This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

frequent freezes [Solved]

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there
This is relatively recent new HD and reinstall of XP home and restoration of files moved over from old HD.
Last month or so every so often computer freezes up: cursor won't move, task manager window won't come up.

I've scanned w/Adaware and AVG free (both today).

Here is HijackThis log:
Thanx,
denno

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:04:02 PM, on 1/30/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fppdis

1.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI

9HA.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Common Files\Java\Java

Update\jusched.exe
C:\Program Files\Fighters\Tray\FightersTray.exe
C:\Program Files\Fighters\SPAMfighter\sfagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program

Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
C:\Program Files\OpenOffice.org

3\program\soffice.exe
C:\Program Files\OpenOffice.org

3\program\soffice.bin
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\IDrive\IDriveE Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\Program Files\IDrive\IDriveETray.exe
C:\Program Files\IDrive\IDriveEBackground.exe
C:\Program Files\Fighters\SPAMfighter\sfus.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fighters\FighterSuiteService.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\IDrive\IDrivePlugin.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\azzCardfile\azzCardfile.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\Mozilla

Firefox\plugin-container.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla

Firefox\plugin-container.exe
C:\Program Files\Adobe\Reader

10.0\Reader\AcroRd32.exe
C:\Program Files\Adobe\Reader

10.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and

Settings\Denno\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub -

{18DF081C-E8AD-4283-A596-FA578C2EBDC3} -

C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter -

{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -

C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: BFlix Toolbar -

{a6bf16ab-42a1-4bc5-965d-5e407e449aaa} -

C:\Program Files\bflixtoolbar\vmntemplateX.dll
O2 - BHO: 100% Free Chess Toolbar Helper -

{AE4F4014-3BF4-4CEB-B46C-3730A2340C4E} -

C:\Program Files\100% Free Chess

Toolbar\v3.3.0.1\100%_Free_Chess_Toolbar.dll

(file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper -

{DBC80044-A445-435b-BC74-9C25C1C588A9} -

C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl -

{E7E6F031-17CE-4C07-BC86-EABFE594F69C} -

C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Yontoo Layers -

{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -

C:\Program Files\Yontoo Layers\YontooIEClient.dll
O3 - Toolbar: 100% Free Chess Toolbar -

{6F4F95AF-1647-4B72-A632-055405455423} -

C:\Program Files\100% Free Chess

Toolbar\v3.3.0.1\100%_Free_Chess_Toolbar.dll

(file missing)
O3 - Toolbar: BFlix Toolbar -

{a6bf16ab-42a1-4bc5-965d-5e407e449aaa} -

C:\Program Files\bflixtoolbar\vmntemplateX.dll
O4 - HKLM\..\Run: [IgfxTray]

C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds]

C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence]

C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program

Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v1]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fppdis

1.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX620

Series]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI

9HA.EXE /P31 "EPSON Stylus Photo RX620 Series"

/O5 "LPT1:" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [EPSON Stylus Photo RX620

Series (Copy 1)]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI

9HA.EXE /P40 "EPSON Stylus Photo RX620 Series

(Copy 1)" /O6 "USB001" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program

Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program

Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [NeroCheck]

C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched]

"C:\Program Files\Common Files\Java\Java

Update\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck]

%systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [CommonToolkitTray] C:\Program

Files\Fighters\Tray\FightersTray.exe
O4 - HKLM\..\Run: [sfagent] C:\Program

Files\Fighters\SPAMfighter\sfagent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program

Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDriveE Startup] "C:\Program

Files\IDrive\IDrvieEStartup.exe" Hide
O4 - HKCU\..\Run: [InstallIQUpdater] "C:\Program

Files\W3i\InstallIQUpdater\InstallIQUpdater.exe"

/silent /autorun
O4 - Startup: IDrive Tray.lnk = C:\Program

Files\IDrive\IDriveEReg2ini.exe
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program

Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk =

C:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Event Reminder.lnk =

C:\Program Files\The Print Shop 23.1\Remind.exe
O9 - Extra button: (no name) -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001

- {e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}

(Shockwave Flash Object) -

http://fpdownload2.macromedia.com/get/shockwave/c

abs/flash/swflash.cab
O18 - Protocol: linkscanner -

{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -

C:\Program Files\AVG\AVG2012\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader -

{438755C2-A8BA-11D1-B96B-00A0C90312E1} -

C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories

cache daemon -

{8C7461EF-2B13-11d2-BE35-3078302C2030} -

C:\WINDOWS\system32\browseui.dll
O23 - Service: AVGIDSAgent - AVG Technologies CZ,

s.r.o. - C:\Program

Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG

Technologies CZ, s.r.o. - C:\Program

Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: IDriveE Service - Pro Softnet

Corporation - C:\Program Files\IDrive\IDriveE

Service.exe
O23 - Service: Java Quick Starter

(JavaQuickStarterService) - Sun Microsystems,

Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service -

Lavasoft Limited - C:\Program

Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. -

C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service

(LMIMaint) - LogMeIn, Inc. - C:\Program

Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. -

C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: SPAMfighter Update Service -

SPAMfighter ApS - C:\Program

Files\Fighters\SPAMfighter\sfus.exe
O23 - Service: Suite Service - SPAMfighter ApS -

C:\Program Files\Fighters\FighterSuiteService.exe

–
End of file - 8569 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to Start>Control Panel>Folder Options>View
  • Choose to "Show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_29 Run by [removed] at 0:09:57 on 2012-02-02 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.144 [GMT -5:00] . AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fppdis1.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Fighters\Tray\FightersTray.exe C:\Program Files\Fighters\SPAMfighter\sfagent.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin svchost.exe C:\Program Files\IDrive\IDriveE Service.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\Fighters\SPAMfighter\sfus.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\IDrive\IDriveETray.exe C:\Program Files\Fighters\FighterSuiteService.exe C:\Program Files\IDrive\IDriveEBackground.exe C:\Program Files\IDrive\IDrivePlugin.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\azzCardfile\azzCardfile.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Program Files\AVG\AVG2012\avgnsx.exe C:\Program Files\AVG\AVG2012\avgemcx.exe C:\Program Files\AVG\AVG2012\avgrsx.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: BFlix Toolbar: {a6bf16ab-42a1-4bc5-965d-5e407e449aaa} - c:\program files\bflixtoolbar\vmntemplateX.dll BHO: 100% Free Chess Toolbar Helper: {ae4f4014-3bf4-4ceb-b46c-3730a2340c4e} - c:\program files\100% free chess toolbar\v3.3.0.1\100%_Free_Chess_Toolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers\YontooIEClient.dll TB: 100% Free Chess Toolbar: {6f4f95af-1647-4b72-a632-055405455423} - c:\program files\100% free chess toolbar\v3.3.0.1\100%_Free_Chess_Toolbar.dll TB: BFlix Toolbar: {a6bf16ab-42a1-4bc5-965d-5e407e449aaa} - c:\program files\bflixtoolbar\vmntemplateX.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [IDriveE Startup] "c:\program files\idrive\IDrvieEStartup.exe" Hide uRun: [InstallIQUpdater] "c:\program files\w3i\installiqupdater\InstallIQUpdater.exe" /silent /autorun mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [pdfFactory Pro Dispatcher v1] c:\windows\system32\spool\drivers\w32x86\2\fppdis1.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [EPSON Stylus Photo RX620 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9HA.EXE /P31 "EPSON Stylus Photo RX620 Series" /O5 "LPT1:" /M "Stylus Photo RX620" mRun: [EPSON Stylus Photo RX620 Series (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9HA.EXE /P40 "EPSON Stylus Photo RX620 Series (Copy 1)" /O6 "USB001" /M "Stylus Photo RX620" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [CommonToolkitTray] c:\program files\fighters\tray\FightersTray.exe mRun: [sfagent] c:\program files\fighters\spamfighter\sfagent.exe StartupFolder: c:\docume~1\denno\startm~1\programs\startup\idrive~1.lnk - c:\program files\idrive\IDriveEReg2ini.exe StartupFolder: c:\docume~1\denno\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\eventr~1.lnk - c:\program files\the print shop 23.1\Remind.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{CFF501FC-74FD-45DF-A444-135669F120CF} : DhcpNameServer = [removed] [removed] Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Notify: igfxcui - igfxdev.dll Notify: LMIinit - LMIinit.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\denno\application data\mozilla\firefox\profiles\bagfegyi.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z134&form=ZGAADF&install_date=20111124&q= FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\documents and settings\denno\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 23120] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-9-24 64512] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 230608] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 40016] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-4 295248] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776] R2 IDriveE Service;IDriveE Service;c:\program files\idrive\IDriveE Service.exe [2011-6-17 157128] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-8-18 2152152] R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-7-6 374152] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-1-11 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-8-22 47640] R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\fighters\spamfighter\sfus.exe [2011-12-20 215688] R2 Suite Service;Suite Service;c:\program files\fighters\FighterSuiteService.exe [2011-12-13 1324680] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134608] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24272] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 16720] S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-8-18 15232] S4 LMIRfsClientNP;LMIRfsClientNP; [x] . =============== Created Last 30 ================ . 2012-01-09 20:46:57 ——– d—–w- c:\documents and settings\denno\local settings\application data\WMTools Downloaded Files 2012-01-06 17:11:27 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll 2012-01-06 17:11:27 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll 2012-01-06 17:11:27 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll 2012-01-06 17:11:27 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll 2012-01-06 03:11:05 ——– d—–w- c:\program files\Fighters 2012-01-06 03:11:02 ——– d—–w- c:\documents and settings\denno\application data\Fighters 2012-01-06 03:10:11 ——– d—–w- c:\documents and settings\all users\application data\Fighters 2012-01-04 16:32:48 ——– d-sh–w- c:\windows\system32\AI_RecycleBin 2012-01-04 16:32:43 ——– d—–w- c:\program files\W3i 2012-01-04 16:32:43 ——– d—–w- c:\documents and settings\all users\application data\W3i 2012-01-03 13:10:44 182672 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll . ==================== Find3M ==================== . 2011-12-19 15:56:41 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2011-12-19 15:56:41 52096 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll 2011-12-19 15:56:40 87424 —-a-w- c:\windows\system32\LMIinit.dll 2011-12-19 15:56:40 30592 —-a-w- c:\windows\system32\LMIport.dll 2011-11-25 21:57:19 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-21 17:05:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-18 12:35:08 60416 —-a-w- c:\windows\system32\packager.exe 2011-11-16 14:21:44 354816 —-a-w- c:\windows\system32\winhttp.dll 2011-11-16 14:21:44 152064 —-a-w- c:\windows\system32\schannel.dll . ============= FINISH: 0:10:43.35 ===============
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 6/9/2011 12:56:50 PM System Uptime: 1/31/2012 3:17:07 AM (45 hours ago) . Motherboard: Dell Inc. | | 0CU409 Processor: Intel® Pentium® Dual CPU E2180 @ 2.00GHz | Socket 775 | 1994/200mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 298 GiB total, 253.842 GiB free. D: is CDROM (UDF) E: is FIXED (NTFS) - 233 GiB total, 194.388 GiB free. F: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP183: 11/4/2011 7:52:42 PM - System Checkpoint RP184: 11/5/2011 8:53:48 PM - System Checkpoint RP185: 11/6/2011 9:14:55 PM - System Checkpoint RP186: 11/7/2011 9:21:37 PM - System Checkpoint RP187: 11/8/2011 9:19:34 PM - Software Distribution Service 3.0 RP188: 11/9/2011 9:38:25 PM - System Checkpoint RP189: 11/10/2011 10:22:40 PM - System Checkpoint RP190: 11/11/2011 11:21:37 PM - System Checkpoint RP191: 11/12/2011 3:00:53 AM - Software Distribution Service 3.0 RP192: 11/13/2011 3:35:28 AM - System Checkpoint RP193: 11/14/2011 5:07:50 AM - System Checkpoint RP194: 11/15/2011 5:25:25 AM - System Checkpoint RP195: 11/16/2011 5:31:31 AM - System Checkpoint RP196: 11/17/2011 6:29:54 AM - System Checkpoint RP197: 11/18/2011 7:29:54 AM - System Checkpoint RP198: 11/19/2011 8:30:58 AM - System Checkpoint RP199: 11/20/2011 8:48:54 AM - System Checkpoint RP200: 11/21/2011 9:43:50 AM - System Checkpoint RP201: 11/22/2011 9:57:06 AM - System Checkpoint RP202: 11/23/2011 9:57:18 AM - System Checkpoint RP203: 11/24/2011 10:16:41 AM - System Checkpoint RP204: 11/25/2011 11:35:25 AM - System Checkpoint RP205: 11/26/2011 12:17:47 PM - System Checkpoint RP206: 11/27/2011 12:57:19 PM - System Checkpoint RP207: 11/28/2011 12:58:23 PM - System Checkpoint RP208: 11/29/2011 1:57:18 PM - System Checkpoint RP209: 11/30/2011 1:57:42 PM - System Checkpoint RP210: 12/1/2011 2:22:59 PM - System Checkpoint RP211: 12/2/2011 2:57:42 PM - System Checkpoint RP212: 12/3/2011 2:58:47 PM - System Checkpoint RP213: 12/4/2011 4:11:24 PM - System Checkpoint RP214: 12/5/2011 4:57:43 PM - System Checkpoint RP215: 12/6/2011 5:01:49 PM - System Checkpoint RP216: 12/7/2011 6:23:28 PM - System Checkpoint RP217: 12/8/2011 7:01:41 PM - System Checkpoint RP218: 12/9/2011 8:01:42 PM - System Checkpoint RP219: 12/10/2011 9:26:37 PM - System Checkpoint RP220: 12/11/2011 9:44:39 PM - System Checkpoint RP221: 12/12/2011 9:45:43 PM - System Checkpoint RP222: 12/13/2011 10:53:48 PM - System Checkpoint RP223: 12/14/2011 11:45:46 PM - System Checkpoint RP224: 12/15/2011 3:00:14 AM - Software Distribution Service 3.0 RP225: 12/16/2011 3:38:49 AM - System Checkpoint RP226: 12/17/2011 4:26:48 AM - System Checkpoint RP227: 12/18/2011 6:49:43 AM - System Checkpoint RP228: 12/19/2011 7:00:24 AM - System Checkpoint RP229: 12/19/2011 11:21:39 AM - Printer Driver LogMeIn Printer Driver Installed RP230: 12/20/2011 11:59:08 AM - System Checkpoint RP231: 12/21/2011 12:59:08 PM - System Checkpoint RP232: 12/29/2011 2:10:35 AM - System Checkpoint RP233: 12/30/2011 2:23:33 AM - System Checkpoint RP234: 12/31/2011 2:34:06 AM - System Checkpoint RP235: 1/1/2012 3:23:36 AM - System Checkpoint RP236: 1/2/2012 4:23:37 AM - System Checkpoint RP237: 1/3/2012 5:24:41 AM - System Checkpoint RP238: 1/4/2012 5:33:24 AM - System Checkpoint RP239: 1/5/2012 6:23:54 AM - System Checkpoint RP240: 1/5/2012 10:10:59 PM - Installed SPAMfighter. RP241: 1/6/2012 10:24:00 PM - System Checkpoint RP242: 1/7/2012 11:22:26 PM - System Checkpoint RP243: 1/8/2012 11:23:32 PM - System Checkpoint RP244: 1/9/2012 11:31:42 PM - System Checkpoint RP245: 1/10/2012 2:57:55 PM - Software Distribution Service 3.0 RP246: 1/11/2012 3:00:24 AM - Software Distribution Service 3.0 RP247: 1/12/2012 3:56:39 AM - System Checkpoint RP248: 1/13/2012 4:37:27 AM - System Checkpoint RP249: 1/14/2012 5:38:34 AM - System Checkpoint RP250: 1/15/2012 6:37:27 AM - System Checkpoint RP251: 1/16/2012 7:37:27 AM - System Checkpoint RP252: 1/17/2012 7:50:18 AM - System Checkpoint RP253: 1/18/2012 8:32:45 AM - System Checkpoint RP254: 1/19/2012 11:29:36 AM - System Checkpoint RP255: 1/20/2012 11:47:02 AM - System Checkpoint RP256: 1/21/2012 12:32:55 PM - System Checkpoint RP257: 1/22/2012 2:09:47 PM - System Checkpoint RP258: 1/23/2012 2:22:27 PM - System Checkpoint RP259: 1/24/2012 2:23:16 PM - System Checkpoint RP260: 1/25/2012 4:15:53 PM - System Checkpoint RP261: 1/26/2012 4:23:17 PM - System Checkpoint RP262: 1/27/2012 10:16:37 PM - System Checkpoint RP263: 1/28/2012 10:22:14 PM - System Checkpoint RP264: 1/29/2012 11:01:25 PM - System Checkpoint RP265: 1/30/2012 11:59:00 PM - System Checkpoint RP266: 1/31/2012 3:00:13 AM - Software Distribution Service 3.0 RP267: 2/1/2012 3:42:48 AM - System Checkpoint . ==== Installed Programs ====================== . 100% Free Chess 7.30 123 Free Solitaire 2011 v8.0 Ad-Aware Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Photoshop 7.0 Adobe Reader X (10.1.2) AVG 2012 AVG PC Tuneup 2011 azzCardfile 4.1 BFlix Toolbar Dell Resource CD Desktop Taipei version 2.2 EASEUS Data Recovery Wizard Free Edition 5.5.1 EPSON Printer Software EPSON Scan File Type Assistant FinalTorrent 2011 FinePrint pdfFactory Pro Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) IDrive version 3.4.1 July 27, 2011 InstaCodecs InstallIQ Updater Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections 12.1.12.0 Java Auto Updater Java™ 6 Update 22 Java™ 6 Update 29 LivePix 1.1 LogMeIn Macromedia Dreamweaver MX Macromedia Extension Manager MagicCute Data Recovery 2011.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Web Publishing Wizard 1.52 Mozilla Firefox 9.0.1 (x86 en-US) Nero NetAssistant NetAssistant for Firefox NVIDIA Drivers OpenOffice.org 3.3 REALTEK GbE & FE Ethernet PCI NIC Driver Realtek High Definition Audio Driver Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB2530548) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB2559049) Security Update for Windows Internet Explorer 7 (KB2586448) Security Update for Windows Internet Explorer 7 (KB2618444) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB923789) Sothink FLV Player SPAMfighter svBuilder The Print Shop 23.1 Unity Web Player Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) WebFldrs XP Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 . ==== Event Viewer Messages From Past Week ======== . 1/29/2012 11:55:58 AM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.CRT. Reference error message: The referenced assembly is not installed on your system. . 1/29/2012 11:55:58 AM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Mozilla Firefox\components\browsercomps.dll. Reference error message: The operation completed successfully. . 1/29/2012 11:55:58 AM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.CRT could not be found and Last Error was The referenced assembly is not installed on your system. . ==== End Of File ===========================
Hi Denno,

I notice that you have both AVG and LavaSoft antivirus running at the same time. Having more than one antivirus program running at the same time can seriously degrade the performance of your system. Please uninstall either AVG or LavaSoft (which ever you prefer) using either the provided uninstall feature that is part of the antivirus program or through Add/Remove Programs (for Vista and Win 7 users to go to Programs and Features in the Control Panel). As a rule of thumb one should run one firewall, one antivirus program in memory, and one antispyware utility in memory. It's fine to have other security tools available on an as-needed or on-demand basis, but when multiple tools simultaneously perform the same function, you're asking for trouble.
———-

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-
First a question: I have lavasoft adaware. Didn't know it was antivirus. But I can disable it or remove it. Previous info and experience indicated that Adaware detected different things than various other programs. But you are recommending that I, for instance, keep AVG and it will deal with malware, adware, and so forth? Now, then, an apparent glitch: I've got AVG's Resident Whatsit disabled, but whan I run combofix it keeps bringing up windows claiming that components of combofix are "known malware." What gives, and what am I not doing right? Thanks
Hi denno, Lavasoft Adaware used to be a program other than an antivirus; however, Lavasoft AdWatch Live has incorporated an antivirus program along with the malware program. If it were me, I would uninstall AVG as my experience using it has shown that it is a resource hog and then keep LavaSoft. You can decide what you would like to do though. If you decide to remove AVG that should remove the problems running ComboFix too. If you decide to keep AVG and run into the warning you received while scanning with ComboFix, just continue with the scan. :) If you still have problems let me know.
Oy, what a series of PITA! Main problem is I cannot figure out how to turn off and then back on Ad-Aware. No handy drop-down box seems to exist. I did get it done once around, but cannot figure out how I did it. By accident, apparently. Finally had to uninstall and reinstall it, but then found I have no record of the ComboFix scan to give you. So I have to get the thing turned off again…after it finishes reinstalling and updating itself. Gotta go to bed now and come back to this tomorrow. I have the free version, if that clues you as to how to disable/enable it. Thanks. Denno
Hi denno,

Let's start with looking for the ComboFix log. Go to your C:\ folder and look for ComboFix.txt if it is there. If it is please post that to your next reply.

If it is not there, please run ComboFix again and continue with the scan even if you are warned about an antivirus program running.
OK, I found the switch. On a right-click menu on the tray icon.
I have removed AVG.
Some of my log-ins, saved paswords, etc. have vanished with it.

Here is the log:

ComboFix 12-02-02.02 - Denno 02/04/2012 12:15:19.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.381 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((( Files Created from 2012-01-04 to 2012-02-04 )))))))))))))))))))))))))))))))
.
.
2012-02-04 05:48 . 2012-02-04 04:12 16432 —-a-w- c:\windows\system32\lsdelete.exe
2012-02-04 05:48 . 2012-02-04 05:48 384 —ha-w- C:\aaw7boot.cmd
2012-02-04 04:01 . 2011-11-03 17:06 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2012-02-04 04:00 . 2012-02-04 04:00 ——– d—–w- c:\program files\Lavasoft
2012-02-04 03:37 . 2008-04-14 04:48 52480 -c–a-w- c:\windows\system32\dllcache\i8042prt.sys
2012-02-04 03:37 . 2008-04-14 04:48 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2012-01-09 20:46 . 2012-01-09 20:46 ——– d—–w- c:\documents and settings\Denno\Local Settings\Application Data\WMTools Downloaded Files
2012-01-06 17:11 . 2012-01-06 17:11 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-06 17:11 . 2012-01-06 17:11 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-06 17:11 . 2012-01-06 17:11 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-06 17:11 . 2012-01-06 17:11 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-01-06 03:12 . 2012-01-06 03:12 ——– d—–w- c:\documents and settings\LocalService\Application Data\Fighters
2012-01-06 03:11 . 2012-01-06 03:12 ——– d—–w- c:\program files\Fighters
2012-01-06 03:11 . 2012-01-06 03:13 ——– d—–w- c:\documents and settings\Denno\Application Data\Fighters
2012-01-06 03:10 . 2012-01-06 03:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Fighters
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-19 15:56 . 2011-08-22 18:39 52096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-12-19 15:56 . 2011-08-22 18:39 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-12-19 15:56 . 2011-08-22 18:39 30592 —-a-w- c:\windows\system32\LMIport.dll
2011-12-19 15:56 . 2011-08-22 18:38 87424 —-a-w- c:\windows\system32\LMIinit.dll
2011-11-25 21:57 . 2004-08-04 10:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2004-08-04 10:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 17:05 . 2011-06-11 19:11 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-18 12:35 . 2004-08-04 10:00 60416 —-a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2004-08-04 10:00 354816 —-a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2004-08-04 10:00 152064 —-a-w- c:\windows\system32\schannel.dll
2012-01-06 17:11 . 2011-06-10 05:07 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-04_03.40.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-04 04:03 . 2012-02-04 04:03 16384 c:\windows\Temp\Perflib_Perfdata_580.dat
+ 2012-02-04 04:01 . 2011-11-03 17:06 64512 c:\windows\system32\DRVSTORE\lbd_69523D0F7F903BDB477CD80CFD35086362532B23\Lbd.sys
- 2011-09-24 21:40 . 2011-08-18 19:25 64512 c:\windows\system32\DRVSTORE\lbd_69523D0F7F903BDB477CD80CFD35086362532B23\Lbd.sys
+ 2011-06-09 16:57 . 2012-02-04 04:04 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2011-06-09 16:57 . 2012-02-04 03:17 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2011-06-09 16:57 . 2012-02-04 03:17 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-06-09 16:57 . 2012-02-04 04:04 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2012-02-04 04:04 . 2012-02-04 04:04 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2011-06-09 16:57 . 2012-02-04 03:17 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-07-12 04:02 . 2009-07-12 04:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
- 2009-07-12 04:02 . 2009-07-12 04:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
- 2009-07-12 04:05 . 2009-07-12 04:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
- 2009-07-12 04:02 . 2009-07-12 04:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2009-07-12 03:11 . 2009-07-12 03:11 624448 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_069f922e\msvcr90.dll
- 2009-07-12 02:11 . 2009-07-12 02:11 624448 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_069f922e\msvcr90.dll
- 2009-07-12 02:11 . 2009-07-12 02:11 853312 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_069f922e\msvcp90.dll
+ 2009-07-12 03:11 . 2009-07-12 03:11 853312 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_069f922e\msvcp90.dll
- 2009-07-12 02:14 . 2009-07-12 02:14 245760 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_069f922e\msvcm90.dll
+ 2009-07-12 03:14 . 2009-07-12 03:14 245760 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_069f922e\msvcm90.dll
- 2009-07-12 02:11 . 2009-07-12 02:11 176456 c:\windows\WinSxS\amd64_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_673f7fa2\atl90.dll
+ 2009-07-12 03:11 . 2009-07-12 03:11 176456 c:\windows\WinSxS\amd64_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_673f7fa2\atl90.dll
+ 2012-02-04 04:01 . 2012-02-04 04:01 6976512 c:\windows\Installer\108c51.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-06-22 13:34 191488 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDriveE Startup"="c:\program files\IDrive\IDrvieEStartup.exe" [2011-06-24 185800]
"InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-10-11 1179648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-16 138008]
"pdfFactory Pro Dispatcher v1"="c:\windows\System32\spool\DRIVERS\W32X86\2\fppdis1.exe" [2002-06-25 356352]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-26 16132608]
"EPSON Stylus Photo RX620 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-20 98304]
"EPSON Stylus Photo RX620 Series (Copy 1)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-20 98304]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-11 63048]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"CommonToolkitTray"="c:\program files\Fighters\Tray\FightersTray.exe" [2011-12-13 1450120]
"sfagent"="c:\program files\Fighters\SPAMfighter\sfagent.exe" [2011-12-20 1197704]
.
c:\documents and settings\Denno\Start Menu\Programs\Startup\
IDrive Tray.lnk - c:\program files\IDrive\IDriveEReg2ini.exe [2011-6-17 304584]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-6-9 113664]
Event Reminder.lnk - c:\program files\The Print Shop 23.1\Remind.exe [2010-6-21 344064]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-12-19 15:56 87424 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\WS_FTP Pro\\ftp95pro.exe"=
"c:\\Program Files\\FinalTorrent\\FinalTorrent.EXE"=
"c:\\Program Files\\FinalTorrent\\FTCheckForUpdates.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/3/2012 11:01 PM 64512]
R2 IDriveE Service;IDriveE Service;c:\program files\IDrive\IDriveE Service.exe [6/17/2011 11:41 PM 157128]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [11/3/2011 12:06 PM 2152152]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [7/6/2011 3:32 PM 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 6:04 PM 12856]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe [12/20/2011 12:41 PM 215688]
R2 Suite Service;Suite Service;c:\program files\Fighters\FighterSuiteService.exe [12/13/2011 4:08 PM 1324680]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [11/3/2011 12:06 PM 15232]
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-11-03 17:06]
.
2012-02-04 c:\windows\Tasks\FinalTorrent Update Checker.job
- c:\program files\FinalTorrent\FTCheckForUpdates.exe [2011-11-25 20:24]
.
.
——- Supplementary Scan ——-
.
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Denno\Application Data\Mozilla\Firefox\Profiles\bagfegyi.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z134&form=ZGAADF&install_date=20111124&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-04 12:19
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(1692)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-02-04 12:20:45
ComboFix-quarantined-files.txt 2012-02-04 17:20
ComboFix2.txt 2012-02-04 03:43
.
Pre-Run: 279,441,117,184 bytes free
Post-Run: 279,485,583,360 bytes free
.
- - End Of File - - 0AF6F60E1F3CEEF48198834B8BD61AC8

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI