This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer is painfully slow [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:55:41 PM, on 25/08/2012
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\sttray.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Trudy\Desktop\What the Tech\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Coupons.com Toolbar - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Coupons.com - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: Coupons.com Toolbar - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [AgentMonitor] C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 9750 bytes
Hi,

Please do the following:



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.6000.16982 Run by [removed] at 13:22:24 on 2012-08-26 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.2038.1169 [GMT -4:00] . . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Windows\System32\WLTRAY.EXE C:\Windows\sttray.exe C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\DellSupport\DSAgnt.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\IEUser.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe C:\Windows\system32\conime.exe C:\Windows\system32\wuauclt.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.ca/ uURLSearchHooks: Coupons.com Toolbar: {37153479-1976-43c3-a1ee-557513977b64} - c:\program files\coupons.com\prxtbCou0.dll mURLSearchHooks: Coupons.com Toolbar: {37153479-1976-43c3-a1ee-557513977b64} - c:\program files\coupons.com\prxtbCou0.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: Coupons.com Toolbar: {37153479-1976-43c3-a1ee-557513977b64} - c:\program files\coupons.com\prxtbCou0.dll BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll TB: Coupons.com Toolbar: {37153479-1976-43c3-a1ee-557513977b64} - c:\program files\coupons.com\prxtbCou0.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0\bin\jusched.exe" mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [SigmatelSysTrayApp] sttray.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe" mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe" mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe" mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [AgentMonitor] c:\program files\vtech\downloadmanager\system\AgentMonitor.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{53a01cc6-14b0-4512-a2e7-10d39bf83dc4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{2625CA1A-1F3E-4DF1-AA8E-020B34BD9116} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{77CFCE99-12F4-4BD7-9CBC-1D09CFB3EFAE} : DhcpNameServer = [removed] 10.101.101.254 [removed] [removed] 10.101.101.100 Notify: igfxcui - igfxdev.dll Notify: klogon - c:\windows\system32\klogon.dll AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll c:\progra~1\kasper~1\kasper~1\kloehk.dll . ============= SERVICES / DRIVERS =============== . R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2009-9-14 21520] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952] R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-10-20 340520] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-17 366152] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-7-30 22216] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-23 136176] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-23 136176] S3 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20061025.029\IDSvix86.sys [2007-2-5 202872] . =============== Created Last 30 ================ . 2012-08-25 22:05:16 7023536 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{2ccf61d2-174e-4b0b-a47e-70be88332faa}\mpengine.dll 2012-08-12 16:30:08 155648 —-a-w- c:\windows\system32\igfxres.dll . ==================== Find3M ==================== . 2012-06-07 00:59:42 1070152 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2012-05-31 16:25:14 237072 ——w- c:\windows\system32\MpSigStub.exe . ============= FINISH: 13:23:15.84 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 05/02/2007 5:56:17 AM System Uptime: 26/08/2012 9:44:18 AM (4 hours ago) . Motherboard: Dell Inc. | | 0FF049 Processor: Intel® Core™2 CPU T5200 @ 1.60GHz | Microprocessor | 1600/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 100 GiB total, 55.435 GiB free. D: is FIXED (NTFS) - 10 GiB total, 5.487 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP300: 12/08/2012 8:24:22 AM - Windows Update RP301: 15/08/2012 9:40:51 AM - Scheduled Checkpoint RP302: 16/08/2012 4:36:56 PM - Windows Update RP303: 17/08/2012 3:00:34 AM - Windows Update RP304: 18/08/2012 6:20:30 PM - Windows Update RP305: 19/08/2012 6:17:26 PM - Scheduled Checkpoint RP306: 20/08/2012 7:07:47 AM - Scheduled Checkpoint RP307: 25/08/2012 6:01:44 PM - Windows Update RP308: 26/08/2012 1:16:28 PM - Scheduled Checkpoint . ==== Installed Programs ====================== . . Update for Microsoft Office 2007 (KB2508958) Adobe Flash Player 11 ActiveX Adobe Reader X (10.1.1) Amazon Kindle Canon Easy-WebPrint EX Canon IJ Network Scan Utility Canon IJ Network Tool Canon Inkjet Printer/Scanner/Fax Extended Survey Program Canon MP Navigator EX 3.1 Canon MX870 series MP Drivers Canon Speed Dial Utility Canon Utilities Easy-PhotoPrint EX Canon Utilities My Printer Canon Utilities Solution Menu Conexant HDA D110 MDC V.92 Modem Coupon Printer for Windows Coupons.com Toolbar Dell Wireless WLAN Card DellSupport Digital Line Detect DivX Setup ESET Online Scanner v3 Google Toolbar for Internet Explorer Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Java™ SE Runtime Environment 6 Kaspersky Internet Security 2010 Learning Lodge Navigator Malwarebytes' Anti-Malware version 1.51.2.1300 MediaDirect Microsoft .NET Framework 3.5 SP1 Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Works Modem Diagnostic Tool MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NetWaiting Norton Internet Security QuickSet Roxio Creator Audio Roxio Creator BDAV Plugin Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Drag-to-Disc Roxio Express Labeler Roxio MyDVD DE Roxio Update Manager Security Update for CAPICOM (KB931906) Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596856) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition SigmaTel Audio Sonic Activation Module Synaptics Pointing Device Driver Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687400) 32-Bit Edition User's Guides VC80CRTRedist - 8.0.50727.4053 VTech Download Agent Library . ==== Event Viewer Messages From Past Week ======== . 26/08/2012 8:12:53 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.167 for the Network Card with network address 001A923E5159 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 26/08/2012 1:18:52 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.195 for the Network Card with network address 001A923E5159 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 22/08/2012 10:40:55 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: kl1 KLIF spldr Wanarpv6 22/08/2012 10:40:55 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 22/08/2012 10:40:33 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 22/08/2012 10:40:26 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 22/08/2012 10:40:21 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 22/08/2012 10:40:18 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 22/08/2012 10:40:06 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 20/08/2012 6:58:13 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.166 for the Network Card with network address 001A923E5159 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 20/08/2012 6:57:39 AM, Error: Microsoft-Windows-WPD-MTPClassDriver [15300] - MTP WPD Driver has failed to start. Error 0x80070002. 19/08/2012 6:17:37 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.164 for the Network Card with network address 001A923E5159 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 19/08/2012 4:00:50 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.149 for the Network Card with network address 001A923E5159 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File =========================== aswMBR version 0.9.8.977 Copyright© 2011 AVAST Software Run date: 2011-07-28 17:38:23 —————————– 17:38:23.888 OS Version: Windows 6.0.6000 17:38:23.888 Number of processors: 2 586 0xF06 17:38:23.888 ComputerName: TRUDY-PC UserName: Trudy 17:38:24.980 Initialize success 17:38:43.847 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 17:38:43.847 Disk 0 Vendor: SAMSUNG_HM120JI YF100-15 Size: 114473MB BusType: 3 17:38:43.894 Disk 0 MBR read successfully 17:38:43.894 Disk 0 MBR scan 17:38:43.910 Disk 0 Windows VISTA default MBR code 17:38:43.925 Disk 0 scanning sectors +234438656 17:38:44.050 Disk 0 scanning C:\Windows\system32\drivers 17:38:54.252 Service scanning 17:38:55.329 Service ACPI C:\Windows\system32\drivers\acpi.sys **LOCKED** 32 17:38:55.344 Service adp94xx C:\Windows\system32\drivers\adp94xx.sys **LOCKED** 32 17:38:55.360 Service adpahci C:\Windows\system32\drivers\adpahci.sys **LOCKED** 32 17:38:55.391 Service adpu160m C:\Windows\system32\drivers\adpu160m.sys **LOCKED** 32 17:38:55.391 Service adpu320 C:\Windows\system32\drivers\adpu320.sys **LOCKED** 32 17:38:55.407 Service AFD C:\Windows\system32\drivers\afd.sys **LOCKED** 32 17:38:55.937 Service agp440 C:\Windows\system32\drivers\agp440.sys **LOCKED** 32 17:38:55.953 Service aic78xx C:\Windows\system32\drivers\djsvs.sys **LOCKED** 32 17:38:55.968 Service aliide C:\Windows\system32\drivers\aliide.sys **LOCKED** 32 17:38:55.984 Service amdagp C:\Windows\system32\drivers\amdagp.sys **LOCKED** 32 17:38:56.000 Service amdide C:\Windows\system32\drivers\amdide.sys **LOCKED** 32 17:38:56.015 Service AmdK7 C:\Windows\system32\drivers\amdk7.sys **LOCKED** 32 17:38:56.031 Service AmdK8 C:\Windows\system32\drivers\amdk8.sys **LOCKED** 32 17:38:56.062 Service arc C:\Windows\system32\drivers\arc.sys **LOCKED** 32 17:38:56.078 Service arcsas C:\Windows\system32\drivers\arcsas.sys **LOCKED** 32 17:38:56.093 Service AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys **LOCKED** 32 17:38:56.109 Service atapi C:\Windows\system32\drivers\atapi.sys **LOCKED** 32 17:38:56.124 Service BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys **LOCKED** 32 17:38:56.140 Service bcm4sbxp C:\Windows\system32\DRIVERS\bcm4sbxp.sys **LOCKED** 32 17:38:56.140 Service Beep C:\Windows\System32\Drivers\Beep.sys **LOCKED** 32 17:38:56.156 Service BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys **LOCKED** 32 17:38:56.171 Service BrFiltUp C:\Windows\system32\drivers\brfiltup.sys **LOCKED** 32 17:38:56.187 Service Brserid C:\Windows\system32\drivers\brserid.sys **LOCKED** 32 17:38:56.187 Service BrSerWdm C:\Windows\system32\drivers\brserwdm.sys **LOCKED** 32 17:38:56.202 Service BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys **LOCKED** 32 17:38:56.218 Service BrUsbSer C:\Windows\system32\drivers\brusbser.sys **LOCKED** 32 17:38:56.218 Service BTHMODEM C:\Windows\system32\drivers\bthmodem.sys **LOCKED** 32 17:38:56.234 Service cdrom C:\Windows\system32\DRIVERS\cdrom.sys **LOCKED** 32 17:38:56.249 Service circlass C:\Windows\system32\drivers\circlass.sys **LOCKED** 32 17:38:56.265 Service CLFS C:\Windows\System32\CLFS.sys **LOCKED** 32 17:38:56.280 Service CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys **LOCKED** 32 17:38:56.280 Service cmdide C:\Windows\system32\drivers\cmdide.sys **LOCKED** 32 17:38:56.296 Service Compbatt C:\Windows\system32\DRIVERS\compbatt.sys **LOCKED** 32 17:38:56.312 Service crcdisk C:\Windows\system32\drivers\crcdisk.sys **LOCKED** 32 17:38:56.312 Service Crusoe C:\Windows\system32\drivers\crusoe.sys **LOCKED** 32 17:38:56.343 Service disk C:\Windows\system32\drivers\disk.sys **LOCKED** 32 17:38:56.358 Service drmkaud C:\Windows\system32\drivers\drmkaud.sys **LOCKED** 32 17:38:56.374 Service DRVMCDB C:\Windows\System32\Drivers\DRVMCDB.SYS **LOCKED** 32 17:38:56.390 Service DSproct C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys **LOCKED** 32 17:38:56.405 Service dsunidrv C:\Program Files\DellSupport\Drivers\dsunidrv.sys **LOCKED** 32 17:38:56.436 Service DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys **LOCKED** 32 17:38:56.436 Service e1express C:\Windows\system32\DRIVERS\e1e6032.sys **LOCKED** 32 17:38:56.452 Service E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys **LOCKED** 32 17:38:56.577 Service Ecache C:\Windows\System32\drivers\ecache.sys **LOCKED** 32 17:38:56.608 Service elxstor C:\Windows\system32\drivers\elxstor.sys **LOCKED** 32 17:38:56.686 Service fdc C:\Windows\system32\DRIVERS\fdc.sys **LOCKED** 32 17:38:56.717 Service flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys **LOCKED** 32 17:38:56.733 Service gagp30kx C:\Windows\system32\drivers\gagp30kx.sys **LOCKED** 32 17:38:56.764 Service HdAudAddService C:\Windows\system32\drivers\HdAudio.sys **LOCKED** 32 17:38:56.780 Service HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys **LOCKED** 32 17:38:56.795 Service HidBth C:\Windows\system32\drivers\hidbth.sys **LOCKED** 32 17:38:56.826 Service HidIr C:\Windows\system32\drivers\hidir.sys **LOCKED** 32 17:38:56.842 Service HidUsb C:\Windows\system32\DRIVERS\hidusb.sys **LOCKED** 32 17:38:56.858 Service HpCISSs C:\Windows\system32\drivers\hpcisss.sys **LOCKED** 32 17:38:56.858 Service HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys **LOCKED** 32 17:38:56.873 Service HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys **LOCKED** 32 17:38:56.873 Service HTTP C:\Windows\system32\drivers\HTTP.sys **LOCKED** 32 17:38:56.889 Service i2omp C:\Windows\system32\drivers\i2omp.sys **LOCKED** 32 17:38:56.904 Service i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys **LOCKED** 32 17:38:56.920 Service iaStorV C:\Windows\system32\drivers\iastorv.sys **LOCKED** 32 17:38:56.920 Service IDSvix86 C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20061025.029\IDSvix86.sys **LOCKED** 32 17:38:56.936 Service igfx C:\Windows\system32\DRIVERS\igdkmd32.sys **LOCKED** 32 17:38:56.951 Service iirsp C:\Windows\system32\drivers\iirsp.sys **LOCKED** 32 17:38:56.967 Service intelide C:\Windows\system32\drivers\intelide.sys **LOCKED** 32 17:38:56.982 Service intelppm C:\Windows\system32\DRIVERS\intelppm.sys **LOCKED** 32 17:38:56.982 Service IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys **LOCKED** 32 17:38:56.998 Service IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys **LOCKED** 32 17:38:57.014 Service IPNAT C:\Windows\system32\DRIVERS\ipnat.sys **LOCKED** 32 17:38:57.014 Service IRENUM C:\Windows\system32\drivers\irenum.sys **LOCKED** 32 17:38:57.029 Service isapnp C:\Windows\system32\drivers\isapnp.sys **LOCKED** 32 17:38:57.045 Service iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys **LOCKED** 32 17:38:57.045 Service iteatapi C:\Windows\system32\drivers\iteatapi.sys **LOCKED** 32 17:38:57.060 Service iteraid C:\Windows\system32\drivers\iteraid.sys **LOCKED** 32 17:38:57.076 Service kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys **LOCKED** 32 17:38:57.076 Service kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys **LOCKED** 32 17:38:57.092 Service kl1 C:\Windows\system32\DRIVERS\kl1.sys **LOCKED** 32 17:38:57.107 Service klbg C:\Windows\system32\drivers\klbg.sys **LOCKED** 32 17:38:57.138 Service KLIM6 C:\Windows\system32\DRIVERS\klim6.sys **LOCKED** 32 17:38:57.138 Service klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys **LOCKED** 32 17:38:57.154 Service KSecDD C:\Windows\System32\Drivers\ksecdd.sys **LOCKED** 32 17:38:57.170 Service lltdio C:\Windows\system32\DRIVERS\lltdio.sys **LOCKED** 32 17:38:57.185 Service LSI_FC C:\Windows\system32\drivers\lsi_fc.sys **LOCKED** 32 17:38:57.216 Service LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys **LOCKED** 32 17:38:57.216 Service LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys **LOCKED** 32 17:38:57.232 Service mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys **LOCKED** 32 17:38:57.248 Service megasas C:\Windows\system32\drivers\megasas.sys **LOCKED** 32 17:38:57.263 Service Modem C:\Windows\system32\drivers\modem.sys **LOCKED** 32 17:38:57.279 Service monitor C:\Windows\system32\DRIVERS\monitor.sys **LOCKED** 32 17:38:57.279 Service mouclass C:\Windows\system32\DRIVERS\mouclass.sys **LOCKED** 32 17:38:57.294 Service mouhid C:\Windows\system32\DRIVERS\mouhid.sys **LOCKED** 32 17:38:57.310 Service MountMgr C:\Windows\System32\drivers\mountmgr.sys **LOCKED** 32 17:38:57.310 Service mpio C:\Windows\system32\drivers\mpio.sys **LOCKED** 32 17:38:57.326 Service mpsdrv C:\Windows\System32\drivers\mpsdrv.sys **LOCKED** 32 17:38:57.341 Service Mraid35x C:\Windows\system32\drivers\mraid35x.sys **LOCKED** 32 17:38:57.357 Service msahci C:\Windows\system32\drivers\msahci.sys **LOCKED** 32 17:38:57.372 Service msdsm C:\Windows\system32\drivers\msdsm.sys **LOCKED** 32 17:38:57.388 Service msisadrv C:\Windows\system32\drivers\msisadrv.sys **LOCKED** 32 17:38:57.404 Service MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys **LOCKED** 32 17:38:57.404 Service MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys **LOCKED** 32 17:38:57.419 Service MSPQM C:\Windows\system32\drivers\MSPQM.sys **LOCKED** 32 17:38:57.435 Service MsRPC C:\Windows\System32\Drivers\MsRPC.sys **LOCKED** 32 17:38:57.435 Service mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys **LOCKED** 32 17:38:57.450 Service MSTEE C:\Windows\system32\drivers\MSTEE.sys **LOCKED** 32 17:38:57.466 Service NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys **LOCKED** 32 17:38:57.482 Service NDIS C:\Windows\system32\drivers\ndis.sys **LOCKED** 32 17:38:57.482 Service NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys **LOCKED** 32 17:38:57.497 Service Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys **LOCKED** 32 17:38:57.497 Service NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys **LOCKED** 32 17:38:57.513 Service NDProxy C:\Windows\System32\Drivers\NDProxy.sys **LOCKED** 32 17:38:57.528 Service netbt C:\Windows\System32\DRIVERS\netbt.sys **LOCKED** 32 17:38:57.544 Service nfrd960 C:\Windows\system32\drivers\nfrd960.sys **LOCKED** 32 17:38:57.560 Service nsiproxy C:\Windows\system32\drivers\nsiproxy.sys **LOCKED** 32 17:38:57.575 Service ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys **LOCKED** 32 17:38:57.591 Service NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys **LOCKED** 32 17:38:57.591 Service Null C:\Windows\System32\Drivers\Null.sys **LOCKED** 32 17:38:57.606 Service nvraid C:\Windows\system32\drivers\nvraid.sys **LOCKED** 32 17:38:57.622 Service nvstor C:\Windows\system32\drivers\nvstor.sys **LOCKED** 32 17:38:57.622 Service nv_agp C:\Windows\system32\drivers\nv_agp.sys **LOCKED** 32 17:38:57.638 Service ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys **LOCKED** 32 17:38:57.653 Service Parport C:\Windows\system32\drivers\parport.sys **LOCKED** 32 17:38:57.669 Service partmgr C:\Windows\System32\drivers\partmgr.sys **LOCKED** 32 17:38:57.684 Service Parvdm C:\Windows\system32\drivers\parvdm.sys **LOCKED** 32 17:38:57.700 Service pci C:\Windows\system32\drivers\pci.sys **LOCKED** 32 17:38:57.700 Service pciide C:\Windows\system32\DRIVERS\pciide.sys **LOCKED** 32 17:38:57.716 Service pcmcia C:\Windows\system32\drivers\pcmcia.sys **LOCKED** 32 17:38:57.731 Service PEAUTH C:\Windows\system32\drivers\peauth.sys **LOCKED** 32 17:38:57.762 Service PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys **LOCKED** 32 17:38:57.778 Service Processor C:\Windows\system32\drivers\processr.sys **LOCKED** 32 17:38:57.794 Service PSched C:\Windows\system32\DRIVERS\pacer.sys **LOCKED** 32 17:38:57.794 Service PxHelp20 C:\Windows\System32\Drivers\PxHelp20.sys **LOCKED** 32 17:38:57.809 Service ql2300 C:\Windows\system32\drivers\ql2300.sys **LOCKED** 32 17:38:57.809 Service ql40xx C:\Windows\system32\drivers\ql40xx.sys **LOCKED** 32 17:38:57.825 Service QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys **LOCKED** 32 17:38:57.840 Service R300 C:\Windows\system32\DRIVERS\atikmdag.sys **LOCKED** 32 17:38:57.856 Service RasAcd C:\Windows\System32\DRIVERS\rasacd.sys **LOCKED** 32 17:38:57.856 Service Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys **LOCKED** 32 17:38:57.872 Service RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys **LOCKED** 32 17:38:57.887 Service RDPCDD C:\Windows\System32\DRIVERS\RDPCDD.sys **LOCKED** 32 17:38:57.887 Service rdpdr C:\Windows\system32\drivers\rdpdr.sys **LOCKED** 32 17:38:57.903 Service RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys **LOCKED** 32 17:38:57.918 Service RDPWD C:\Windows\System32\Drivers\RDPWD.sys **LOCKED** 32 17:38:57.965 Service rimmptsk C:\Windows\system32\DRIVERS\rimmptsk.sys **LOCKED** 32 17:38:57.981 Service rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys **LOCKED** 32 17:38:57.996 Service rismxdp C:\Windows\system32\DRIVERS\rixdptsk.sys **LOCKED** 32 17:38:58.012 Service rspndr C:\Windows\system32\DRIVERS\rspndr.sys **LOCKED** 32 17:38:58.028 Service sbp2port C:\Windows\system32\drivers\sbp2port.sys **LOCKED** 32 17:38:58.043 Service sdbus C:\Windows\system32\DRIVERS\sdbus.sys **LOCKED** 32 17:38:58.074 Service secdrv C:\Windows\System32\Drivers\secdrv.sys **LOCKED** 32 17:38:58.090 Service Serenum C:\Windows\system32\drivers\serenum.sys **LOCKED** 32 17:38:58.106 Service Serial C:\Windows\system32\drivers\serial.sys **LOCKED** 32 17:38:58.106 Service sermouse C:\Windows\system32\drivers\sermouse.sys **LOCKED** 32 17:38:58.121 Service sffdisk C:\Windows\system32\drivers\sffdisk.sys **LOCKED** 32 17:38:58.137 Service sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys **LOCKED** 32 17:38:58.152 Service sffp_sd C:\Windows\system32\drivers\sffp_sd.sys **LOCKED** 32 17:38:58.152 Service sfloppy C:\Windows\system32\drivers\sfloppy.sys **LOCKED** 32 17:38:58.168 Service sisagp C:\Windows\system32\drivers\sisagp.sys **LOCKED** 32 17:38:58.184 Service SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys **LOCKED** 32 17:38:58.199 Service SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys **LOCKED** 32 17:38:58.215 Service Smb C:\Windows\system32\DRIVERS\smb.sys **LOCKED** 32 17:38:58.230 Service spldr C:\Windows\System32\Drivers\spldr.sys **LOCKED** 32 17:38:58.246 Service STHDA C:\Windows\system32\drivers\stwrt.sys **LOCKED** 32 17:38:58.262 Service swenum C:\Windows\system32\DRIVERS\swenum.sys **LOCKED** 32 17:38:58.277 Service Symc8xx C:\Windows\system32\drivers\symc8xx.sys **LOCKED** 32 17:38:58.293 Service SymEvent C:\Windows\system32\Drivers\SYMEVENT.SYS **LOCKED** 32 17:38:58.308 Service Sym_hi C:\Windows\system32\drivers\sym_hi.sys **LOCKED** 32 17:38:58.324 Service Sym_u3 C:\Windows\system32\drivers\sym_u3.sys **LOCKED** 32 17:38:58.340 Service SynTP C:\Windows\system32\DRIVERS\SynTP.sys **LOCKED** 32 17:38:58.355 Service Tcpip C:\Windows\System32\drivers\tcpip.sys **LOCKED** 32 17:38:58.371 Service Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys **LOCKED** 32 17:38:58.371 Service tcpipreg C:\Windows\System32\drivers\tcpipreg.sys **LOCKED** 32 17:38:58.386 Service TDPIPE C:\Windows\system32\drivers\tdpipe.sys **LOCKED** 32 17:38:58.402 Service TDTCP C:\Windows\system32\drivers\tdtcp.sys **LOCKED** 32 17:38:58.402 Service tdx C:\Windows\system32\DRIVERS\tdx.sys **LOCKED** 32 17:38:58.418 Service TermDD C:\Windows\system32\DRIVERS\termdd.sys **LOCKED** 32 17:38:58.433 Service tssecsrv C:\Windows\System32\DRIVERS\tssecsrv.sys **LOCKED** 32 17:38:58.449 Service tunmp C:\Windows\system32\DRIVERS\tunmp.sys **LOCKED** 32 17:38:58.464 Service tunnel C:\Windows\system32\DRIVERS\tunnel.sys **LOCKED** 32 17:38:58.464 Service uagp35 C:\Windows\system32\drivers\uagp35.sys **LOCKED** 32 17:38:58.480 Service uliagpkx C:\Windows\system32\drivers\uliagpkx.sys **LOCKED** 32 17:38:58.496 Service uliahci C:\Windows\system32\drivers\uliahci.sys **LOCKED** 32 17:38:58.511 Service UlSata C:\Windows\system32\drivers\ulsata.sys **LOCKED** 32 17:38:58.511 Service ulsata2 C:\Windows\system32\drivers\ulsata2.sys **LOCKED** 32 17:38:58.527 Service umbus C:\Windows\system32\DRIVERS\umbus.sys **LOCKED** 32 17:38:58.542 Service usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys **LOCKED** 32 17:38:58.558 Service usbcir C:\Windows\system32\drivers\usbcir.sys **LOCKED** 32 17:38:58.574 Service usbehci C:\Windows\system32\DRIVERS\usbehci.sys **LOCKED** 32 17:38:58.574 Service usbhub C:\Windows\system32\DRIVERS\usbhub.sys **LOCKED** 32 17:38:58.589 Service usbohci C:\Windows\system32\drivers\usbohci.sys **LOCKED** 32 17:38:58.605 Service usbprint C:\Windows\system32\drivers\usbprint.sys **LOCKED** 32 17:38:58.605 Service USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS **LOCKED** 32 17:38:58.620 Service usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys **LOCKED** 32 17:38:58.636 Service vga C:\Windows\system32\DRIVERS\vgapnp.sys **LOCKED** 32 17:38:58.636 Service VgaSave C:\Windows\System32\drivers\vga.sys **LOCKED** 32 17:38:58.652 Service viaagp C:\Windows\system32\drivers\viaagp.sys **LOCKED** 32 17:38:58.667 Service ViaC7 C:\Windows\system32\drivers\viac7.sys **LOCKED** 32 17:38:58.667 Service viaide C:\Windows\system32\drivers\viaide.sys **LOCKED** 32 17:38:58.683 Service volmgr C:\Windows\system32\drivers\volmgr.sys **LOCKED** 32 17:38:58.698 Service volmgrx C:\Windows\System32\drivers\volmgrx.sys **LOCKED** 32 17:38:58.698 Service volsnap C:\Windows\system32\drivers\volsnap.sys **LOCKED** 32 17:38:58.714 Service vsmraid C:\Windows\system32\drivers\vsmraid.sys **LOCKED** 32 17:38:58.730 Service WacomPen C:\Windows\system32\drivers\wacompen.sys **LOCKED** 32 17:38:58.745 Service Wanarp C:\Windows\system32\DRIVERS\wanarp.sys **LOCKED** 32 17:38:58.761 Service Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys **LOCKED** 32 17:38:58.776 Service Wd C:\Windows\system32\drivers\wd.sys **LOCKED** 32 17:38:58.792 Service Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys **LOCKED** 32 17:38:58.808 Service winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys **LOCKED** 32 17:38:58.839 Service WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys **LOCKED** 32 17:38:58.854 Service WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys **LOCKED** 32 17:38:58.870 Service ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys **LOCKED** 32 17:38:58.886 Service WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys **LOCKED** 32 17:38:58.901 Service XAudio C:\Windows\system32\DRIVERS\xaudio.sys **LOCKED** 32 17:38:59.478 Modules scanning 17:39:09.603 Disk 0 trace - called modules: 17:39:09.634 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys 17:39:09.634 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x852b9488] 17:39:09.650 3 ntkrnlpa.exe[820b07e2] -> nt!IofCallDriver -> [0x84bd34e0] 17:39:09.650 5 acpi.sys[8046932a] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x84bbdbb0] 17:39:09.665 Scan finished successfully 17:40:01.732 Disk 0 MBR has been saved successfully to "C:\Users\Trudy\Desktop\What the Tech\MBR.dat" 17:40:01.748 The log file has been saved successfully to "C:\Users\Trudy\Desktop\What the Tech\aswMBR.txt" aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-26 13:29:43 —————————– 13:29:43.283 OS Version: Windows 6.0.6000 13:29:43.283 Number of processors: 2 586 0xF06 13:29:43.283 ComputerName: TRUDY-PC UserName: Trudy 13:29:45.732 Initialize success 13:31:36.636 AVAST engine defs: 12082600 13:31:46.995 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 13:31:46.995 Disk 0 Vendor: SAMSUNG_HM120JI YF100-15 Size: 114473MB BusType: 3 13:31:47.042 Disk 0 MBR read successfully 13:31:47.042 Disk 0 MBR scan 13:31:47.057 Disk 0 Windows VISTA default MBR code 13:31:47.057 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63 13:31:47.088 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 98304 13:31:47.135 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 102136 MB offset 21069824 13:31:47.151 Disk 0 Partition - 00 0F Extended LBA 2048 MB offset 230244352 13:31:47.260 Disk 0 Partition 4 00 DD MSDOS5.0 2047 MB offset 230246400 13:31:47.276 Disk 0 scanning sectors +234438656 13:31:47.432 Disk 0 scanning C:\Windows\system32\drivers 13:32:02.486 Service scanning 13:32:28.257 Modules scanning 13:32:34.856 Disk 0 trace - called modules: 13:32:34.887 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys 13:32:34.887 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84c4fad8] 13:32:34.902 3 ntkrnlpa.exe[820b07e2] -> nt!IofCallDriver -> [0x84bd18e8] 13:32:34.918 5 acpi.sys[8046932a] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x84bcfbb0] 13:32:35.604 AVAST engine scan C:\Windows 13:32:39.286 AVAST engine scan C:\Windows\system32 13:35:48.186 AVAST engine scan C:\Windows\system32\drivers 13:36:02.726 AVAST engine scan C:\Users\Trudy 13:40:57.425 AVAST engine scan C:\ProgramData 13:47:24.492 Scan finished successfully 13:52:57.459 Disk 0 MBR has been saved successfully to "C:\Users\Trudy\Desktop\What the Tech\MBR.dat" 13:52:57.459 The log file has been saved successfully to "C:\Users\Trudy\Desktop\What the Tech\aswMBR.txt"

Attachments:

Please run the following

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
ComboFix 12-08-25.04 - Trudy 26/08/2012 16:52:48.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.2038.1155 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-07-26 to 2012-08-26 )))))))))))))))))))))))))))))))
.
.
2012-08-26 21:03 . 2012-08-26 21:03 ——– d—–w- c:\users\White\AppData\Local\temp
2012-08-26 21:03 . 2012-08-26 21:03 ——– d—–w- c:\users\Public\AppData\Local\temp
2012-08-26 21:03 . 2012-08-26 21:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-08-26 21:03 . 2012-08-26 21:03 ——– d—–w- c:\users\Austin\AppData\Local\temp
2012-08-26 21:03 . 2012-08-26 21:03 ——– d—–w- c:\users\Austin.Trudy-PC\AppData\Local\temp
2012-08-25 22:05 . 2012-08-01 22:51 7023536 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2CCF61D2-174E-4B0B-A47E-70BE88332FAA}\mpengine.dll
2012-08-19 22:24 . 2012-08-19 22:24 ——– d—–w- c:\users\Austin.Trudy-PC\AppData\Roaming\DivX
2012-08-12 16:30 . 2006-11-15 18:08 155648 —-a-w- c:\windows\system32\igfxres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-07 00:59 . 2012-06-07 00:59 1070152 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-05-31 16:25 . 2011-05-07 22:17 237072 ——w- c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{37153479-1976-43c3-a1ee-557513977b64}"= "c:\program files\Coupons.com\prxtbCou0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{37153479-1976-43c3-a1ee-557513977b64}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{37153479-1976-43c3-a1ee-557513977b64}]
2011-05-09 09:49 176936 —-a-w- c:\program files\Coupons.com\prxtbCou0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{37153479-1976-43c3-a1ee-557513977b64}"= "c:\program files\Coupons.com\prxtbCou0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{37153479-1976-43c3-a1ee-557513977b64}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{37153479-1976-43C3-A1EE-557513977B64}"= "c:\program files\Coupons.com\prxtbCou0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{37153479-1976-43c3-a1ee-557513977b64}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2011-05-08 1232896]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2006-11-12 446976]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-09-23 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-15 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-15 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-15 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2007-02-05 77824]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-27 1540096]
"SigmatelSysTrayApp"="sttray.exe" [2006-12-01 303104]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-10-13 184320]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2011-05-07 340520]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-11-01 2508104]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-09-03 767312]
"IJNetworkScanUtility"="c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2009-09-28 140640]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"AgentMonitor"="c:\program files\VTech\DownloadManager\System\AgentMonitor.exe" [2011-12-13 357800]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-2-5 50688]
QuickSet.lnk - c:\windows\Installer\{53A01CC6-14B0-4512-A2E7-10D39BF83DC4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-2-5 45056]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - aswMBR
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-23 15:22]
.
2012-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-23 15:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-26 17:03
Windows 6.0.6000 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-08-26 17:07:45
ComboFix-quarantined-files.txt 2012-08-26 21:07
ComboFix2.txt 2011-07-29 23:11
.
Pre-Run: 58,713,473,024 bytes free
Post-Run: 58,998,460,416 bytes free
.
- - End Of File - - D43C12D77FCC012E3ACE8471DE368D9E
Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.27.05 Windows Vista x86 NTFS Internet Explorer 7.0.6000.16982 Trudy :: TRUDY-PC [administrator] Protection: Enabled 27/08/2012 6:17:27 PM mbam-log-2012-08-27 (18-17-27).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 231904 Time elapsed: 10 minute(s), 57 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESET found nothing
Your Java is out of date, so go to Start > Control Panel > Programs and Features > scroll down to the Java installation and Remove it, now download the latest Java version 7 update 6 and install it: http://java.com/en/download/index.jsp


NEXT


Please download Farbar Service Scanner and run it
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


NEXT


How is the computer running now? Are there any outstanding issues?
Farbar Service Scanner Version: 06-08-2012 Ran by [removed] (administrator) on 27-08-2012 at 21:42:20 Running from "C:\Users\Trudy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TRVCSV0I" Microsoft® Windows Vista™ Home Premium (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Other Services: ============== File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll [2006-11-02 04:56] - [2006-11-02 05:46] - 0204800 ____A (Microsoft Corporation) 17210D8064EC116A3FC6B5E45E577D43 C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log **** The computer hasn't really changed. I noticed that we scanned a lot for virues, mallware, etc and nothing was found.
we've eliminated malware as the cause as the machine appears to be clean.

I suggest starting a new topic in our Windows forum

http://forums.whatthetech.com/index.php?showforum=119

let the expert techs know that you have been cleared by the malware forum, then see if they can tweak the performance of your machine

in the meantime, let's clean up our tools


You can delete the DDS, aswMBR and the Farbar logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Press the WinKey +R to open a run box
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI