This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP Start up painfully slow [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi
Recently, start and re-boot time is painfully slow in my XP computer.
I keep it generally clean and free of unnecessary software and clean the registry regularly so can't understand where the problem lies.
Help appreciated.
Thanks in advance.
Hijack This log below:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:47:34, on 08/01/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\tbZone.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
O4 - HKLM\..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe /icon="hidden"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe

–
End of file - 7642 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———-


Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
Hi Jeff Here we go . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 17:00:19 on 2012-01-12 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3318.2350 [GMT 0:00] . AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: ZoneAlarm Security Suite Antivirus *Disabled/Outdated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF} FW: ZoneAlarm Free Firewall *Enabled* . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG2012\avgrsx.exe C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Google\Update\GoogleUpdate.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\AVG\AVG2012\avgnsx.exe C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\Program Files\Trusteer\Rapport\bin\RapportService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\CheckPoint\ZAForceField\ForceField.exe C:\Program Files\Mozilla Thunderbird\thunderbird.exe C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uStart Page = hxxp://news.bbc.co.uk/ uSearch Bar = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = localhost;*.local mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: H - No File uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uURLSearchHooks: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - c:\program files\zonealarm_security\tbZone.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} EB: Groove Folder Synchronization: {2a541ae1-5bf6-4665-a8a3-cfa9672e4291} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\neil\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [ZoneAlarm] "c:\program files\checkpoint\zonealarm\zatray.exe" mRun: [ISW] c:\program files\checkpoint\zaforcefield\ForceField.exe /icon="hidden" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t uPolicies-explorer: DisallowRun = 1 (0x1) uPolicies-disallowrun: 1 = avnotify.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{719223B8-401E-4ED0-84B3-8A466A643177} : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{97623468-20AE-4AFF-8288-82381C70FD59} : DhcpNameServer = 192.168.0.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll Hosts: 127.0.0.1 www.spywareinfo.com . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592] R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [2008-1-7 15172] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-7-11 230608] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248] R1 RapportCerberus_34302;RapportCerberus_34302;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\34302\RapportCerberus32_34302.sys [2011-12-15 228208] R1 RapportEI;RapportEI;c:\program files\trusteer\rapport\bin\RapportEI.sys [2011-12-14 71440] R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2011-12-14 164112] R1 Vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2011-11-9 525840] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776] R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2011-11-3 27016] R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2011-11-3 497280] R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2011-6-18 12184] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2011-12-14 931640] R2 vsmon;TrueVector Internet Monitor;c:\program files\checkpoint\zonealarm\vsmon.exe -service –> c:\program files\checkpoint\zonealarm\vsmon.exe -service [?] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-7-11 16720] R3 RapportIaso;RapportIaso;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\28896\RapportIaso.sys [2011-8-7 21520] S1 RapportBuka;RapportBuka;\??\c:\windows\system32\drivers\rapportbuka.sys –> c:\windows\system32\drivers\RapportBuka.sys [?] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-10-27 133104] S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [2011-2-26 1714176] S3 avera800;AVerMedia DVB-T BDA Video Capture(A800);c:\windows\system32\drivers\avera800.sys [2006-11-22 41600] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-10-27 133104] S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2010-4-10 266544] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-10 14336] S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2006-11-21 272128] S3 SDTHelper;Helper driver for SDT-Tool;\??\c:\documents and settings\neil\my documents\downloads\radix_installer_trial\sdthlpr.sys –> c:\documents and settings\neil\my documents\downloads\radix_installer_trial\sdthlpr.sys [?] . =============== File Associations =============== . JSEFile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 . =============== Created Last 30 ================ . 2012-01-12 13:30:17 43520 -c–a-w- c:\windows\system32\dllcache\OLD125.tmp 2012-01-12 13:30:17 16439 -c–a-w- c:\windows\system32\dllcache\OLD123.tmp 2012-01-12 13:30:16 20540 -c–a-w- c:\windows\system32\dllcache\OLD121.tmp 2012-01-12 13:30:11 76288 -c–a-w- c:\windows\system32\dllcache\OLD11C.tmp 2012-01-12 13:30:11 46592 -c–a-w- c:\windows\system32\dllcache\OLD11F.tmp 2012-01-12 13:30:09 188480 -c–a-w- c:\windows\system32\dllcache\OLD119.tmp 2012-01-12 13:30:08 275968 -c–a-w- c:\windows\system32\dllcache\OLD116.tmp 2012-01-12 13:29:53 16439 -c–a-w- c:\windows\system32\dllcache\OLD113.tmp 2012-01-12 13:29:52 20540 -c–a-w- c:\windows\system32\dllcache\OLD110.tmp 2012-01-12 13:29:48 290816 -c–a-w- c:\windows\system32\dllcache\OLD10D.tmp 2012-01-12 13:29:47 43520 -c–a-w- c:\windows\system32\dllcache\OLD10A.tmp 2012-01-12 13:29:45 16439 -c–a-w- c:\windows\system32\dllcache\OLD107.tmp 2012-01-12 13:29:44 20540 -c–a-w- c:\windows\system32\dllcache\OLD104.tmp 2012-01-03 13:10:44 182672 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2011-12-28 11:39:56 ——– d—–w- c:\program files\common files\xing shared 2011-12-24 09:12:21 ——– d—–w- c:\windows\system32\wbem\mof\bad 2011-12-22 09:19:22 20464 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-22 09:19:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-12-19 10:02:17 ——– d—–w- c:\documents and settings\all users\application data\Corel 2011-12-17 11:31:28 637848 —-a-w- c:\windows\system32\npdeployJava1.dll 2011-12-14 12:23:32 56208 —-a-w- c:\windows\system32\drivers\RapportKELL.sys . ==================== Find3M ==================== . 2011-12-28 11:38:14 499712 —-a-w- c:\windows\system32\msvcp71.dll 2011-12-28 11:38:14 348160 —-a-w- c:\windows\system32\msvcr71.dll 2011-12-23 17:33:00 2672 -csha-w- c:\documents and settings\all users\application data\KGyGaAvL.sys 2011-12-17 11:31:01 567184 -c–a-w- c:\windows\system32\deployJava1.dll 2011-12-17 11:31:01 141312 —-a-w- c:\windows\system32\javacpl.cpl 2011-11-25 21:57:19 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-21 12:29:26 16400 -c–a-w- c:\windows\system32\drivers\LNonPnP.sys 2011-11-18 12:35:08 60416 -c–a-w- c:\windows\system32\packager.exe 2011-11-04 19:20:51 916992 —-a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20:51 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20:51 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23:59 385024 —-a-w- c:\windows\system32\html.iec 2011-11-03 15:28:36 386048 -c–a-w- c:\windows\system32\qdvd.dll 2011-11-03 15:28:36 1292288 —-a-w- c:\windows\system32\quartz.dll 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37:08 2148864 -c–a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:02 2027008 -c–a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-24 14:29:02 94208 -c–a-w- c:\windows\system32\QuickTimeVR.qtx 2011-10-24 14:29:02 69632 -c–a-w- c:\windows\system32\QuickTime.qts 2011-10-14 17:38:00 456192 -c–a-w- c:\windows\system32\encdec.dll . ============= FINISH: 17:02:47.95 =============== aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-12 17:04:40 —————————– 17:04:40.734 OS Version: Windows 5.1.2600 Service Pack 3 17:04:40.734 Number of processors: 2 586 0x604 17:04:40.750 ComputerName: NEIL-A672D62AD1 UserName: Neil 17:04:45.375 Initialize success 17:05:04.453 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 17:05:04.453 Disk 0 Vendor: SAMSUNG_SP2504C VT100-48 Size: 238418MB BusType: 3 17:05:04.484 Disk 0 MBR read successfully 17:05:04.484 Disk 0 MBR scan 17:05:04.484 Disk 0 Windows XP default MBR code 17:05:04.484 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63 17:05:04.500 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 174032 MB offset 96390 17:05:04.515 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 59576 MB offset 356514480 17:05:04.546 Disk 0 Partition 4 00 DB CP/M / CTOS MSDOS5.0 4753 MB offset 478528155 17:05:04.562 Disk 0 scanning sectors +488263545 17:05:04.656 Disk 0 scanning C:\WINDOWS\system32\drivers 17:05:26.750 Service scanning 17:05:31.406 Modules scanning 17:05:54.875 Module: C:\WINDOWS\System32\DLA\DLADResN.SYS **SUSPICIOUS** 17:06:12.015 Disk 0 trace - called modules: 17:06:12.031 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys 17:06:12.031 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b22aab8] 17:06:12.046 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-17[0x8b203b00] 17:06:12.046 Scan finished successfully 17:06:47.515 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Neil\Desktop\MBR.dat" 17:06:47.531 The log file has been saved successfully to "C:\Documents and Settings\Neil\Desktop\aswMBR.txt"

Attachments:

Hi neilski,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-
ComboFix 12-01-12.02 - Neil 12/01/2012 17:50:42.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3318.2509 [GMT 0:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ZoneAlarm Security Suite Antivirus *Disabled/Outdated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Free Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\windows\kb913800.exe
c:\windows\system32\20041216.dat
c:\windows\system32\Cache
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\2eeb84b414669877.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\bb22143a9bf00f31.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\Drivers\dbtfqtyaxlbq.sys
c:\windows\system32\drivers\ghoxhpilldkb.sys
c:\windows\system32\Drivers\pgfsjgmlhngc.sys
c:\windows\system32\Drivers\qfgnwwlonbkj.sys
c:\windows\system32\PowerToyReadme.htm
G:\autorun.inf
.
c:\windows\system32\drivers\i8042prt.sys was missing
Restored copy from - c:\windows\ServicePackFiles\i386\i8042prt.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_dbtfqtyaxlbq
——-\Legacy_ghoxhpilldkb
——-\Legacy_pgfsjgmlhngc
——-\Legacy_qfgnwwlonbkj
——-\Service_dbtfqtyaxlbq
——-\Service_ghoxhpilldkb
——-\Service_pgfsjgmlhngc
——-\Service_qfgnwwlonbkj
.
.
((((((((((((((((((((((((( Files Created from 2011-12-12 to 2012-01-12 )))))))))))))))))))))))))))))))
.
.
2012-01-12 18:14 . 2012-01-12 18:19 5277429 -c–a-w- C:\Ntf3.tmp
2012-01-12 18:14 . 2012-01-12 18:14 67 -c–a-w- C:\Ntf4.tmp
2012-01-12 18:03 . 2008-04-13 19:18 52480 -c–a-w- c:\windows\system32\dllcache\i8042prt.sys
2012-01-12 18:03 . 2008-04-13 19:18 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2011-12-28 12:23 . 2011-12-28 12:23 ——– d—–w- c:\documents and settings\Neil\Application Data\Canon
2011-12-28 11:39 . 2011-12-28 11:39 ——– d—–w- c:\program files\Common Files\xing shared
2011-12-24 09:12 . 2011-12-24 09:12 ——– d—–w- c:\windows\system32\wbem\mof\bad
2011-12-22 09:19 . 2011-12-28 11:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-22 09:19 . 2011-12-10 15:24 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-19 10:13 . 2011-12-19 10:13 ——– d—–w- c:\documents and settings\Amanda\Application Data\Logitech
2011-12-19 10:02 . 2011-12-23 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Corel
2011-12-17 11:31 . 2011-12-17 11:31 ——– d—–w- c:\program files\Common Files\Java
2011-12-17 11:31 . 2011-12-17 11:31 637848 —-a-w- c:\windows\system32\npdeployJava1.dll
2011-12-14 12:23 . 2011-12-14 12:23 56208 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-28 11:38 . 2011-11-19 11:51 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-12-28 11:38 . 2006-11-21 15:43 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-12-23 17:33 . 2009-09-24 20:36 2672 -csha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2011-12-17 11:31 . 2011-06-12 21:31 141312 —-a-w- c:\windows\system32\javacpl.cpl
2011-12-17 11:31 . 2010-11-24 12:46 567184 -c–a-w- c:\windows\system32\deployJava1.dll
2011-11-25 21:57 . 2004-08-10 11:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2004-08-10 11:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 12:29 . 2011-06-18 15:17 16400 -c–a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-11-18 12:35 . 2004-08-10 11:00 60416 -c–a-w- c:\windows\system32\packager.exe
2011-11-04 19:20 . 2004-08-10 11:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-10 11:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-10 11:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-10 11:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-03 15:28 . 2004-08-10 11:00 386048 -c–a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2004-08-10 11:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2004-08-10 11:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-10 11:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-08-10 11:00 2148864 -c–a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 -c–a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 14:29 . 2011-10-24 14:29 94208 -c–a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 14:29 . 2011-10-24 14:29 69632 -c–a-w- c:\windows\system32\QuickTime.qts
2011-10-20 20:33 . 2011-10-20 20:33 53248 -c–a-r- c:\documents and settings\Neil\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-11-09 73360]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-11-03 738944]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 -c–a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW]
2011-11-03 14:44 738944 —-a-w- c:\program files\CheckPoint\ZAForceField\ForceField.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"ISW"=c:\program files\CheckPoint\ZAForceField\ForceField.exe /icon="hidden"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [11/07/2011 00:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [13/09/2011 05:30 32592]
R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [07/01/2008 12:12 15172]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [11/07/2011 00:13 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/07/2011 00:14 295248]
R1 RapportCerberus_34302;RapportCerberus_34302;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys [15/12/2011 16:54 228208]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [14/12/2011 12:23 71440]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [14/12/2011 12:23 164112]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [12/10/2011 06:25 4433248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [02/08/2011 05:09 192776]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [03/11/2011 14:44 27016]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [03/11/2011 14:44 497280]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [18/06/2011 15:16 12184]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [14/12/2011 12:23 931640]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [11/07/2011 00:14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [11/07/2011 00:14 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [11/07/2011 00:14 16720]
R3 RapportIaso;RapportIaso;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportIaso.sys [07/08/2011 12:28 21520]
S1 RapportBuka;RapportBuka;\??\c:\windows\system32\drivers\RapportBuka.sys –> c:\windows\system32\drivers\RapportBuka.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2009 09:44 133104]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 18:19 13592]
S3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [26/02/2011 19:36 1714176]
S3 avera800;AVerMedia DVB-T BDA Video Capture(A800);c:\windows\system32\drivers\avera800.sys [22/11/2006 10:20 41600]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2009 09:44 133104]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [10/04/2010 16:05 266544]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [10/08/2004 11:00 14336]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [21/11/2006 14:28 272128]
S3 SDTHelper;Helper driver for SDT-Tool;\??\c:\documents and settings\Neil\My Documents\Downloads\radix_installer_trial\sdthlpr.sys –> c:\documents and settings\Neil\My Documents\Downloads\radix_installer_trial\sdthlpr.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-01-12 c:\windows\Tasks\Auslogics Disk Defrag Sheduled Defragmentation.job
- c:\program files\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe [2011-11-15 15:09]
.
2012-01-12 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-03-01 16:09]
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 09:43]
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1004Core.job
- c:\documents and settings\Hannah\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-12 08:57]
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1004UA.job
- c:\documents and settings\Hannah\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-12 08:57]
.
2012-01-12 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1229272821-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-01-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1229272821-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-01-12 c:\windows\Tasks\User_Feed_Synchronization-{D7175847-31C0-4205-A548-03632A903D24}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://news.bbc.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.0.1
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-12 18:19
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(996)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(1060)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'explorer.exe'(3160)
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2012-01-12 18:30:36 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-12 18:30
.
Pre-Run: 133,027,799,040 bytes free
Post-Run: 132,818,759,680 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - E83AFF8088A47FB079635D85A26FD156
Hi neilski,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    DDS::
    uURLSearchHooks: H - No File
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    {e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
    
    File::
    C:\Ntf3.tmp
    C:\Ntf4.tmp
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

In your next reply please post the log created by ComboFix. :)
ComboFix 12-01-12.04 - Neil 12/01/2012 20:06:20.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3318.2550 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Neil\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ZoneAlarm Security Suite Antivirus *Disabled/Outdated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Free Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
FILE ::
"C:\Ntf3.tmp"
"C:\Ntf4.tmp"
.
.
((((((((((((((((((((((((( Files Created from 2011-12-12 to 2012-01-12 )))))))))))))))))))))))))))))))
.
.
2012-01-12 18:14 . 2012-01-12 18:19 5277429 -c–a-w- C:\Ntf3.tmp
2012-01-12 18:14 . 2012-01-12 18:14 67 -c–a-w- C:\Ntf4.tmp
2012-01-12 18:03 . 2008-04-13 19:18 52480 -c–a-w- c:\windows\system32\dllcache\i8042prt.sys
2012-01-12 18:03 . 2008-04-13 19:18 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2011-12-28 12:23 . 2011-12-28 12:23 ——– d—–w- c:\documents and settings\Neil\Application Data\Canon
2011-12-28 11:39 . 2011-12-28 11:39 ——– d—–w- c:\program files\Common Files\xing shared
2011-12-24 09:12 . 2011-12-24 09:12 ——– d—–w- c:\windows\system32\wbem\mof\bad
2011-12-22 09:19 . 2011-12-28 11:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-22 09:19 . 2011-12-10 15:24 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-19 10:13 . 2011-12-19 10:13 ——– d—–w- c:\documents and settings\Amanda\Application Data\Logitech
2011-12-19 10:02 . 2011-12-23 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Corel
2011-12-17 11:31 . 2011-12-17 11:31 ——– d—–w- c:\program files\Common Files\Java
2011-12-17 11:31 . 2011-12-17 11:31 637848 —-a-w- c:\windows\system32\npdeployJava1.dll
2011-12-14 12:23 . 2011-12-14 12:23 56208 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-28 11:38 . 2011-11-19 11:51 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-12-28 11:38 . 2006-11-21 15:43 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-12-23 17:33 . 2009-09-24 20:36 2672 -csha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2011-12-17 11:31 . 2011-06-12 21:31 141312 —-a-w- c:\windows\system32\javacpl.cpl
2011-12-17 11:31 . 2010-11-24 12:46 567184 -c–a-w- c:\windows\system32\deployJava1.dll
2011-11-25 21:57 . 2004-08-10 11:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2004-08-10 11:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 12:29 . 2011-06-18 15:17 16400 -c–a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-11-18 12:35 . 2004-08-10 11:00 60416 -c–a-w- c:\windows\system32\packager.exe
2011-11-04 19:20 . 2004-08-10 11:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-10 11:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-10 11:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-10 11:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-03 15:28 . 2004-08-10 11:00 386048 -c–a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2004-08-10 11:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2004-08-10 11:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-10 11:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-08-10 11:00 2148864 -c–a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 -c–a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 14:29 . 2011-10-24 14:29 94208 -c–a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 14:29 . 2011-10-24 14:29 69632 -c–a-w- c:\windows\system32\QuickTime.qts
2011-10-20 20:33 . 2011-10-20 20:33 53248 -c–a-r- c:\documents and settings\Neil\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-11-09 73360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 -c–a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW]
2011-11-03 14:44 738944 —-a-w- c:\program files\CheckPoint\ZAForceField\ForceField.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"ISW"=c:\program files\CheckPoint\ZAForceField\ForceField.exe /icon="hidden"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [11/07/2011 00:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [13/09/2011 05:30 32592]
R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [07/01/2008 12:12 15172]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [11/07/2011 00:13 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/07/2011 00:14 295248]
R1 RapportCerberus_34302;RapportCerberus_34302;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys [15/12/2011 16:54 228208]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [14/12/2011 12:23 71440]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [14/12/2011 12:23 164112]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [12/10/2011 06:25 4433248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [02/08/2011 05:09 192776]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [03/11/2011 14:44 27016]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [03/11/2011 14:44 497280]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [18/06/2011 15:16 12184]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [14/12/2011 12:23 931640]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [11/07/2011 00:14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [11/07/2011 00:14 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [11/07/2011 00:14 16720]
R3 RapportIaso;RapportIaso;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportIaso.sys [07/08/2011 12:28 21520]
S1 RapportBuka;RapportBuka;\??\c:\windows\system32\drivers\RapportBuka.sys –> c:\windows\system32\drivers\RapportBuka.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2009 09:44 133104]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 18:19 13592]
S3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [26/02/2011 19:36 1714176]
S3 avera800;AVerMedia DVB-T BDA Video Capture(A800);c:\windows\system32\drivers\avera800.sys [22/11/2006 10:20 41600]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2009 09:44 133104]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [10/04/2010 16:05 266544]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [10/08/2004 11:00 14336]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [21/11/2006 14:28 272128]
S3 SDTHelper;Helper driver for SDT-Tool;\??\c:\documents and settings\Neil\My Documents\Downloads\radix_installer_trial\sdthlpr.sys –> c:\documents and settings\Neil\My Documents\Downloads\radix_installer_trial\sdthlpr.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-01-12 c:\windows\Tasks\Auslogics Disk Defrag Sheduled Defragmentation.job
- c:\program files\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe [2011-11-15 15:09]
.
2012-01-12 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-03-01 16:09]
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 09:43]
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1004Core.job
- c:\documents and settings\Hannah\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-12 08:57]
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1004UA.job
- c:\documents and settings\Hannah\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-12 08:57]
.
2012-01-12 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1229272821-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-01-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1229272821-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-01-12 c:\windows\Tasks\User_Feed_Synchronization-{D7175847-31C0-4205-A548-03632A903D24}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://news.bbc.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.0.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-ISW - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-12 20:16
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(996)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\system32\igfxdev.dll
.
- - - - - - - > 'lsass.exe'(1060)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'explorer.exe'(6068)
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-01-12 20:20:53
ComboFix-quarantined-files.txt 2012-01-12 20:20
ComboFix2.txt 2012-01-12 18:30
.
Pre-Run: 132,722,843,648 bytes free
Post-Run: 132,711,886,848 bytes free
.
- - End Of File - - 80BB763BCBC23A1CE28CDAB1384027A7
Hi,

I see that you have Malwarebytes on your computer. Please open Malwarebytes, update it and then run a Quick Scan. There will be a log created that I will need in your next reply.
———-

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]
  • Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
———-

In your next reply please post the logs made by Malwarebytes and ESET online scanner. :)
MAlwarebytes log Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.12.05 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Neil :: NEIL-A672D62AD1 [administrator] 12/01/2012 20:31:09 mbam-log-2012-01-12 (20-31-09).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 216821 Time elapsed: 13 minute(s), 7 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Eset scan results C:\Documents and Settings\Hannah\Local Settings\Temp\Update_3df7.exe a variant of Win32/MessengerPlus.A application C:\Documents and Settings\Hannah\Local Settings\Temp\Update_e189.exe a variant of Win32/MessengerPlus.A application C:\Documents and Settings\Neil\My Documents\Downloaded Program Updates\zlsSetup_70_462_000_en.exe a variant of Win32/AdInstaller application
Hi neilski,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    File::
    C:\Documents and Settings\Hannah\Local Settings\Temp\Update_3df7.exe	
    C:\Documents and Settings\Hannah\Local Settings\Temp\Update_e189.exe	
    C:\Documents and Settings\Neil\My Documents\Downloaded Program Updates\zlsSetup_70_462_000_en.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

In your next reply please post the logs created by ComboFix and let me know how your system is running. :)
ComboFix 12-01-13.03 - Neil 13/01/2012 16:23:56.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3318.2712 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Neil\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ZoneAlarm Security Suite Antivirus *Disabled/Outdated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Free Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
FILE ::
"c:\documents and settings\Hannah\Local Settings\Temp\Update_3df7.exe"
"c:\documents and settings\Hannah\Local Settings\Temp\Update_e189.exe"
"c:\documents and settings\Neil\My Documents\Downloaded Program Updates\zlsSetup_70_462_000_en.exe"
.
.
((((((((((((((((((((((((( Files Created from 2011-12-13 to 2012-01-13 )))))))))))))))))))))))))))))))
.
.
2012-01-12 20:55 . 2012-01-12 20:55 ——– d—–w- c:\program files\ESET
2012-01-12 18:14 . 2012-01-12 18:19 5277429 -c–a-w- C:\Ntf3.tmp
2012-01-12 18:14 . 2012-01-12 18:14 67 -c–a-w- C:\Ntf4.tmp
2012-01-12 18:03 . 2008-04-13 19:18 52480 -c–a-w- c:\windows\system32\dllcache\i8042prt.sys
2012-01-12 18:03 . 2008-04-13 19:18 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2011-12-28 12:23 . 2011-12-28 12:23 ——– d—–w- c:\documents and settings\Neil\Application Data\Canon
2011-12-28 11:39 . 2011-12-28 11:39 ——– d—–w- c:\program files\Common Files\xing shared
2011-12-24 09:12 . 2011-12-24 09:12 ——– d—–w- c:\windows\system32\wbem\mof\bad
2011-12-22 09:19 . 2011-12-28 11:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-22 09:19 . 2011-12-10 15:24 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-19 10:13 . 2011-12-19 10:13 ——– d—–w- c:\documents and settings\Amanda\Application Data\Logitech
2011-12-19 10:02 . 2011-12-23 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Corel
2011-12-17 11:31 . 2011-12-17 11:31 ——– d—–w- c:\program files\Common Files\Java
2011-12-17 11:31 . 2011-12-17 11:31 637848 —-a-w- c:\windows\system32\npdeployJava1.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-28 11:38 . 2011-11-19 11:51 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-12-28 11:38 . 2006-11-21 15:43 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-12-23 17:33 . 2009-09-24 20:36 2672 -csha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2011-12-17 11:31 . 2011-06-12 21:31 141312 —-a-w- c:\windows\system32\javacpl.cpl
2011-12-17 11:31 . 2010-11-24 12:46 567184 -c–a-w- c:\windows\system32\deployJava1.dll
2011-12-14 12:23 . 2011-12-14 12:23 56208 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2011-11-25 21:57 . 2004-08-10 11:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2004-08-10 11:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 12:29 . 2011-06-18 15:17 16400 -c–a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-11-18 12:35 . 2004-08-10 11:00 60416 -c–a-w- c:\windows\system32\packager.exe
2011-11-04 19:20 . 2004-08-10 11:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-10 11:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-10 11:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-10 11:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-03 15:28 . 2004-08-10 11:00 386048 -c–a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2004-08-10 11:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2004-08-10 11:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-10 11:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-08-10 11:00 2148864 -c–a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 -c–a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 14:29 . 2011-10-24 14:29 94208 -c–a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 14:29 . 2011-10-24 14:29 69632 -c–a-w- c:\windows\system32\QuickTime.qts
2011-10-20 20:33 . 2011-10-20 20:33 53248 -c–a-r- c:\documents and settings\Neil\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-11-09 73360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 -c–a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW]
2011-11-03 14:44 738944 —-a-w- c:\program files\CheckPoint\ZAForceField\ForceField.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"ISW"=c:\program files\CheckPoint\ZAForceField\ForceField.exe /icon="hidden"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [11/07/2011 00:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [13/09/2011 05:30 32592]
R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [07/01/2008 12:12 15172]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [11/07/2011 00:13 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/07/2011 00:14 295248]
R1 RapportCerberus_34302;RapportCerberus_34302;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys [15/12/2011 16:54 228208]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [14/12/2011 12:23 71440]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [14/12/2011 12:23 164112]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [02/08/2011 05:09 192776]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [03/11/2011 14:44 27016]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [03/11/2011 14:44 497280]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [18/06/2011 15:16 12184]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [14/12/2011 12:23 931640]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [11/07/2011 00:14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [11/07/2011 00:14 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [11/07/2011 00:14 16720]
R3 RapportIaso;RapportIaso;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportIaso.sys [07/08/2011 12:28 21520]
S1 RapportBuka;RapportBuka;\??\c:\windows\system32\drivers\RapportBuka.sys –> c:\windows\system32\drivers\RapportBuka.sys [?]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [12/10/2011 06:25 4433248]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2009 09:44 133104]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 18:19 13592]
S3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [26/02/2011 19:36 1714176]
S3 avera800;AVerMedia DVB-T BDA Video Capture(A800);c:\windows\system32\drivers\avera800.sys [22/11/2006 10:20 41600]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2009 09:44 133104]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [10/04/2010 16:05 266544]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [10/08/2004 11:00 14336]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [21/11/2006 14:28 272128]
S3 SDTHelper;Helper driver for SDT-Tool;\??\c:\documents and settings\Neil\My Documents\Downloads\radix_installer_trial\sdthlpr.sys –> c:\documents and settings\Neil\My Documents\Downloads\radix_installer_trial\sdthlpr.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-01-12 c:\windows\Tasks\Auslogics Disk Defrag Sheduled Defragmentation.job
- c:\program files\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe [2011-11-15 15:09]
.
2012-01-12 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-03-01 16:09]
.
2012-01-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 09:43]
.
2012-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1004Core.job
- c:\documents and settings\Hannah\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-12 08:57]
.
2012-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1004UA.job
- c:\documents and settings\Hannah\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-12 08:57]
.
2012-01-12 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1229272821-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-01-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1229272821-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-01-13 c:\windows\Tasks\User_Feed_Synchronization-{D7175847-31C0-4205-A548-03632A903D24}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://news.bbc.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.0.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-13 16:39
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(996)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\system32\igfxdev.dll
.
- - - - - - - > 'lsass.exe'(1060)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'explorer.exe'(1548)
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-01-13 16:43:18
ComboFix-quarantined-files.txt 2012-01-13 16:43
ComboFix2.txt 2012-01-12 20:20
ComboFix3.txt 2012-01-12 18:30
.
Pre-Run: 132,275,134,464 bytes free
Post-Run: 132,269,654,016 bytes free
.
- - End Of File - - D84DFBCF86705AA6B58847318E0553ED
I rebooted and it was very slow but I'll give it another try later. No significant improvements whilst using other programmes. Did you find anything suspicious? Thanks Neil
I didn't find anything particularly bad. I do notice that you are running AVG and ZoneAlarm. From what I have seen using both of those programs, they can weigh heavy on resources. Unless you are paying for either of those I would consider using a different antivirus and firewall. Let me know if you would like to try different programs. ————

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI