —D | C] – C:\ProgramData\RoboForm
[2011/04/12 09:21:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
[2011/04/10 10:37:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/04/10 10:36:50 | 000,000,000 | -HSD | C] – C:\Windows\System32\%APPDATA%
[2011/04/08 18:28:36 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/04/08 17:50:35 | 000,017,472 | —- | C] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\System32\SsiEfr.exe
[2011/04/08 17:49:47 | 000,045,072 | —- | C] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\System32\drivers\ssfmonm.sys
[2011/04/08 17:47:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot
[2011/04/08 17:47:08 | 000,000,000 | -H-D | C] – C:\ProgramData\{3140EA8C-7399-4EC4-819C-16996F38FCFC}
[2011/04/08 17:40:42 | 000,000,000 | —D | C] – C:\ProgramData\webroot
[2011/04/08 13:13:44 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2011/04/08 13:12:46 | 000,311,312 | —- | C] (Kaspersky Lab) – C:\Windows\System32\drivers\4655128.sys
[2011/04/08 13:12:46 | 000,128,016 | —- | C] (Kaspersky Lab) – C:\Windows\System32\drivers\46551281.sys
[2011/04/08 13:12:46 | 000,037,392 | —- | C] (Kaspersky Lab) – C:\Windows\System32\drivers\46551282.sys
[2011/04/08 13:12:46 | 000,000,000 | —D | C] – C:\Users\H39e1t7w\Desktop\Virus Removal Tool
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/06 13:09:24 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/06 13:09:24 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/06 11:52:36 | 000,001,038 | —- | M] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/05/06 11:52:35 | 000,001,040 | —- | M] () – C:\Users\H39e1t7w\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/05/06 11:52:35 | 000,001,016 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/05/06 11:52:22 | 000,001,023 | —- | M] () – C:\Users\H39e1t7w\Application Data\Microsoft\Internet Explorer\Quick Launch\Protected Folder.lnk
[2011/05/06 11:52:22 | 000,000,999 | —- | M] () – C:\Users\Public\Desktop\Protected Folder.lnk
[2011/05/06 11:51:13 | 000,000,959 | —- | M] () – C:\Users\Public\Desktop\IObit Security 360.lnk
[2011/05/06 11:09:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/06 01:14:26 | 000,626,030 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/06 01:14:26 | 000,112,462 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/05 23:59:58 | 000,001,081 | —- | M] () – C:\Users\H39e1t7w\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/05/05 23:59:58 | 000,001,057 | —- | M] () – C:\Users\H39e1t7w\Desktop\Spybot - Search & Destroy.lnk
[2011/04/28 10:27:00 | 000,001,551 | —- | M] () – C:\Users\H39e1t7w\Desktop\H39e1t7w Account.lnk
[2011/04/28 10:26:17 | 000,001,533 | —- | M] () – C:\Users\H39e1t7w\Desktop\User Accounts.lnk
[2011/04/28 10:21:50 | 000,001,523 | —- | M] () – C:\Users\H39e1t7w\Desktop\© OS.lnk
[2011/04/27 09:36:00 | 000,000,408 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{C17E5B9E-75C1-4531-B7CD-2E9ACDDF5D9D}.job
[2011/04/27 01:47:52 | 000,000,398 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{79F6CD71-52BC-43B9-B909-F68F720BB247}.job
[2011/04/17 13:19:51 | 000,336,584 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/16 21:38:57 | 000,000,450 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration3.job
[2011/04/16 21:38:57 | 000,000,448 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration.job
[2011/04/12 11:38:13 | 000,002,485 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/04/10 08:34:27 | 000,000,950 | —- | M] () – C:\Users\Public\Desktop\ParetoLogic DriverCure.lnk
[2011/04/10 07:53:19 | 000,000,386 | —- | M] () – C:\Windows\tasks\DriverCure.job
[2011/04/09 02:06:49 | 000,000,422 | —- | M] () – C:\Windows\tasks\ParetoLogic Update Version2.job
[2011/04/08 18:24:21 | 000,001,356 | —- | M] () – C:\Users\H39e1t7w\AppData\Local\d3d9caps.dat
[2011/04/08 17:47:09 | 000,001,314 | —- | M] () – C:\Users\Public\Desktop\Webroot AntiVirus with Spy Sweeper.lnk
[2011/04/08 13:13:44 | 000,002,176 | —- | M] () – C:\Users\H39e1t7w\Desktop\Start.lnk
[2011/04/07 22:21:41 | 000,009,326 | -HS- | M] () – C:\ProgramData\o0117nc2nv5tpb633d15bq765wo1
[2011/04/07 20:38:30 | 000,000,409 | —- | M] () – C:\Windows\wininit.ini
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/06 11:52:36 | 000,001,038 | —- | C] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/05/06 11:52:35 | 000,001,040 | —- | C] () – C:\Users\H39e1t7w\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/05/06 11:52:35 | 000,001,016 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/05/06 11:52:22 | 000,001,023 | —- | C] () – C:\Users\H39e1t7w\Application Data\Microsoft\Internet Explorer\Quick Launch\Protected Folder.lnk
[2011/05/06 11:52:22 | 000,000,999 | —- | C] () – C:\Users\Public\Desktop\Protected Folder.lnk
[2011/05/06 11:51:13 | 000,000,959 | —- | C] () – C:\Users\Public\Desktop\IObit Security 360.lnk
[2011/05/05 23:59:58 | 000,001,081 | —- | C] () – C:\Users\H39e1t7w\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/05/05 23:59:58 | 000,001,057 | —- | C] () – C:\Users\H39e1t7w\Desktop\Spybot - Search & Destroy.lnk
[2011/04/28 10:26:27 | 000,001,551 | —- | C] () – C:\Users\H39e1t7w\Desktop\H39e1t7w Account.lnk
[2011/04/28 10:22:15 | 000,001,533 | —- | C] () – C:\Users\H39e1t7w\Desktop\User Accounts.lnk
[2011/04/28 10:20:59 | 000,001,523 | —- | C] () – C:\Users\H39e1t7w\Desktop\© OS.lnk
[2011/04/10 08:35:27 | 000,000,450 | —- | C] () – C:\Windows\tasks\ParetoLogic Registration3.job
[2011/04/08 17:50:35 | 000,030,424 | —- | C] () – C:\Windows\System32\wrLZMA.dll
[2011/04/08 17:47:09 | 000,001,314 | —- | C] () – C:\Users\Public\Desktop\Webroot AntiVirus with Spy Sweeper.lnk
[2011/04/08 13:13:44 | 000,002,176 | —- | C] () – C:\Users\H39e1t7w\Desktop\Start.lnk
[2011/04/07 17:51:15 | 000,009,326 | -HS- | C] () – C:\ProgramData\o0117nc2nv5tpb633d15bq765wo1
[2011/03/03 23:13:46 | 000,000,600 | —- | C] () – C:\Users\H39e1t7w\AppData\Local\PUTTY.RND
[2011/01/10 01:28:01 | 000,001,356 | —- | C] () – C:\Users\H39e1t7w\AppData\Local\d3d9caps.dat
[2010/05/14 11:28:27 | 000,695,578 | —- | C] () – C:\Windows\System32\unins000.exe
[2010/05/14 11:28:27 | 000,001,075 | —- | C] () – C:\Windows\System32\unins000.dat
[2010/04/05 20:02:33 | 000,000,096 | —- | C] () – C:\Users\H39e1t7w\AppData\Local\fusioncache.dat
[2010/01/23 17:56:46 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/01/23 16:10:23 | 000,006,656 | —- | C] () – C:\Windows\System32\bcmwlrc.dll
[2010/01/23 16:09:07 | 000,054,784 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2010/01/23 16:08:37 | 000,026,112 | —- | C] () – C:\Windows\System32\WLTRYSVC.EXE
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2009/09/20 00:46:03 | 000,000,760 | —- | C] () – C:\Users\H39e1t7w\AppData\Roaming\setup_ldm.iss
[2009/04/30 22:39:36 | 000,082,289 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2009/03/26 17:23:33 | 000,247,808 | —- | C] () – C:\Windows\System32\prgiso.dll
[2009/03/26 17:23:25 | 004,244,992 | —- | C] () – C:\Windows\System32\qtp-mt334.dll
[2009/03/26 17:23:24 | 000,013,824 | —- | C] () – C:\Windows\System32\wnaspi32.dll
[2008/11/26 04:05:48 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2008/11/26 04:05:48 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/03/27 09:04:32 | 000,691,545 | —- | C] () – C:\Windows\unins000.exe
[2008/03/27 09:04:32 | 000,002,546 | —- | C] () – C:\Windows\unins000.dat
[2007/11/05 16:22:58 | 000,153,088 | —- | C] () – C:\Windows\UNWISE.EXE
[2007/08/05 22:43:44 | 000,000,021 | —- | C] () – C:\Windows\CS_SETUP.ini
[2007/08/05 22:12:45 | 000,000,000 | —- | C] () – C:\Windows\OpPrintServer.INI
[2007/07/04 08:52:04 | 000,000,672 | —- | C] () – C:\Windows\EReg077.dat
[2007/06/07 09:50:26 | 000,056,056 | —- | C] () – C:\Windows\System32\DLAAPI_W.DLL
[2007/06/07 09:50:25 | 000,000,409 | —- | C] () – C:\Windows\wininit.ini
[2007/06/01 12:56:47 | 000,000,141 | —- | C] () – C:\Windows\asym.ini
[2007/05/29 10:55:57 | 000,030,720 | —- | C] () – C:\Users\H39e1t7w\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/18 02:50:31 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2007/05/18 02:50:31 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/05/18 02:50:31 | 000,138,101 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2007/05/18 02:50:30 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/05/18 02:50:20 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2006/11/07 15:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,336,584 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,626,030 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,112,462 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/17 00:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll

< End of report >
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Download unhide.exe & save it to your windows folder:

Right click on unhide.exe and select Run as administrator (In case you have Vista or Win7)
Reboot

This will unhide folders/files that were set to be hidden by the infection you had.

Delete this folder

C:\ProgramData\o0117nc2nv5tpb633d15bq765wo1

Reboot and let me know how it's running.
It would not let me download/save to C:\Windows , so I saved to my Admin account and then copied it into C:\Windows. However, it has not unhidden anything after 5 minutes, so I right-clicked and ran it again as Administrator but still nothing. I cannot write in delete C:\ProgramData\o0117nc2nv5tpb633d15bq765wo1 Thanks for your patience.
Logs will be closed if you haven't replied within 3 days



Please don't attach the scans / logs for these tools, use "copy/paste".


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista / Windows7 Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.



I've been seeing some Java infections lately.

Go here and follow the instructions to clear your Java Cache
http://www.java.com/en/download/help/plugin_cache.xml


Next:
Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.


  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
I performed a Full Scan an it found 3 items and I removed them and here are the results: I will reboot after I post this. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6569 Windows 6.0.6001 Service Pack 1 Internet Explorer 8.0.6001.19048 5/13/2011 5:02:24 PM mbam-log-2011-05-13 (17-02-24).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 437221 Time elapsed: 2 hour(s), 23 minute(s), 2 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Users\m26-3r8u5-3a7\documents\1-my businesses\craigs list-org\craigslist\how-to-fix-windows\ebookfix.exe (Spyware.Passwords) -> Quarantined and deleted successfully. c:\Users\m26-3r8u5-3a7\documents\1-my businesses\a-secret affiliate weapon\UWV\u-w-videos\ultimate website videos\freetoolbars.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\m26-3r8u5-3a7\documents\1-my businesses\a-secret affiliate weapon\UWV\ultimate website videos\freetoolbars.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt in your next reply
Let me first give a description of the behavior of my laptop before I ran the script:

1. When I am typing this, Webroot Spysweeper flashes up and interrupts my typing
so that I miss keystrokes. Kaspersky Anti-Virus Tool is still on the machine and
I know that suppresses Webroot Spysweeper but Kaspersky is not listed in the Control Panel
and has no self-installed tool to uninstall it with.

2. All the same problems remain on the machine as when I began this post:
a. All file associations between all programs are broken in the M26 account,
although they are not broken in a new account that was established after the virus
was found and removed before I submitted this problem.
b. Webroot Spysweeper has 2 files in the Task Manager but will not run.
Problem signature
Problem Event Name: APPCRASH
Application Name: WRFrame.exe
Application Version: 7.0.8.7
Application Timestamp: 4d77b121
Fault Module Name: ntdll.dll
Fault Module Version: 6.0.6001.18538
Fault Module Timestamp: 4cb733dc
Exception Code: c0000005
Exception Offset: 0004308e
OS Version: 6.0.6001.2.1.0.768.3
Locale ID: 1033
Additional Information 1: 84f8
Additional Information 2: f38b7905824fbe3b729d03296edc2d6a
Additional Information 3: ead8
Additional Information 4: f548af2ab58a7b801f111ad2cc36b745

c. No Windows Updates can be made and not for service Pack2 especially.
This articles describes the problem I am having: http://support.microsoft.com/kb/971204


I did not know what had scripting blocks and what did not so I ran this without shutting
down anything. Here is the DDS.txt file:

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 20:13:41.47 on Fri 05/13/2011
Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_11
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1917.254 [GMT -4:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: IObit Security 360 *Enabled/Updated* {FAE2835A-B90A-9E7A-85DA-82DBDA7C1E3A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdServer.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\IObit\IObit Security 360\is360tray.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Logitech\Logitech Vid\Vid.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\OnlyWire\OnlyWireWindows.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\system32\java.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\WerCon.exe
C:\Users\H39e1t7w\Desktop\Virus Removal Tool\setup_9.0.0.722_08.04.2011_20-42\setup_9.0.0.722_08.04.2011_20-42.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\wscript.exe
C:\Program Files\Webroot\Security\Current\Framework\WRFrame.exe
C:\Users\H39e1t7w\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.websucess4you.biz
mStart Page = hxxp://www.websucess4you.biz
mSearch Page = hxxp://www.google.com
mWindow Title = Windows Internet Explorer provided by Comcast
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: AutoSurfer Pro: {8666b42e-fbeb-40f2-8aab-d8f8dbd0caea} - c:\program files\auto surfer pro\autosurferex.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: AutoSurfer Pro: {8666b42e-fbeb-40f2-8aab-d8f8dbd0caea} - c:\program files\auto surfer pro\autosurferex.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [Pareto_Update] "c:\program files\common files\paretologic\uus2\Pareto_Update.exe"
uRun: [Logitech Vid] "c:\program files\logitech\logitech vid\Vid.exe" -bootmode
uRun: [SUPERAntiSpyware] "c:\program files\superantispyware\SUPERAntiSpyware.exe"
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Advanced SystemCare 4] "c:\program files\iobit\advanced systemcare 4\ASCTray.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [Broadcom Wireless Manager UI] "c:\windows\system32\WLTRAY.exe"
mRun: [WinPatrol] "c:\program files\billp studios\winpatrol\WinPatrol.exe" -expressboot
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [SigmatelSysTrayApp] "c:\program files\sigmatel\c-major audio\wdm\sttray.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [IObit Security 360] "c:\program files\iobit\iobit security 360\IS360tray.exe" /autostart
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\onlywire.lnk - c:\program files\onlywire\OnlyWireWindows.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{53a01cc6-14b0-4512-a2e7-10d39bf83dc4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {85A5E317-3DD7-415a-9403-B9F61453B7E5} - {8666B42E-FBEB-40f2-8AAB-D8F8DBD0CAEA} - c:\program files\auto surfer pro\autosurferex.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: turbotax.com
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\h39e1t7w\appdata\roaming\mozilla\firefox\profiles\f071cevy.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BSRTDF&PC=BBSR&q=
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/?pc=Z006&form=ZGAPHP
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z006&form=ZGAADF&q=
FF - component: c:\program files\siber systems\ai roboform\firefox\components\rfproxy_31.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npRLCT4Player.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Search Toolbar: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: FoxLingo: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66} - %profile%\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - c:\program files\siber systems\ai roboform\Firefox
.
============= SERVICES / DRIVERS ===============
.
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2009-3-26 38432]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-10-21 214664]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-3-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-3-23 72944]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-5-6 352656]
R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2011-5-6 312152]
R2 PfFilter;PfFilter;c:\program files\iobit\protected folder\pffilter.sys [2011-5-6 32672]
R2 RosettaStoneLtdController;RosettaStoneLtdController;c:\program files\rosettastoneltdservices\RosettaStoneLtdController.exe [2008-9-16 352312]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-5-5 1153368]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-3-23 7408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;"c:\program files\webroot\spy sweeper\spysweeper.exe" –> c:\program files\webroot\spy sweeper\SpySweeper.exe [?]
S2 WRConsumerService;Webroot Client Service;"c:\program files\webroot\spy sweeper\wrconsumerservice.exe" –> c:\program files\webroot\spy sweeper\WRConsumerService.exe [?]
S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-2-28 183560]
S3 LGPPPDX;LGPPPDX; [x]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-11-24 79816]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-11-24 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-1-22 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-1-22 40552]
S3 MSHUSBVideo;NX6000/NX3000/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [2007-4-12 34136]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2008-9-20 21504]
S3 VIWFA;VIWFA; [x]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-05-13 23:17:03 7071056 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{4ff7053d-3457-43fa-bc8d-5d8c999cff99}\mpengine.dll
2011-05-13 18:30:39 ——– d—–w- c:\users\h39e1t7w\appdata\roaming\Malwarebytes
2011-05-13 18:30:33 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-13 18:30:32 ——– d—–w- c:\progra~2\Malwarebytes
2011-05-13 18:30:28 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-13 18:30:28 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-05-11 04:12:38 502095 —-a-w- c:\windows\unhide.exe
2011-05-11 04:07:40 502095 —-a-w- c:\users\h39e1t7w\unhide.exe
2011-05-07 02:08:47 ——– d—–w- c:\program files\Windows Live SkyDrive
2011-05-07 02:06:37 ——– d—–w- c:\windows\PCHEALTH
2011-05-07 02:06:26 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2011-05-07 02:05:48 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2011-05-07 02:03:47 74520 —-a-w- c:\program files\common files\windows live\.cache\2b33e41cc0c5b\DSETUP.dll
2011-05-07 02:03:47 484632 —-a-w- c:\program files\common files\windows live\.cache\2b33e41cc0c5b\DXSETUP.exe
2011-05-07 02:03:47 1670936 —-a-w- c:\program files\common files\windows live\.cache\2b33e41cc0c5b\dsetup32.dll
2011-05-07 02:00:29 ——– d—–w- c:\program files\common files\Windows Live
2011-05-07 01:55:27 ——– d—–w- C:\b71af59d1dcbd1d1d77159901f80c16f
2011-05-06 18:35:27 388096 —-a-r- c:\users\h39e1t7w\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-05-06 17:05:07 ——– d—–w- c:\windows\system32\EventProviders
2011-05-06 15:51:09 ——– d—–w- c:\users\h39e1t7w\appdata\roaming\IObit
2011-05-06 15:51:06 ——– d—–w- c:\progra~2\IObit
2011-05-06 15:51:02 ——– d—–w- c:\program files\IObit
2011-04-28 03:04:24 ——– d—–w- c:\users\h39e1t7w\z) excess number of ntuser_dat files
2011-04-17 03:34:44 292864 —-a-w- c:\windows\system32\atmfd.dll
2011-04-17 03:34:42 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-04-17 03:34:30 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-04-17 03:34:01 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-17 03:34:00 638232 —-a-w- c:\program files\internet explorer\iexplore.exe
2011-04-17 03:32:53 213504 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-17 03:32:51 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-17 03:32:50 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-04-17 03:32:50 105984 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-17 03:32:19 1136640 —-a-w- c:\windows\system32\mfc42.dll
2011-04-17 03:32:13 1161728 —-a-w- c:\windows\system32\mfc42u.dll
2011-04-17 03:32:01 304640 —-a-w- c:\windows\system32\drivers\srv.sys
2011-04-17 03:32:00 146432 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-04-17 03:31:59 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-17 03:31:49 86528 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-04-17 03:31:48 25088 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-04-17 03:31:26 2040832 —-a-w- c:\windows\system32\win32k.sys
2011-04-17 03:31:08 738816 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-17 03:30:56 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-04-14 02:37:25 ——– d—–w- c:\users\h39e1t7w\appdata\local\Microsoft Games
.
==================== Find3M ====================
.
2011-02-22 06:17:08 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 06:16:53 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 06:16:40 71680 —-a-w- c:\windows\system32\iesetup.dll
2011-02-22 06:16:40 109056 —-a-w- c:\windows\system32\iesysprep.dll
2011-02-22 05:20:39 385024 —-a-w- c:\windows\system32\html.iec
2011-02-22 04:43:54 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2011-02-22 04:42:38 1638912 —-a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 20:17:42.05 ===============
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have XP SP3, use the XP SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI