This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

live security platinum [Solved]

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had to run fixexec.exe and malwarebytes and turned off restore and restarted computer and seemed fine then about two minutes later it popped back up. Here is my hijack this log. Thank you in advance.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:46:11 PM, on 7/25/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\AOL\1317604369\ee\AOLSoftware.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\PROGRA~1\AOLDES~1.6\waol.exe
C:\PROGRA~1\AOLDES~1.6\shellmon.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1317604369\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Dorothy Powell\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\PROGRA~1\AOLDES~1.6\AOL.EXE" -b
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 9718 bytes
Hello primjunkie and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Spybot TeaTimer

Please disable this program and leave it disabled until we are done as it can interfere with some of the tools we use.
  • launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • on the left hand side, click on Tools, then click on the Resident Icon in the list.
  • uncheck the Resident TeaTimer (Protection of overall system settings) active box.
  • click on the System Startup icon in the List
  • uncheck the "TeaTimer" box and click OK at any prompts.
  • if Teatimer gives you a warning that changes were made, click Allow Change when prompted.
  • exit Spybot S&D.
(When we are finished, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup).

===================================================

I need a couple more scans to see what we’re dealing with before starting to clean up.

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Please include the following in your next post :

DDS.txt
Attach.txt
aswMBR log


Thanks

Satchfan
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_31 Run by [removed] at 11:35:52 on 2012-07-26 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.480 [GMT -4:00] . . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\stsystra.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Common Files\AOL\1317604369\ee\AOLSoftware.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Real\RealPlayer\update\realsched.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\AOLDES~1.6\waol.exe C:\PROGRA~1\AOLDES~1.6\shellmon.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Google Update] "c:\documents and settings\dorothy powell\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [AOL Fast Start] "c:\progra~1\aoldes~1.6\AOL.EXE" -b mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [HostManager] c:\program files\common files\aol\1317604369\ee\AOLSoftware.exe mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: mswsock.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{9551EC05-49DA-49B7-8203-D5C1D77BA0AE} : DhcpNameServer = 192.168.2.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: LMIinit - LMIinit.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\dorothy powell\application data\mozilla\firefox\profiles\i4mjnsgl.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-games-chromesbox-en-us&tb_uuid=20111105222643531&tb_oid=05-11-2011&tb_mrud=05-11-2011 FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9416c616-cee5-4527-8203-92236b4af295%7D&mid=cd41374a5a0547d1995fd14acce4e9e6-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=10.0.0.7&lang=en&pr=fr&d=2012-03-01%2019%3A28%3A14&sap=ku&q= FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll . —- FIREFOX POLICIES —- FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false ============= SERVICES / DRIVERS =============== . R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-6-8 374184] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-1-11 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-6-16 47640] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-7-24 655944] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-7-24 22344] S0 cerc6;cerc6; [x] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-10-22 136176] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-6-20 250056] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-10-22 136176] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-4 113120] S4 LMIRfsClientNP;LMIRfsClientNP; [x] . =============== Created Last 30 ================ . 2012-07-25 22:43:36 388096 —-a-r- c:\documents and settings\dorothy powell\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2012-07-24 20:03:44 ——– d—–w- c:\windows\system32\NtmsData 2012-07-24 19:58:15 ——– d—–w- c:\windows\system32\appmgmt 2012-07-24 13:30:55 ——– d—–w- c:\documents and settings\dorothy powell\application data\Malwarebytes 2012-07-24 13:30:40 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2012-07-24 13:30:39 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-07-24 13:30:39 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-07-22 03:16:24 ——– d—–w- c:\documents and settings\all users\application data\036E192935CFC44C15DF076B7B07D287 2012-07-20 03:08:57 ——– d—–w- c:\documents and settings\dorothy powell\application data\iFunbox_UserCache 2012-07-20 03:08:36 ——– d—–w- c:\program files\i-Funbox DevTeam 2012-07-13 01:07:19 9226440 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe 2012-07-08 23:17:49 ——– d—–w- c:\documents and settings\dorothy powell\local settings\application data\SanDisk 2012-07-08 23:17:45 ——– d—–w- c:\documents and settings\dorothy powell\local settings\application data\Spoon 2012-07-04 18:59:10 ——– d—–w- c:\windows\system32\wbem\repository\FS 2012-07-04 18:59:10 ——– d—–w- c:\windows\system32\wbem\Repository 2012-07-04 18:58:24 ——– d—–w- c:\program files\Horse Racing Simulation LLC 2012-07-04 18:58:19 ——– d–h–w- c:\documents and settings\all users\application data\{72020B27-0E75-455A-BCEC-9F6C7675B3DA} . ==================== Find3M ==================== . 2012-07-13 01:07:21 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-07-13 01:07:21 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-07-11 22:39:01 87456 —-a-w- c:\windows\system32\LMIinit.dll 2012-07-11 22:39:01 83392 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-07-11 22:39:01 52128 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll 2012-07-11 22:39:01 30624 —-a-w- c:\windows\system32\LMIport.dll 2012-06-13 13:19:59 1866112 —-a-w- c:\windows\system32\win32k.sys 2012-06-05 15:50:25 1372672 —-a-w- c:\windows\system32\msxml6.dll 2012-06-05 15:50:25 1172480 —-a-w- c:\windows\system32\msxml3.dll 2012-06-04 04:32:08 152576 —-a-w- c:\windows\system32\schannel.dll 2012-06-02 19:19:44 22040 —-a-w- c:\windows\system32\wucltui.dll.mui 2012-06-02 19:19:38 219160 —-a-w- c:\windows\system32\wuaucpl.cpl 2012-06-02 19:19:38 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui 2012-06-02 19:19:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui 2012-06-02 19:19:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui 2012-06-02 19:18:58 275696 —-a-w- c:\windows\system32\mucltui.dll 2012-06-02 19:18:58 214256 —-a-w- c:\windows\system32\muweb.dll 2012-06-02 19:18:58 17136 —-a-w- c:\windows\system32\mucltui.dll.mui 2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll 2012-05-22 01:57:38 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll.000.bak 2012-05-22 01:57:37 87424 —-a-w- c:\windows\system32\LMIinit.dll.000.bak 2012-05-16 15:08:26 916992 —-a-w- c:\windows\system32\wininet.dll 2012-05-11 14:42:33 43520 —-a-w- c:\windows\system32\licmgr10.dll 2012-05-11 14:42:33 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2012-05-11 11:38:02 385024 —-a-w- c:\windows\system32\html.iec 2012-05-04 13:16:13 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 12:32:19 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-05-02 13:46:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys . ============= FINISH: 11:36:52.12 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 6/15/2011 10:50:33 PM System Uptime: 7/25/2012 4:16:17 PM (19 hours ago) . Motherboard: Dell Inc | | Processor: AMD Athlon™ 64 X2 Dual Core Processor 3600+ | Socket M2 | 1903/1000mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 596 GiB total, 578.226 GiB free. D: is CDROM () E: is CDROM (CDFS) F: is CDROM () G: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP1: 7/24/2012 4:06:24 PM - System Checkpoint RP2: 7/25/2012 5:11:19 PM - System Checkpoint RP3: 7/25/2012 6:43:02 PM - Removed HiJackThis RP4: 7/25/2012 6:43:35 PM - Installed HiJackThis . ==== Installed Programs ====================== . . Adobe Acrobat 6.0 Standard Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Shockwave Player 11.6 AOL Uninstaller (Choose which Products to Remove) Apple Application Support Apple Mobile Device Support Apple Software Update Athlon 64 Processor Driver ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver Bonjour Broadcom 440x 10/100 Integrated Controller Canon MP Navigator EX 1.0 Canon MP470 series Conexant D850 56K V.9x DFVc Modem DivX Setup Download Updater (AOL LLC) Google Chrome Google Earth Plug-in Google Toolbar for Internet Explorer Google Update Helper HiJackThis HijackThis 1.99.1 Horse Racing Fantasy 3 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) iTunes Java Auto Updater Java™ 6 Update 31 LogMeIn MagicDisc 2.7.106 Malwarebytes Anti-Malware version 1.62.0.1300 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Picture It! Express 7.0 Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft VC9 runtime libraries Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Mozilla Firefox 14.0.1 (x86 en-US) Mozilla Maintenance Service NVIDIA Drivers QuickTime RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer RealUpgrade 1.1 Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft Office 2007 suites (KB2596666) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows Internet Explorer 8 (KB2675157) Security Update for Windows Internet Explorer 8 (KB2699988) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2621440) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2641653) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2647518) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2655992) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2685939) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2691442) Security Update for Windows XP (KB2695962) Security Update for Windows XP (KB2698365) Security Update for Windows XP (KB2707511) Security Update for Windows XP (KB2709162) Security Update for Windows XP (KB2718523) Security Update for Windows XP (KB2719985) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) SigmaTel Audio Spybot - Search & Destroy swMSM Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit Edition Update for Windows XP (KB2345886) Update for Windows XP (KB2541763) Update for Windows XP (KB2616676-v2) Update for Windows XP (KB2641690) Update for Windows XP (KB2718704) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VC80CRTRedist - 8.0.50727.6195 Viewpoint Media Player WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 . ==== Event Viewer Messages From Past Week ======== . 7/24/2012 7:09:51 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the MBAMService service to connect. 7/24/2012 7:09:51 PM, error: Service Control Manager [7000] - The MBAMService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/24/2012 1:23:05 PM, error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s). 7/23/2012 9:54:40 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 4 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/23/2012 9:53:40 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/23/2012 9:52:39 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/23/2012 9:52:15 AM, error: Service Control Manager [7031] - The Google Software Updater service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 900000 milliseconds: Restart the service. 7/23/2012 9:52:15 AM, error: Service Control Manager [7023] - The Network Location Awareness (NLA) service terminated with the following error: The specified procedure could not be found. 7/23/2012 9:09:17 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 7/23/2012 8:43:49 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 7/23/2012 8:42:19 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip 7/23/2012 8:42:19 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 7/23/2012 8:42:19 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 7/23/2012 8:42:19 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 7/23/2012 8:42:19 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 7/23/2012 8:42:19 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 7/23/2012 8:42:19 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 7/23/2012 8:41:22 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 7/23/2012 8:41:07 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 7/23/2012 8:37:09 AM, error: Dhcp [1002] - The IP address lease 192.168.2.4 for the Network Card with network address 00188B6E4011 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 7/23/2012 11:28:33 AM, error: Service Control Manager [7034] - The LMIGuardianSvc service terminated unexpectedly. It has done this 3 time(s). 7/23/2012 11:28:33 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect. 7/23/2012 11:28:33 AM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/23/2012 10:27:08 AM, error: Service Control Manager [7034] - The LMIGuardianSvc service terminated unexpectedly. It has done this 2 time(s). 7/23/2012 10:27:08 AM, error: Service Control Manager [7034] - The IMAPI CD-Burning COM Service service terminated unexpectedly. It has done this 1 time(s). 7/23/2012 1:56:58 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdK8 Fips 7/23/2012 1:38:12 PM, error: Service Control Manager [7034] - The LMIGuardianSvc service terminated unexpectedly. It has done this 4 time(s). 7/23/2012 1:38:12 PM, error: Service Control Manager [7034] - The IMAPI CD-Burning COM Service service terminated unexpectedly. It has done this 2 time(s). 7/22/2012 10:27:14 AM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service. 7/21/2012 11:20:18 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Apple Mobile Device service to connect. 7/21/2012 11:20:18 PM, error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/21/2012 11:19:18 PM, error: Service Control Manager [7034] - The LogMeIn service terminated unexpectedly. It has done this 1 time(s). 7/21/2012 11:19:18 PM, error: Service Control Manager [7034] - The LogMeIn Maintenance Service service terminated unexpectedly. It has done this 1 time(s). 7/21/2012 11:19:18 PM, error: Service Control Manager [7034] - The LMIGuardianSvc service terminated unexpectedly. It has done this 1 time(s). 7/21/2012 11:19:18 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 7/21/2012 11:19:18 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 7/21/2012 11:19:18 PM, error: Service Control Manager [7034] - The Ati HotKey Poller service terminated unexpectedly. It has done this 1 time(s). 7/21/2012 11:19:18 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/20/2012 10:25:51 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Update for Windows XP (KB2633952). . ==== End Of File =========================== aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-26 11:38:19 —————————– 11:38:19.203 OS Version: Windows 5.1.2600 Service Pack 3 11:38:19.203 Number of processors: 2 586 0x6B01 11:38:19.203 ComputerName: DELL1234 UserName: 11:38:20.765 Initialize success 11:38:43.046 AVAST engine download error: 0 11:38:57.765 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\nvgts1Port0Path0Target0Lun0 11:38:57.765 Disk 0 Vendor: WDC_WD64 01.0 Size: 610480MB BusType: 1 11:38:57.796 Disk 0 MBR read successfully 11:38:57.796 Disk 0 MBR scan 11:38:57.796 Disk 0 Windows XP default MBR code 11:38:57.796 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 610469 MB offset 63 11:38:57.812 Disk 0 scanning sectors +1250242560 11:38:57.906 Disk 0 scanning C:\WINDOWS\system32\drivers 11:39:02.968 File: C:\WINDOWS\system32\drivers\mrxsmb.sys **SUSPICIOUS** 11:39:04.375 Disk 0 trace - called modules: 11:39:04.406 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xf6346698]<< 11:39:04.406 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d03ab8] 11:39:04.406 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> [0x86a4c0e8] 11:39:04.406 \Driver\00000577[0x86b7f978] -> IRP_MJ_CREATE -> 0xf6346698 11:39:04.421 Scan finished successfully 11:39:32.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Dorothy Powell\Desktop\MBR.dat" 11:39:32.203 The log file has been saved successfully to "C:\Documents and Settings\Dorothy Powell\Desktop\aswMBR.txt"
As I suspected, you have a very nasty infection on your computer which can sometimes take a lot of work to eliminate so let’s get started.

FIRST

Spybot TeaTimer

Please disable this program and leave it disabled until we are done as it can interfere with some of the tools we use.
  • launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • on the left hand side, click on Tools, then click on the Resident Icon in the list.
  • uncheck the Resident TeaTimer (Protection of overall system settings) active box.
  • click on the System Startup icon in the List
  • uncheck the "TeaTimer" box and click OK at any prompts.
  • if Teatimer gives you a warning that changes were made, click Allow Change when prompted.
  • exit Spybot S&D.
(When we are finished, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup).

======================================================

Please run these in the order requested.

Run TDSSKiller

Please download TDSSKiller.zip
  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan
    • only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
    • then click Continue > Reboot now
  • copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)
======================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • see this Link for programs that need to be disabled and instruction on how to disable them.
  • remember to re-enable them when we're done.
  • double click on ComboFix.exe & follow the prompts.
  • as part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    🖼Click to load external image (Posted Image)


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    🖼Click to load external image (Posted Image)


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please also remember to include the TDSSKiller log

Thanks

Satchfan
I am sorry for the life of me I can not find the TDSSKiller_*** log. Just can't find where it was saved but here is the Combofix log If you tell me how to find this log I will post it. I forgot to write which told me this but it said I had RootKit.ZeroAccess which had inserted into TCP/IP My computer is already running faster. Yall are great.

ComboFix 12-07-27.02 - Dorothy Powell 07/26/2012 14:44:19.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.698 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Dorothy Powell\Application Data\.#
c:\documents and settings\Dorothy Powell\Application Data\.#\MBX@174@384190.###
c:\documents and settings\Dorothy Powell\Application Data\.#\MBX@174@3841C0.###
c:\documents and settings\Dorothy Powell\Application Data\.#\MBX@174@3841F0.###
.
.
((((((((((((((((((((((((( Files Created from 2012-06-26 to 2012-07-26 )))))))))))))))))))))))))))))))
.
.
2012-07-26 18:23 . 2012-07-26 18:23 ——– d—–w- C:\TDSSKiller_Quarantine
2012-07-25 22:43 . 2012-07-25 22:43 388096 —-a-r- c:\documents and settings\Dorothy Powell\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-07-24 20:03 . 2012-07-24 20:04 ——– d—–w- c:\windows\system32\NtmsData
2012-07-24 13:30 . 2012-07-24 13:30 ——– d—–w- c:\documents and settings\Dorothy Powell\Application Data\Malwarebytes
2012-07-24 13:30 . 2012-07-24 13:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-07-24 13:30 . 2012-07-24 13:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-07-24 13:30 . 2012-07-03 17:46 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-22 03:16 . 2012-07-25 00:17 ——– d—–w- c:\documents and settings\All Users\Application Data\036E192935CFC44C15DF076B7B07D287
2012-07-20 03:08 . 2012-07-20 03:08 ——– d—–w- c:\documents and settings\Dorothy Powell\Application Data\iFunbox_UserCache
2012-07-20 03:08 . 2012-07-24 19:57 ——– d—–w- c:\program files\i-Funbox DevTeam
2012-07-13 01:07 . 2012-07-13 01:07 9226440 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-07-08 23:17 . 2012-07-08 23:17 ——– d—–w- c:\documents and settings\Dorothy Powell\Local Settings\Application Data\SanDisk
2012-07-08 23:17 . 2012-07-08 23:17 ——– d—–w- c:\documents and settings\Dorothy Powell\Local Settings\Application Data\Spoon
2012-07-04 18:59 . 2012-07-04 18:59 ——– d—–w- c:\windows\system32\wbem\Repository
2012-07-04 18:58 . 2012-07-04 18:58 ——– d—–w- c:\program files\Horse Racing Simulation LLC
2012-07-04 18:58 . 2012-07-04 18:58 ——– d–h–w- c:\documents and settings\All Users\Application Data\{72020B27-0E75-455A-BCEC-9F6C7675B3DA}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-26 18:24 . 2008-04-14 07:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-07-13 01:07 . 2012-06-20 16:30 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-13 01:07 . 2011-06-16 13:52 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-11 22:39 . 2011-06-16 15:35 83392 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-07-11 22:39 . 2011-06-16 15:35 52128 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2012-07-11 22:39 . 2011-06-16 15:35 30624 —-a-w- c:\windows\system32\LMIport.dll
2012-07-11 22:39 . 2011-06-16 15:35 87456 —-a-w- c:\windows\system32\LMIinit.dll
2012-06-13 13:19 . 2008-04-14 07:00 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-04-14 07:00 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-14 07:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 07:00 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2011-06-16 20:30 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2011-06-16 20:30 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2011-06-16 02:47 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2011-06-16 02:47 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2011-06-16 02:47 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2011-06-16 20:30 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2011-06-16 20:30 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2011-06-16 02:47 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2011-06-16 02:47 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2008-04-14 07:00 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2011-06-16 20:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2011-06-16 02:47 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2011-06-16 02:47 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2011-10-03 02:25 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2011-10-03 02:25 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2011-10-03 02:25 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2008-04-14 07:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-22 01:57 . 2011-06-16 15:35 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll.000.bak
2012-05-22 01:57 . 2011-06-16 15:35 87424 —-a-w- c:\windows\system32\LMIinit.dll.000.bak
2012-05-16 15:08 . 2008-04-14 07:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2008-04-14 07:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2008-04-14 07:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2008-04-14 07:00 385024 —-a-w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2008-04-14 07:00 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2008-04-14 00:01 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2011-06-16 02:46 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-18 12:59 . 2012-02-02 18:26 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-10-22 39408]
"AOL Fast Start"="c:\progra~1\AOLDES~1.6\AOL.EXE" [2011-04-25 42320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
"nwiz"="nwiz.exe" [2006-08-23 1617920]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 282624]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-11 63048]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"HostManager"="c:\program files\Common Files\AOL\1317604369\ee\AOLSoftware.exe" [2010-03-08 41800]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-16 28672]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2012-04-24 296056]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2011-6-16 576000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-07-11 22:39 87456 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [6/8/2011 1:04 PM 374184]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 7:04 PM 12856]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/24/2012 9:30 AM 655944]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/24/2012 9:30 AM 22344]
S0 cerc6;cerc6; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/22/2011 1:08 PM 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6/20/2012 12:30 PM 250056]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/22/2011 1:08 PM 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/4/2012 6:31 AM 113120]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - BITS
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-20 01:07]
.
2012-06-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-22 17:08]
.
2012-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-22 17:08]
.
2012-07-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-602162358-1708537768-1417001333-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-03-30 19:39]
.
2012-07-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-602162358-1708537768-1417001333-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-03-30 19:39]
.
2012-07-26 c:\windows\Tasks\User_Feed_Synchronization-{2277EE30-CBE9-419D-9C4C-AADBC506B017}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
2012-07-26 c:\windows\Tasks\User_Feed_Synchronization-{4545CBED-01B0-4F67-A074-0B795254EA1B}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\Dorothy Powell\Application Data\Mozilla\Firefox\Profiles\i4mjnsgl.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-games-chromesbox-en-us&tb_uuid=20111105222643531&tb_oid=05-11-2011&tb_mrud=05-11-2011
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9416c616-cee5-4527-8203-92236b4af295%7D&mid=cd41374a5a0547d1995fd14acce4e9e6-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=10.0.0.7&lang=en&pr=fr&d=2012-03-01%2019%3A28%3A14&sap=ku&q=
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-46518440.sys
AddRemove-Adobe Atmosphere Player - c:\windows\atmoUn.exe
AddRemove-MP Navigator EX 1.0 - c:\program files\Canon\MP Navigator EX 1.0\Maint.exe
AddRemove-SoftwareUpdUtility - c:\program files\Common Files\Software Update Utility\uninstall.exe
AddRemove-Google Chrome - c:\documents and settings\Dorothy Powell\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\Installer\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-26 14:51
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(644)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
.
Completion time: 2012-07-26 14:53:32
ComboFix-quarantined-files.txt 2012-07-26 18:53
.
Pre-Run: 621,749,047,296 bytes free
Post-Run: 622,138,511,360 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 463F8ED35F72D29EF3B914D37A896D4A
The TDSSKiller report can be found in your root directory, (usually C:\ folder) and will reflect the date that it was run
I'm sorry ran search for it and everything. 14:21:05.0390 3124 TDSS rootkit removing tool [removed] Jul 24 2012 13:16:32 14:21:07.0390 3124 ============================================================ 14:21:07.0390 3124 Current date / time: 2012/07/26 14:21:07.0390 14:21:07.0390 3124 SystemInfo: 14:21:07.0390 3124 14:21:07.0390 3124 OS Version: 5.1.2600 ServicePack: 3.0 14:21:07.0390 3124 Product type: Workstation 14:21:07.0390 3124 ComputerName: DELL1234 14:21:07.0390 3124 UserName: Dorothy Powell 14:21:07.0390 3124 Windows directory: C:\WINDOWS 14:21:07.0390 3124 System windows directory: C:\WINDOWS 14:21:07.0390 3124 Processor architecture: Intel x86 14:21:07.0390 3124 Number of processors: 2 14:21:07.0390 3124 Page size: 0x1000 14:21:07.0390 3124 Boot type: Normal boot 14:21:07.0390 3124 ============================================================ 14:21:09.0125 3124 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058 14:21:09.0156 3124 Drive \Device\Harddisk1\DR2 - Size: 0xEFBFFE00 (3.75 Gb), SectorSize: 0x200, Cylinders: 0x1E9, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 14:21:09.0171 3124 ============================================================ 14:21:09.0171 3124 \Device\Harddisk0\DR0: 14:21:09.0171 3124 MBR partitions: 14:21:09.0171 3124 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4A852FC1 14:21:09.0171 3124 \Device\Harddisk1\DR2: 14:21:09.0171 3124 MBR partitions: 14:21:09.0171 3124 \Device\Harddisk1\DR2\Partition0: MBR, Type 0xB, StartLBA 0x26, BlocksNum 0x779FC2 14:21:09.0171 3124 ============================================================ 14:21:09.0203 3124 C: <-> \Device\Harddisk0\DR0\Partition0 14:21:09.0234 3124 ============================================================ 14:21:09.0234 3124 Initialize success 14:21:09.0234 3124 ============================================================ 14:21:13.0578 2840 ============================================================ 14:21:13.0578 2840 Scan started 14:21:13.0578 2840 Mode: Manual; 14:21:13.0578 2840 ============================================================ 14:21:13.0828 2840 Abiosdsk - ok 14:21:13.0843 2840 abp480n5 - ok 14:21:13.0906 2840 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 14:21:13.0921 2840 ACPI - ok 14:21:13.0953 2840 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 14:21:13.0953 2840 ACPIEC - ok 14:21:14.0031 2840 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 14:21:14.0031 2840 AdobeFlashPlayerUpdateSvc - ok 14:21:14.0046 2840 adpu160m - ok 14:21:14.0109 2840 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 14:21:14.0109 2840 aec - ok 14:21:14.0156 2840 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 14:21:14.0171 2840 AFD - ok 14:21:14.0171 2840 Aha154x - ok 14:21:14.0203 2840 aic78u2 - ok 14:21:14.0234 2840 aic78xx - ok 14:21:14.0281 2840 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll 14:21:14.0281 2840 Alerter - ok 14:21:14.0312 2840 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe 14:21:14.0312 2840 ALG - ok 14:21:14.0312 2840 AliIde - ok 14:21:14.0390 2840 AmdK8 (0a4d13b388c814560bd69c3a496ecfa8) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 14:21:14.0390 2840 AmdK8 - ok 14:21:14.0390 2840 amsint - ok 14:21:14.0546 2840 AOL ACS (85180cf88c5ebad73b452a43a004ca51) C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe 14:21:14.0546 2840 AOL ACS - ok 14:21:14.0609 2840 Apple Mobile Device (d8e18021f91ad79ca8491cb5a5da22d4) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 14:21:14.0625 2840 Apple Mobile Device - ok 14:21:14.0671 2840 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll 14:21:14.0671 2840 AppMgmt - ok 14:21:14.0671 2840 asc - ok 14:21:14.0703 2840 asc3350p - ok 14:21:14.0734 2840 asc3550 - ok 14:21:14.0828 2840 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 14:21:14.0843 2840 aspnet_state - ok 14:21:14.0843 2840 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 14:21:14.0843 2840 AsyncMac - ok 14:21:14.0875 2840 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\drivers\atapi.sys 14:21:14.0875 2840 atapi - ok 14:21:14.0906 2840 Atdisk - ok 14:21:14.0968 2840 Ati HotKey Poller (a2eaeb497ca29ecaeaf0df66ad85c57d) C:\WINDOWS\system32\Ati2evxx.exe 14:21:14.0984 2840 Ati HotKey Poller - ok 14:21:15.0015 2840 ATI Smart (312a17dff710a0f4e6d4dd1d52ead1a8) C:\WINDOWS\system32\ati2sgag.exe 14:21:15.0046 2840 ATI Smart - ok 14:21:15.0171 2840 ati2mtag (492bd2a5f65f218d4ede5764a3bb67e9) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 14:21:15.0203 2840 ati2mtag - ok 14:21:15.0265 2840 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 14:21:15.0265 2840 Atmarpc - ok 14:21:15.0296 2840 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll 14:21:15.0312 2840 AudioSrv - ok 14:21:15.0328 2840 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 14:21:15.0328 2840 audstub - ok 14:21:15.0375 2840 bcm4sbxp (cd4646067cc7dcba1907fa0acf7e3966) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 14:21:15.0375 2840 bcm4sbxp - ok 14:21:15.0406 2840 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 14:21:15.0406 2840 Beep - ok 14:21:15.0484 2840 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe 14:21:15.0500 2840 Bonjour Service - ok 14:21:15.0546 2840 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll 14:21:15.0546 2840 Browser - ok 14:21:15.0578 2840 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 14:21:15.0578 2840 cbidf2k - ok 14:21:15.0578 2840 cd20xrnt - ok 14:21:15.0625 2840 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 14:21:15.0625 2840 Cdaudio - ok 14:21:15.0640 2840 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 14:21:15.0640 2840 Cdfs - ok 14:21:15.0687 2840 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 14:21:15.0687 2840 Cdrom - ok 14:21:15.0687 2840 cerc6 - ok 14:21:15.0718 2840 Changer - ok 14:21:15.0765 2840 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe 14:21:15.0765 2840 CiSvc - ok 14:21:15.0765 2840 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe 14:21:15.0765 2840 ClipSrv - ok 14:21:15.0843 2840 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 14:21:15.0890 2840 clr_optimization_v2.0.50727_32 - ok 14:21:15.0890 2840 CmdIde - ok 14:21:15.0921 2840 COMSysApp - ok 14:21:15.0968 2840 Cpqarray - ok 14:21:16.0000 2840 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll 14:21:16.0000 2840 CryptSvc - ok 14:21:16.0031 2840 dac2w2k - ok 14:21:16.0062 2840 dac960nt - ok 14:21:16.0109 2840 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll 14:21:16.0156 2840 DcomLaunch - ok 14:21:16.0171 2840 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll 14:21:16.0171 2840 Dhcp - ok 14:21:16.0187 2840 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 14:21:16.0187 2840 Disk - ok 14:21:16.0203 2840 dmadmin - ok 14:21:16.0296 2840 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 14:21:16.0312 2840 dmboot - ok 14:21:16.0328 2840 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 14:21:16.0328 2840 dmio - ok 14:21:16.0359 2840 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 14:21:16.0359 2840 dmload - ok 14:21:16.0375 2840 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll 14:21:16.0375 2840 dmserver - ok 14:21:16.0406 2840 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 14:21:16.0406 2840 DMusic - ok 14:21:16.0437 2840 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll 14:21:16.0437 2840 Dnscache - ok 14:21:16.0468 2840 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll 14:21:16.0484 2840 Dot3svc - ok 14:21:16.0500 2840 dot4 (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys 14:21:16.0500 2840 dot4 - ok 14:21:16.0515 2840 Dot4Print (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys 14:21:16.0515 2840 Dot4Print - ok 14:21:16.0546 2840 dot4usb (6ec3af6bb5b30e488a0c559921f012e1) C:\WINDOWS\system32\DRIVERS\dot4usb.sys 14:21:16.0546 2840 dot4usb - ok 14:21:16.0562 2840 dpti2o - ok 14:21:16.0593 2840 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 14:21:16.0593 2840 drmkaud - ok 14:21:16.0625 2840 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll 14:21:16.0625 2840 EapHost - ok 14:21:16.0640 2840 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll 14:21:16.0640 2840 ERSvc - ok 14:21:16.0703 2840 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 14:21:16.0718 2840 Eventlog - ok 14:21:16.0750 2840 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll 14:21:16.0750 2840 EventSystem - ok 14:21:16.0796 2840 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 14:21:16.0796 2840 Fastfat - ok 14:21:16.0828 2840 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 14:21:16.0843 2840 FastUserSwitchingCompatibility - ok 14:21:16.0875 2840 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 14:21:16.0890 2840 Fdc - ok 14:21:16.0906 2840 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 14:21:16.0906 2840 Fips - ok 14:21:16.0921 2840 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 14:21:16.0921 2840 Flpydisk - ok 14:21:16.0953 2840 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 14:21:16.0953 2840 FltMgr - ok 14:21:17.0046 2840 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 14:21:17.0046 2840 FontCache3.0.0.0 - ok 14:21:17.0046 2840 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 14:21:17.0046 2840 Fs_Rec - ok 14:21:17.0093 2840 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 14:21:17.0093 2840 Ftdisk - ok 14:21:17.0125 2840 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 14:21:17.0125 2840 GEARAspiWDM - ok 14:21:17.0140 2840 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 14:21:17.0140 2840 Gpc - ok 14:21:17.0218 2840 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe 14:21:17.0234 2840 gupdate - ok 14:21:17.0234 2840 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe 14:21:17.0234 2840 gupdatem - ok 14:21:17.0296 2840 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 14:21:17.0296 2840 gusvc - ok 14:21:17.0343 2840 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 14:21:17.0343 2840 HDAudBus - ok 14:21:17.0390 2840 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 14:21:17.0390 2840 helpsvc - ok 14:21:17.0406 2840 HidServ (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll 14:21:17.0406 2840 HidServ - ok 14:21:17.0421 2840 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 14:21:17.0421 2840 hidusb - ok 14:21:17.0468 2840 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll 14:21:17.0468 2840 hkmsvc - ok 14:21:17.0484 2840 hpn - ok 14:21:17.0515 2840 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 14:21:17.0515 2840 HSFHWBS2 - ok 14:21:17.0593 2840 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 14:21:17.0625 2840 HSF_DP - ok 14:21:17.0671 2840 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 14:21:17.0671 2840 HTTP - ok 14:21:17.0718 2840 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll 14:21:17.0718 2840 HTTPFilter - ok 14:21:17.0734 2840 i2omgmt - ok 14:21:17.0750 2840 i2omp - ok 14:21:17.0796 2840 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\drivers\i8042prt.sys 14:21:17.0796 2840 i8042prt - ok 14:21:18.0078 2840 idsvc (c01ac32dc5c03076cfb852cb5da5229c) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 14:21:18.0093 2840 idsvc - ok 14:21:18.0140 2840 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 14:21:18.0140 2840 Imapi - ok 14:21:18.0171 2840 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe 14:21:18.0187 2840 ImapiService - ok 14:21:18.0203 2840 ini910u - ok 14:21:18.0250 2840 IntelIde - ok 14:21:18.0281 2840 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 14:21:18.0281 2840 Ip6Fw - ok 14:21:18.0312 2840 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 14:21:18.0312 2840 IpFilterDriver - ok 14:21:18.0328 2840 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 14:21:18.0328 2840 IpInIp - ok 14:21:18.0375 2840 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 14:21:18.0390 2840 IpNat - ok 14:21:18.0500 2840 iPod Service (33642c17c232aa272c68e446a2619899) C:\Program Files\iPod\bin\iPodService.exe 14:21:18.0515 2840 iPod Service - ok 14:21:18.0531 2840 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 14:21:18.0531 2840 IPSec - ok 14:21:18.0546 2840 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 14:21:18.0562 2840 IRENUM - ok 14:21:18.0593 2840 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 14:21:18.0593 2840 isapnp - ok 14:21:18.0671 2840 JavaQuickStarterService (0a5709543986843d37a92290b7838340) C:\Program Files\Java\jre6\bin\jqs.exe 14:21:18.0671 2840 JavaQuickStarterService - ok 14:21:18.0703 2840 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 14:21:18.0703 2840 Kbdclass - ok 14:21:18.0718 2840 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 14:21:18.0718 2840 kbdhid - ok 14:21:18.0765 2840 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 14:21:18.0781 2840 kmixer - ok 14:21:18.0796 2840 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 14:21:18.0812 2840 KSecDD - ok 14:21:18.0843 2840 LanmanServer (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll 14:21:18.0843 2840 LanmanServer - ok 14:21:18.0890 2840 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll 14:21:18.0906 2840 lanmanworkstation - ok 14:21:18.0906 2840 lbrtfdc - ok 14:21:18.0984 2840 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll 14:21:18.0984 2840 LmHosts - ok 14:21:19.0031 2840 LMIGuardianSvc (63daf163d1617dd611bd0ab8e41a43e8) C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe 14:21:19.0046 2840 LMIGuardianSvc - ok 14:21:19.0078 2840 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys 14:21:19.0078 2840 LMIInfo - ok 14:21:19.0078 2840 LMIMaint (175f50f37eeaa1d4d744bcccbb7cf68c) C:\Program Files\LogMeIn\x86\RaMaint.exe 14:21:19.0093 2840 LMIMaint - ok 14:21:19.0125 2840 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys 14:21:19.0125 2840 lmimirr - ok 14:21:19.0140 2840 LMIRfsClientNP - ok 14:21:19.0171 2840 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys 14:21:19.0171 2840 LMIRfsDriver - ok 14:21:19.0218 2840 LogMeIn (432618fa75b61059d2c57d6a7e55147a) C:\Program Files\LogMeIn\x86\LogMeIn.exe 14:21:19.0234 2840 LogMeIn - ok 14:21:19.0265 2840 MBAMProtector (6dfe7f2e8e8a337263aa5c92a215f161) C:\WINDOWS\system32\drivers\mbam.sys 14:21:19.0265 2840 MBAMProtector - ok 14:21:19.0406 2840 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 14:21:19.0421 2840 MBAMService - ok 14:21:19.0468 2840 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\WINDOWS\system32\DRIVERS\mcdbus.sys 14:21:19.0468 2840 mcdbus - ok 14:21:19.0484 2840 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 14:21:19.0484 2840 mdmxsdk - ok 14:21:19.0515 2840 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll 14:21:19.0515 2840 Messenger - ok 14:21:19.0578 2840 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 14:21:19.0578 2840 Microsoft Office Groove Audit Service - ok 14:21:19.0625 2840 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 14:21:19.0625 2840 mnmdd - ok 14:21:19.0656 2840 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe 14:21:19.0656 2840 mnmsrvc - ok 14:21:19.0687 2840 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 14:21:19.0687 2840 Modem - ok 14:21:19.0703 2840 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 14:21:19.0718 2840 MODEMCSA - ok 14:21:19.0750 2840 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 14:21:19.0765 2840 Mouclass - ok 14:21:19.0765 2840 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 14:21:19.0765 2840 mouhid - ok 14:21:19.0812 2840 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 14:21:19.0812 2840 MountMgr - ok 14:21:19.0859 2840 MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 14:21:19.0859 2840 MozillaMaintenance - ok 14:21:19.0875 2840 mraid35x - ok 14:21:19.0921 2840 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 14:21:19.0921 2840 MRxDAV - ok 14:21:19.0968 2840 MRxSmb (5287ca4d2b74a11df5b718ac8982daab) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 14:21:19.0984 2840 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\mrxsmb.sys. Real md5: 5287ca4d2b74a11df5b718ac8982daab, Fake md5: 7d304a5eb4344ebeeab53a2fe3ffb9f0 14:21:20.0000 2840 MRxSmb ( Virus.Win32.ZAccess.c ) - infected 14:21:20.0000 2840 MRxSmb - detected Virus.Win32.ZAccess.c (0) 14:21:20.0031 2840 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe 14:21:20.0031 2840 MSDTC - ok 14:21:20.0046 2840 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 14:21:20.0046 2840 Msfs - ok 14:21:20.0078 2840 MSIServer - ok 14:21:20.0125 2840 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 14:21:20.0125 2840 MSKSSRV - ok 14:21:20.0125 2840 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 14:21:20.0140 2840 MSPCLOCK - ok 14:21:20.0156 2840 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 14:21:20.0156 2840 MSPQM - ok 14:21:20.0203 2840 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 14:21:20.0203 2840 mssmbios - ok 14:21:20.0234 2840 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 14:21:20.0234 2840 Mup - ok 14:21:20.0265 2840 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll 14:21:20.0281 2840 napagent - ok 14:21:20.0296 2840 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 14:21:20.0296 2840 NDIS - ok 14:21:20.0312 2840 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 14:21:20.0312 2840 NdisTapi - ok 14:21:20.0343 2840 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 14:21:20.0343 2840 Ndisuio - ok 14:21:20.0359 2840 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 14:21:20.0359 2840 NdisWan - ok 14:21:20.0406 2840 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 14:21:20.0406 2840 NDProxy - ok 14:21:20.0421 2840 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 14:21:20.0421 2840 NetBIOS - ok 14:21:20.0468 2840 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 14:21:20.0468 2840 NetBT - ok 14:21:20.0500 2840 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 14:21:20.0500 2840 NetDDE - ok 14:21:20.0500 2840 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 14:21:20.0515 2840 NetDDEdsdm - ok 14:21:20.0546 2840 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:21:20.0546 2840 Netlogon - ok 14:21:20.0593 2840 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll 14:21:20.0593 2840 Netman - ok 14:21:20.0703 2840 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 14:21:20.0718 2840 NetTcpPortSharing - ok 14:21:20.0750 2840 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll 14:21:20.0750 2840 Nla - ok 14:21:20.0765 2840 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 14:21:20.0765 2840 Npfs - ok 14:21:20.0812 2840 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 14:21:20.0812 2840 Ntfs - ok 14:21:20.0828 2840 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:21:20.0828 2840 NtLmSsp - ok 14:21:20.0875 2840 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll 14:21:20.0906 2840 NtmsSvc - ok 14:21:20.0921 2840 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 14:21:20.0921 2840 Null - ok 14:21:21.0187 2840 nv (15a6306a0b958bf60f09688d0ee70479) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 14:21:21.0281 2840 nv - ok 14:21:21.0390 2840 nvgts (a0b3f3a5049931657164f0ffcf0b208e) C:\WINDOWS\system32\drivers\nvgts.sys 14:21:21.0390 2840 nvgts - ok 14:21:21.0421 2840 NVSvc (986d6666e076afd2b60acafd5b01a00f) C:\WINDOWS\system32\nvsvc32.exe 14:21:21.0437 2840 NVSvc - ok 14:21:21.0484 2840 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 14:21:21.0484 2840 NwlnkFlt - ok 14:21:21.0484 2840 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 14:21:21.0484 2840 NwlnkFwd - ok 14:21:21.0625 2840 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 14:21:21.0671 2840 odserv - ok 14:21:21.0718 2840 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 14:21:21.0750 2840 ose - ok 14:21:21.0781 2840 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 14:21:21.0781 2840 Parport - ok 14:21:21.0796 2840 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 14:21:21.0796 2840 PartMgr - ok 14:21:21.0828 2840 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 14:21:21.0828 2840 ParVdm - ok 14:21:21.0843 2840 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 14:21:21.0843 2840 PCI - ok 14:21:21.0875 2840 PCIDump - ok 14:21:21.0890 2840 PCIIde - ok 14:21:21.0968 2840 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 14:21:21.0984 2840 Pcmcia - ok 14:21:21.0984 2840 PDCOMP - ok 14:21:22.0000 2840 PDFRAME - ok 14:21:22.0031 2840 PDRELI - ok 14:21:22.0062 2840 PDRFRAME - ok 14:21:22.0093 2840 perc2 - ok 14:21:22.0109 2840 perc2hib - ok 14:21:22.0234 2840 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 14:21:22.0234 2840 PlugPlay - ok 14:21:22.0265 2840 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:21:22.0265 2840 PolicyAgent - ok 14:21:22.0328 2840 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 14:21:22.0328 2840 PptpMiniport - ok 14:21:22.0406 2840 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 14:21:22.0406 2840 Processor - ok 14:21:22.0406 2840 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:21:22.0406 2840 ProtectedStorage - ok 14:21:22.0437 2840 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 14:21:22.0437 2840 PSched - ok 14:21:22.0468 2840 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 14:21:22.0468 2840 Ptilink - ok 14:21:22.0484 2840 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 14:21:22.0484 2840 PxHelp20 - ok 14:21:22.0515 2840 ql1080 - ok 14:21:22.0546 2840 Ql10wnt - ok 14:21:22.0562 2840 ql12160 - ok 14:21:22.0593 2840 ql1240 - ok 14:21:22.0625 2840 ql1280 - ok 14:21:22.0671 2840 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 14:21:22.0671 2840 RasAcd - ok 14:21:22.0703 2840 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll 14:21:22.0703 2840 RasAuto - ok 14:21:22.0734 2840 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 14:21:22.0734 2840 Rasl2tp - ok 14:21:22.0765 2840 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll 14:21:22.0812 2840 RasMan - ok 14:21:22.0812 2840 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 14:21:22.0812 2840 RasPppoe - ok 14:21:22.0828 2840 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 14:21:22.0843 2840 Raspti - ok 14:21:22.0890 2840 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 14:21:22.0906 2840 Rdbss - ok 14:21:22.0937 2840 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 14:21:22.0937 2840 RDPCDD - ok 14:21:22.0984 2840 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 14:21:22.0984 2840 rdpdr - ok 14:21:23.0046 2840 RDPWD (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys 14:21:23.0062 2840 RDPWD - ok 14:21:23.0093 2840 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe 14:21:23.0109 2840 RDSessMgr - ok 14:21:23.0156 2840 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 14:21:23.0156 2840 redbook - ok 14:21:23.0203 2840 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll 14:21:23.0203 2840 RemoteAccess - ok 14:21:23.0250 2840 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll 14:21:23.0250 2840 RemoteRegistry - ok 14:21:23.0281 2840 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe 14:21:23.0281 2840 RpcLocator - ok 14:21:23.0375 2840 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll 14:21:23.0390 2840 RpcSs - ok 14:21:23.0453 2840 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe 14:21:23.0453 2840 RSVP - ok 14:21:23.0500 2840 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:21:23.0500 2840 SamSs - ok 14:21:23.0750 2840 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe 14:21:23.0781 2840 SCardSvr - ok 14:21:24.0015 2840 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll 14:21:24.0031 2840 Schedule - ok 14:21:24.0093 2840 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 14:21:24.0093 2840 Secdrv - ok 14:21:24.0140 2840 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll 14:21:24.0140 2840 seclogon - ok 14:21:24.0187 2840 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll 14:21:24.0187 2840 SENS - ok 14:21:24.0234 2840 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 14:21:24.0234 2840 Serial - ok 14:21:24.0328 2840 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 14:21:24.0328 2840 Sfloppy - ok 14:21:24.0375 2840 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 14:21:24.0375 2840 ShellHWDetection - ok 14:21:24.0390 2840 Simbad - ok 14:21:24.0437 2840 Sparrow - ok 14:21:24.0484 2840 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 14:21:24.0484 2840 splitter - ok 14:21:24.0515 2840 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe 14:21:24.0515 2840 Spooler - ok 14:21:24.0562 2840 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 14:21:24.0562 2840 sr - ok 14:21:24.0578 2840 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll 14:21:24.0609 2840 srservice - ok 14:21:24.0640 2840 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 14:21:24.0640 2840 Srv - ok 14:21:24.0703 2840 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll 14:21:24.0703 2840 SSDPSRV - ok 14:21:24.0796 2840 STHDA (8990440e4b2a7ca5a56a1833b03741fd) C:\WINDOWS\system32\drivers\sthda.sys 14:21:24.0843 2840 STHDA - ok 14:21:24.0890 2840 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll 14:21:24.0906 2840 stisvc - ok 14:21:24.0953 2840 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 14:21:24.0953 2840 swenum - ok 14:21:24.0968 2840 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 14:21:24.0968 2840 swmidi - ok 14:21:25.0000 2840 SwPrv - ok 14:21:25.0031 2840 symc810 - ok 14:21:25.0046 2840 symc8xx - ok 14:21:25.0078 2840 sym_hi - ok 14:21:25.0093 2840 sym_u3 - ok 14:21:25.0140 2840 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 14:21:25.0140 2840 sysaudio - ok 14:21:25.0171 2840 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe 14:21:25.0187 2840 SysmonLog - ok 14:21:25.0218 2840 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll 14:21:25.0218 2840 TapiSrv - ok 14:21:25.0265 2840 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 14:21:25.0281 2840 Tcpip - ok 14:21:25.0328 2840 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 14:21:25.0328 2840 TDPIPE - ok 14:21:25.0328 2840 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 14:21:25.0328 2840 TDTCP - ok 14:21:25.0390 2840 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 14:21:25.0390 2840 TermDD - ok 14:21:25.0437 2840 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll 14:21:25.0437 2840 TermService - ok 14:21:25.0484 2840 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 14:21:25.0484 2840 Themes - ok 14:21:25.0515 2840 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe 14:21:25.0515 2840 TlntSvr - ok 14:21:25.0515 2840 TosIde - ok 14:21:25.0546 2840 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll 14:21:25.0562 2840 TrkWks - ok 14:21:25.0593 2840 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 14:21:25.0593 2840 Udfs - ok 14:21:25.0609 2840 ultra - ok 14:21:25.0703 2840 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 14:21:25.0703 2840 Update - ok 14:21:25.0750 2840 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll 14:21:25.0765 2840 upnphost - ok 14:21:25.0765 2840 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe 14:21:25.0765 2840 UPS - ok 14:21:25.0828 2840 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 14:21:25.0828 2840 USBAAPL - ok 14:21:25.0875 2840 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 14:21:25.0875 2840 usbccgp - ok 14:21:25.0890 2840 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 14:21:25.0890 2840 usbehci - ok 14:21:25.0906 2840 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 14:21:25.0906 2840 usbhub - ok 14:21:25.0953 2840 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 14:21:25.0953 2840 usbohci - ok 14:21:26.0000 2840 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 14:21:26.0000 2840 usbprint - ok 14:21:26.0015 2840 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 14:21:26.0015 2840 usbscan - ok 14:21:26.0062 2840 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 14:21:26.0078 2840 USBSTOR - ok 14:21:26.0093 2840 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 14:21:26.0093 2840 VgaSave - ok 14:21:26.0109 2840 ViaIde - ok 14:21:26.0171 2840 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 14:21:26.0171 2840 VolSnap - ok 14:21:26.0218 2840 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe 14:21:26.0265 2840 VSS - ok 14:21:26.0312 2840 W32Time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll 14:21:26.0328 2840 W32Time - ok 14:21:26.0343 2840 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 14:21:26.0343 2840 Wanarp - ok 14:21:26.0437 2840 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys 14:21:26.0437 2840 wanatw - ok 14:21:26.0453 2840 WDICA - ok 14:21:26.0515 2840 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 14:21:26.0515 2840 wdmaud - ok 14:21:26.0531 2840 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll 14:21:26.0531 2840 WebClient - ok 14:21:26.0593 2840 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 14:21:26.0609 2840 winachsf - ok 14:21:26.0687 2840 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll 14:21:26.0703 2840 winmgmt - ok 14:21:26.0765 2840 WmdmPmSN (051b1bdecd6dee18c771b5d5ec7f044d) C:\WINDOWS\system32\MsPMSNSv.dll 14:21:26.0765 2840 WmdmPmSN - ok 14:21:26.0812 2840 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll 14:21:26.0843 2840 Wmi - ok 14:21:26.0890 2840 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe 14:21:26.0890 2840 WmiApSrv - ok 14:21:27.0015 2840 WMPNetworkSvc (6bab4dc65515a098505f8b3d01fb6fe5) C:\Program Files\Windows Media Player\WMPNetwk.exe 14:21:27.0046 2840 WMPNetworkSvc - ok 14:21:27.0109 2840 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 14:21:27.0125 2840 WudfPf - ok 14:21:27.0156 2840 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 14:21:27.0156 2840 WudfRd - ok 14:21:27.0187 2840 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll 14:21:27.0203 2840 WudfSvc - ok 14:21:27.0250 2840 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll 14:21:27.0250 2840 WZCSVC - ok 14:21:27.0312 2840 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll 14:21:27.0312 2840 xmlprov - ok 14:21:27.0359 2840 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 14:21:27.0796 2840 \Device\Harddisk0\DR0 - ok 14:21:27.0796 2840 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR2 14:21:27.0812 2840 \Device\Harddisk1\DR2 - ok 14:21:27.0828 2840 Boot (0x1200) (1bd8551ab3501392766f9ed70f4f492d) \Device\Harddisk0\DR0\Partition0 14:21:27.0859 2840 \Device\Harddisk0\DR0\Partition0 - ok 14:21:27.0875 2840 Boot (0x1200) (cd41a48ba99e6b1ce1f99b66a8c3709c) \Device\Harddisk1\DR2\Partition0 14:21:27.0875 2840 \Device\Harddisk1\DR2\Partition0 - ok 14:21:27.0875 2840 ============================================================ 14:21:27.0875 2840 Scan finished 14:21:27.0875 2840 ============================================================ 14:21:27.0921 3024 Detected object count: 1 14:21:27.0921 3024 Actual detected object count: 1 14:23:21.0421 3024 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys - copied to quarantine 14:23:21.0531 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\@ - copied to quarantine 14:23:21.0562 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\Desktop.ini - copied to quarantine 14:23:21.0593 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\L\00000004.@ - copied to quarantine 14:23:21.0593 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\L\201d3dde - copied to quarantine 14:23:21.0609 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\L\pkvlgifw - copied to quarantine 14:23:21.0640 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\00000004.@ - copied to quarantine 14:23:21.0656 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\00000008.@ - copied to quarantine 14:23:21.0671 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\000000cb.@ - copied to quarantine 14:23:21.0703 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\80000000.@ - copied to quarantine 14:23:21.0718 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\80000032.@ - copied to quarantine 14:23:22.0500 3024 Backup copy found, using it.. 14:23:22.0515 3024 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys - will be cured on reboot 14:23:23.0656 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\@ - will be deleted on reboot 14:23:23.0656 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\Desktop.ini - will be deleted on reboot 14:23:23.0656 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\00000004.@ - will be deleted on reboot 14:23:23.0656 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\00000008.@ - will be deleted on reboot 14:23:23.0656 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\000000cb.@ - will be deleted on reboot 14:23:23.0656 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\80000000.@ - will be deleted on reboot 14:23:23.0656 3024 C:\WINDOWS\$NtUninstallKB25008$\3443502223\U\80000032.@ - will be deleted on reboot 14:23:23.0656 3024 C:\WINDOWS\$NtUninstallKB25008$\418030166 - will be deleted on reboot 14:23:23.0656 3024 MRxSmb ( Virus.Win32.ZAccess.c ) - User select action: Cure 14:23:29.0093 3900 Deinitialize success
It looks as if TDSSK took dare of the offending file.

Run ComboFix

Delete the version of ComboFix you have here:

c:\documents and settings\Dorothy Powell\My Documents\Downloads\ComboFix.exe

Download a new version which MUST be saved directly to your desktop. Choose save as and then make sure you choose Desktop

Download a new version from one of the following locations:

Link1
Link2
Link3

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • open ComboFix
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
Driver::
cerc6

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

Can you tell me how your computer is behaving now

Satchfan
The computer seems to be running faster than it has in quiet a while. here is the combofix.txt Hope I followed the directions correctly. It still said I had rootkit on my computer.

ComboFix 12-07-27.03 - Dorothy Powell 07/27/2012 13:53:02.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.708 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dorothy Powell\Desktop\CFScript.txt.txt
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_cerc6
.
.
((((((((((((((((((((((((( Files Created from 2012-06-27 to 2012-07-27 )))))))))))))))))))))))))))))))
.
.
2012-07-27 00:07 . 2012-07-27 00:07 9821896 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-07-26 18:23 . 2012-07-26 18:23 ——– d—–w- C:\TDSSKiller_Quarantine
2012-07-25 22:43 . 2012-07-25 22:43 388096 —-a-r- c:\documents and settings\Dorothy Powell\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-07-24 20:03 . 2012-07-24 20:04 ——– d—–w- c:\windows\system32\NtmsData
2012-07-24 13:30 . 2012-07-24 13:30 ——– d—–w- c:\documents and settings\Dorothy Powell\Application Data\Malwarebytes
2012-07-24 13:30 . 2012-07-24 13:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-07-24 13:30 . 2012-07-24 13:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-07-24 13:30 . 2012-07-03 17:46 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-22 03:16 . 2012-07-25 00:17 ——– d—–w- c:\documents and settings\All Users\Application Data\036E192935CFC44C15DF076B7B07D287
2012-07-20 03:08 . 2012-07-20 03:08 ——– d—–w- c:\documents and settings\Dorothy Powell\Application Data\iFunbox_UserCache
2012-07-20 03:08 . 2012-07-24 19:57 ——– d—–w- c:\program files\i-Funbox DevTeam
2012-07-08 23:17 . 2012-07-08 23:17 ——– d—–w- c:\documents and settings\Dorothy Powell\Local Settings\Application Data\SanDisk
2012-07-08 23:17 . 2012-07-08 23:17 ——– d—–w- c:\documents and settings\Dorothy Powell\Local Settings\Application Data\Spoon
2012-07-04 18:59 . 2012-07-04 18:59 ——– d—–w- c:\windows\system32\wbem\Repository
2012-07-04 18:58 . 2012-07-04 18:58 ——– d—–w- c:\program files\Horse Racing Simulation LLC
2012-07-04 18:58 . 2012-07-04 18:58 ——– d–h–w- c:\documents and settings\All Users\Application Data\{72020B27-0E75-455A-BCEC-9F6C7675B3DA}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-27 00:07 . 2012-06-20 16:30 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-27 00:07 . 2011-06-16 13:52 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-26 18:24 . 2008-04-14 07:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-07-11 22:39 . 2011-06-16 15:35 83392 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-07-11 22:39 . 2011-06-16 15:35 52128 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2012-07-11 22:39 . 2011-06-16 15:35 30624 —-a-w- c:\windows\system32\LMIport.dll
2012-07-11 22:39 . 2011-06-16 15:35 87456 —-a-w- c:\windows\system32\LMIinit.dll
2012-06-13 13:19 . 2008-04-14 07:00 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-04-14 07:00 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-14 07:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 07:00 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2011-06-16 20:30 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2011-06-16 20:30 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2011-06-16 02:47 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2011-06-16 02:47 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2011-06-16 02:47 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2011-06-16 20:30 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2011-06-16 20:30 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2011-06-16 02:47 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2011-06-16 02:47 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2008-04-14 07:00 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2011-06-16 20:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2011-06-16 02:47 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2011-06-16 02:47 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2011-10-03 02:25 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2011-10-03 02:25 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2011-10-03 02:25 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2008-04-14 07:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-22 01:57 . 2011-06-16 15:35 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll.000.bak
2012-05-22 01:57 . 2011-06-16 15:35 87424 —-a-w- c:\windows\system32\LMIinit.dll.000.bak
2012-05-16 15:08 . 2008-04-14 07:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2008-04-14 07:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2008-04-14 07:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2008-04-14 07:00 385024 —-a-w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2008-04-14 07:00 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2008-04-14 00:01 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2011-06-16 02:46 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-18 12:59 . 2012-02-02 18:26 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-26_18.51.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-27 18:00 . 2012-07-27 18:00 16384 c:\windows\Temp\Perflib_Perfdata_740.dat
+ 2012-07-27 00:07 . 2012-07-27 00:07 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_268_Plugin.exe
+ 2012-07-26 23:07 . 2012-07-26 23:07 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_268_ActiveX.exe
+ 2012-07-26 23:07 . 2012-07-26 23:07 466632 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_268_ActiveX.dll
+ 2012-06-20 16:30 . 2012-07-27 00:07 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
- 2012-06-20 16:30 . 2012-07-13 01:07 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-07-27 00:07 . 2012-07-27 00:07 9465032 c:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-10-22 39408]
"AOL Fast Start"="c:\program files\AOL Desktop 9.6\AOL.EXE" [2011-04-25 42320]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
"nwiz"="nwiz.exe" [2006-08-23 1617920]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 282624]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-11 63048]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"HostManager"="c:\program files\Common Files\AOL\1317604369\ee\AOLSoftware.exe" [2010-03-08 41800]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-16 28672]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2012-04-24 296056]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2011-6-16 576000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-07-11 22:39 87456 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [6/8/2011 1:04 PM 374184]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 7:04 PM 12856]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/24/2012 9:30 AM 655944]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/24/2012 9:30 AM 22344]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/22/2011 1:08 PM 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6/20/2012 12:30 PM 250056]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/22/2011 1:08 PM 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/4/2012 6:31 AM 113120]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-20 00:07]
.
2012-06-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-22 17:08]
.
2012-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-22 17:08]
.
2012-07-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-602162358-1708537768-1417001333-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-03-30 19:39]
.
2012-07-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-602162358-1708537768-1417001333-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-03-30 19:39]
.
2012-07-27 c:\windows\Tasks\User_Feed_Synchronization-{2277EE30-CBE9-419D-9C4C-AADBC506B017}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
2012-07-27 c:\windows\Tasks\User_Feed_Synchronization-{4545CBED-01B0-4F67-A074-0B795254EA1B}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\Dorothy Powell\Application Data\Mozilla\Firefox\Profiles\i4mjnsgl.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-games-chromesbox-en-us&tb_uuid=20111105222643531&tb_oid=05-11-2011&tb_mrud=05-11-2011
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9416c616-cee5-4527-8203-92236b4af295%7D&mid=cd41374a5a0547d1995fd14acce4e9e6-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=10.0.0.7&lang=en&pr=fr&d=2012-03-01%2019%3A28%3A14&sap=ku&q=
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-27 14:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(648)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
.
- - - - - - - > 'explorer.exe'(2128)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\program files\AOL Desktop 9.6\waol.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\AOL Desktop 9.6\shellmon.exe
.
**************************************************************************
.
Completion time: 2012-07-27 14:05:12 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-27 18:05
ComboFix2.txt 2012-07-27 17:37
ComboFix3.txt 2012-07-26 18:53
.
Pre-Run: 621,989,462,016 bytes free
Post-Run: 621,877,633,024 bytes free
.
- - End Of File - - 080A15AEE1B1D04E3141F6A12F4F9EA0
When it was running the scan it had a popup that stated that It had Rootkit and I had to click ok then it did something else then it said it was gonna restart.
There is no sign of a rootkit in your log.

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
Logs to include with the next post:

checkup.txt
Mbam.txt


Can you tell me if there are any outstanding problems.

Satchfan
The computer seems to be running fine. Faster than it was and will navigate websites without having to reload.

Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org

Database version: v2012.07.27.09

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Dorothy Powell :: DELL1234 [administrator]

Protection: Disabled

7/28/2012 1:04:35 PM
mbam-log-2012-07-28 (13-04-35).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 202795
Time elapsed: 4 minute(s), 16 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


Results of screen317's Security Check version 0.99.43
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.62.0.1300
HijackThis 1.99.1
Java™ 6 Update 31
Java version out of Date!
Adobe Flash Player 11.3.300.268
Mozilla Firefox (14.0.1)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 18% Defragment your hard drive soon!
````````````````````End of Log``````````````````````
Good work, your computer appears to be clean.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

You can delete the DDS, TDSSKiller, Security Check and aswMBR logs and programs from your desktop.

Uninstall Combofix

Follow these steps to uninstall Combofix
  • click START then RUN
  • now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
  • please follow the prompts to uninstall Combofix.
  • once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
===================================================

Antivirus

You have no active antivirus on your computer. If you use the Internet without an antivirus your computer will certainly become infected again. It is also imperative that you update your Antivirus software at least once a week, (even more if you wish). If you do not update it, it will not be able to catch any of the new variants of malware that come out on a daily basis.

Do NOT install more than one or they will fight against each other and render both ineffective.

Here are some of the better AV products.

Download and install one of these free antivirus programs: • AVG 2012 Free
• Free Avast Home Edition
• Avira AntiVir® Personal Edition Classic
• Microsoft Security Essentials
===================================================

Firewall

You're using the Windows Firewall which is not adequate protection. The main reason you should use a third-party firewall over the Windows XP Firewall is because Windows Firewall only stops incoming signals from accessing your computer. However, it will not stop Outgoing signals (possibly ones that could intrude your privacy) from sending information to the Internet or to other networks. That means if malware happens to compromise your PC again, it will be able to SEND OUT out your credit card data and any other personal information.

I suggest you install a more robust third party firewall that filters both incoming and outgoing traffic.

Download and install one of the following freeware firewalls from below:

Sygate Personal Firewall Free Edition:
Zone Alarm Free:
Comodo Personal Firewall:

NOTE only install one firewall. Having more than one could cause many programs to stop working altogether. Also, the firewalls may get in each others' way and cause some security holes that would not be there with just one firewall.

When you have done that:

Disable Windows firewall:
  • Click on Start, Settings and then Control Panel
  • Click on the Security Center icon.
  • Click on the Windows Firewall icon
  • Click Off (not recommended) and then click OK.
You should take the time to read Understanding and Using Firewalls

===================================================

Windows updates

I notice that Windows updates are waiting to be installed. Click here for information on how to get the latest Windows updates:

===================================================

Update installed programs

You have an old version of Java on your computer which is vulnerable to infections.
  • click on Start, Settings, Control Panel.
  • double-click on Add or remove programs.
  • select any versions of Java then click Uninstall.
Install the latest version:

Java

===================================================

Recommended programs

Update and run Malwarebytes. This really is an excellent program that you should update and run on a regular basis, probably weekly.

=========================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Safe computing

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI