This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New Hard Drive and Windows XP Installed [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HD crashed….New one installed with Windows XP Home Addition…..All updates including SP3

Here is my OTL file, Take a look and lets remove this Babylon Toolbar, etc., and any other things that could be a threat….PC running great!
Malwarebytes clean, and Microsoft Issentials reports no viruses…..

Thanks!

OTL logfile created on: 06/11/2012 11:08:16 PM - Run 7
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\Compaq_Administrator\Desktop\Computer Tools
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

958.48 Mb Total Physical Memory | 428.13 Mb Available Physical Memory | 44.67% Memory free
2.26 Gb Paging File | 1.89 Gb Available in Paging File | 83.89% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.68 Gb Total Space | 187.84 Gb Free Space | 83.60% Space Free | Partition Type: NTFS
Drive D: | 8.18 Gb Total Space | 0.54 Gb Free Space | 6.63% Space Free | Partition Type: FAT32
Drive F: | 93.37 Gb Total Space | 15.04 Gb Free Space | 16.11% Space Free | Partition Type: NTFS

Computer Name: COMPAQ-PRESARIO | User Name: Compaq_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Macrium\Reflect\ReflectService.exe ()
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Compaq_Administrator\Desktop\Computer Tools\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\UPHClean\uphclean.exe (Windows ® Codename Longhorn DDK provider)
PRC - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\Program Files\Common Files\Motive\motivebrowser.exe (Motive Communications, Inc.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Macrium\Reflect\ReflectService.exe ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (ReflectService.exe) – C:\Program Files\Macrium\Reflect\ReflectService.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Windows ® Codename Longhorn DDK provider)
SRV - (CLDTVHNService) – C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
SRV - (ARSVC) – C:\WINDOWS\arservice.exe (Microsoft)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (pssnap) – C:\WINDOWS\system32\DRIVERS\pssnap.sys (Macrium Software)
DRV - (PSMounter) – C:\WINDOWS\system32\drivers\psmounter.sys (Macrium Software)
DRV - (mbamchameleon) – C:\WINDOWS\system32\drivers\mbamchameleon.sys ()
DRV - (DrvAgent32) – C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Almico Software)
DRV - (ntk_dtv) – C:\Program Files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys (Cyberlink Corp.)
DRV - (USB_RNDIS_XP) – C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (MCSTRM) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (PCD5SRVC{8A863ACB-F5F6CC6A-05010003}) – C:\Program Files\PC-Doctor 5 for Windows\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/02 14:39:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/09 08:10:10 | 000,000,000 | —D | M]

[2011/12/31 15:28:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Extensions
[2012/04/23 22:32:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\788pfasp.default\extensions
[2011/12/31 15:27:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/07/03 01:06:59 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
() (No name found) – C:\DOCUMENTS AND SETTINGS\COMPAQ_ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\788PFASP.DEFAULT\EXTENSIONS\[removed]
[2011/12/21 03:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/03/18 14:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/11/24 17:22:52 | 000,611,224 | —- | M] (Oracle Corporation) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 14:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/04/23 22:32:08 | 000,002,310 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/12/21 00:30:41 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/21 00:30:41 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/05/16 21:14:47 | 000,442,026 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 -h-n7y15mc.firoli-sys.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 15213 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll (TODO: )
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No CLSID value found.
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [MotiveReportAgent] C:\Program Files\Common Files\Motive\McciBootStrapper.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled [2010/09/14 08:43:53 | 000,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EditLevel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Photodex Presenter AX control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.1.0…xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D}: DhcpNameServer = [removed] [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DE6A30FD-221E-48A6-B77C-0C5CE0CB4B3E}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (SDEarlyDelete \??)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/06/10 18:44:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Garmin
[2012/06/10 18:43:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\GARMIN_Corp
[2012/06/10 16:55:16 | 000,016,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2012/06/10 16:54:35 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Connect 2
[2012/06/10 16:51:50 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2012/06/10 16:51:50 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2012/06/10 12:01:11 | 000,181,064 | —- | C] (Sysinternals) – C:\WINDOWS\PSEXESVC.EXE
[2012/06/10 11:59:49 | 000,000,000 | —D | C] – C:\Tweaking.com_Windows_Repair_Logs
[2012/06/10 11:59:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
[2012/06/10 11:59:38 | 000,000,000 | —D | C] – C:\Program Files\Tweaking.com
[2012/06/09 08:08:14 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2012/06/09 08:08:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBlaster
[2012/06/08 11:58:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\Application Data\OpenOffice.org
[2012/06/08 11:55:56 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2012/06/08 11:54:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\Desktop\OpenOffice.org 3.4 (en-US) Installation Files
[2012/05/25 10:49:50 | 000,053,952 | —- | C] (Macrium Software) – C:\WINDOWS\System32\drivers\psmounter.sys
[2012/05/25 10:49:50 | 000,016,064 | —- | C] (Macrium Software) – C:\WINDOWS\System32\drivers\pssnap.sys
[2012/05/25 10:49:50 | 000,012,992 | —- | C] (Paramount Software UK Ltd) – C:\WINDOWS\System32\drivers\PSVolAcc.sys
[2012/05/17 11:13:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\My Documents\Contacts
[2012/05/17 09:23:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\DiskInternals
[2012/05/17 09:22:58 | 000,000,000 | —D | C] – C:\Program Files\DiskInternals
[2012/05/13 12:45:14 | 000,419,488 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/06/11 23:12:00 | 000,000,452 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
[2012/06/11 22:54:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/11 22:31:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/11 20:06:35 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/06/11 19:56:25 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/11 18:46:58 | 000,040,710 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Tornado Icon!.pdf
[2012/06/11 02:54:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/10 17:07:01 | 000,000,808 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/06/10 17:04:54 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2012/06/10 17:04:53 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2012/06/10 16:55:20 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/06/10 16:53:12 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2012/06/10 16:51:57 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012/06/10 16:50:29 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/06/10 12:27:47 | 000,002,411 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Reflect.lnk
[2012/06/10 12:01:11 | 000,181,064 | —- | M] (Sysinternals) – C:\WINDOWS\PSEXESVC.EXE
[2012/06/10 12:01:10 | 000,000,042 | —- | M] () – C:\repairs_running.dat
[2012/06/10 12:00:56 | 000,000,299 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Something just not right!.url
[2012/06/10 11:59:42 | 000,001,916 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2012/06/10 11:58:41 | 004,484,304 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\tweaking.com_windows_repair_aio_setup.exe
[2012/06/09 09:44:57 | 000,000,269 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William & Mary S3E1 (1-5) - YouTube.url
[2012/06/09 09:39:49 | 000,000,269 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William and Mary - Series 2, Ep 6, Part 3-3 - YouTube.url
[2012/06/09 08:12:29 | 000,322,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/07 17:39:21 | 000,049,362 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/06/07 17:27:59 | 000,870,128 | —- | M] () – C:\WINDOWS\System32\mcs.rma
[2012/06/07 17:27:59 | 000,000,004 | —- | M] () – C:\WINDOWS\System32\0AFDEE
[2012/06/07 12:23:05 | 000,000,218 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Environmental Turf - Our Grasses - UltimateFlora® Zoysia.url
[2012/06/07 12:21:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/04 08:48:57 | 000,000,200 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Medicare Advantage Plans AMAC, Inc..url
[2012/06/01 20:27:37 | 004,246,614 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Spending account claims that need to be sent.bmp
[2012/05/31 09:22:09 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2012/05/25 09:52:47 | 000,012,992 | —- | M] (Paramount Software UK Ltd) – C:\WINDOWS\System32\drivers\PSVolAcc.sys
[2012/05/25 09:52:37 | 000,016,064 | —- | M] (Macrium Software) – C:\WINDOWS\System32\drivers\pssnap.sys
[2012/05/25 09:52:31 | 000,053,952 | —- | M] (Macrium Software) – C:\WINDOWS\System32\drivers\psmounter.sys
[2012/05/23 17:57:59 | 000,001,753 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Jennifer's Way Helping Those With Celiac Disease.url
[2012/05/18 22:54:51 | 004,246,614 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\My Spending Account Reinbursement for 2012.bmp
[2012/05/17 13:13:11 | 000,159,809 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\flomaster pump sprayer.pdf
[2012/05/17 11:45:17 | 000,018,560 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\SCHEDULE. TXT
[2012/05/17 11:38:45 | 000,018,351 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\SCHEDULE
[2012/05/16 21:14:47 | 000,442,026 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/05/14 18:23:02 | 000,458,446 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/05/14 18:23:02 | 000,078,716 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/05/13 12:45:14 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/05/13 12:45:14 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/11 18:46:57 | 000,040,710 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Tornado Icon!.pdf
[2012/06/10 16:51:57 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012/06/10 12:01:10 | 000,000,042 | —- | C] () – C:\repairs_running.dat
[2012/06/10 12:00:56 | 000,000,299 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Something just not right!.url
[2012/06/10 11:59:42 | 000,001,916 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2012/06/10 11:58:40 | 004,484,304 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\tweaking.com_windows_repair_aio_setup.exe
[2012/06/09 09:44:57 | 000,000,269 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William & Mary S3E1 (1-5) - YouTube.url
[2012/06/09 09:39:49 | 000,000,269 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William and Mary - Series 2, Ep 6, Part 3-3 - YouTube.url
[2012/06/07 12:23:05 | 000,000,218 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Environmental Turf - Our Grasses - UltimateFlora® Zoysia.url
[2012/06/06 10:32:15 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/04 08:48:57 | 000,000,200 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Medicare Advantage Plans AMAC, Inc..url
[2012/06/01 20:27:36 | 004,246,614 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Spending account claims that need to be sent.bmp
[2012/05/23 17:57:59 | 000,001,753 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Jennifer's Way Helping Those With Celiac Disease.url
[2012/05/18 22:54:50 | 004,246,614 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\My Spending Account Reinbursement for 2012.bmp
[2012/05/17 13:13:11 | 000,159,809 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\flomaster pump sprayer.pdf
[2012/05/17 11:45:17 | 000,018,560 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\SCHEDULE. TXT
[2012/05/17 11:38:45 | 000,018,351 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\SCHEDULE
[2012/05/10 11:00:47 | 000,000,135 | —- | C] () – C:\Documents and Settings\All Users\Application Data\avalon2.2_WIPE2012.ini
[2012/05/10 11:00:32 | 000,340,992 | —- | C] () – C:\WINDOWS\System32\sqlite36_engine.dll
[2012/05/10 11:00:29 | 000,340,992 | —- | C] () – C:\WINDOWS\sqlite36_engine.dll
[2012/05/08 20:32:10 | 000,032,072 | —- | C] () – C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2012/02/25 12:48:22 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2012/02/23 12:53:33 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/02/23 12:53:33 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/02/23 12:53:33 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/02/23 12:53:33 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/02/23 12:53:33 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/02/15 23:13:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/06 18:08:24 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT11.ini
[2011/12/01 00:46:28 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat
[2011/07/24 15:47:34 | 002,130,002 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/07/10 13:48:52 | 000,024,408 | —- | C] () – C:\WINDOWS\System32\ventmon.dll
[2011/07/03 01:10:37 | 000,017,408 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\WebpageIcons.db
[2011/05/14 16:11:18 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/05/14 16:11:18 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/05/14 16:11:18 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/12 18:31:18 | 000,000,600 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\PUTTY.RND
[2011/01/07 17:08:16 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT10.ini

< End of report >
Hi Lewg,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
MOD - C:\WINDOWS\system32\sbe.dll ()
[2011/03/18 14:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/03/18 14:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/04/23 22:32:08 | 000,002,310 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found.
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No CLSID value found.
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.
I copied the text in the OTL program and clicked on Run Fix. My virus program Microsoft Essentials popped up a windows saying the program was not protecting my system because the prosess was turned off. The OTL program did not respond to removing the info put in the custom scan box……I turned off Microsoft Essentials, but the same window popped up saying the same thing stopping the OTL program from responding….. I may have to remove Microsoft Essential, and d/load it again after running OTL's Run Fix………Any ideas!
I thought I would send you a copy of my HJT log file also…..Just ran it…..It might help as well.

Thanks!


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:23:46 PM, on 9/19/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Documents and Settings\All Users\Application Data\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Application Data\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\PCShowServerPMWrapper.exe
C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\NDSPCShowServer.exe
C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Lew\My Documents\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: CrossriderApp0004493 - {11111111-1111-1111-1111-110011441193} - C:\Program Files\Coupon Companion\Coupon Companion.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O3 - Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - (no file)
O3 - Toolbar: Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - "C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PCShowServer] "C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\PCShowServerPMWrapper.exe"
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1347465718176
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1347978180406
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - AppInit_DLLs: c:\docume~1\alluse~1\applic~1\browse~1\22643~1.41\{16cdf~1\browse~1.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Browser Manager - Unknown owner - C:\Documents and Settings\All Users\Application Data\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 7150 bytes
It ran OK this time after turning off MSE the second time…..Don't know what happened to the log file but it read All Processes Killed…. What's next?
Ok… for the time being, let's assume it worked as planned.

Download ComboFix:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 12-09-18.07 - Lew 09/19/2012 22:00:26.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.475 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Lew\WINDOWS
c:\windows\system32\dllcache\dlimport.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-08-20 to 2012-09-20 )))))))))))))))))))))))))))))))
.
.
2012-09-19 14:46 . 2012-09-19 14:46 ——– d—–w- C:\c57b15f097730dbd27a55ca19911
2012-09-19 14:05 . 2012-09-19 14:05 ——– d—–w- C:\_OTL
2012-09-18 17:25 . 2012-09-18 17:25 ——– d—–w- C:\HP
2012-09-18 17:24 . 2012-09-18 17:24 ——– d—–w- C:\temp
2012-09-14 15:59 . 2012-09-18 18:28 ——– d—–w- C:\QUICKENW
2012-09-14 15:57 . 2012-09-14 15:58 ——– d—–w- C:\Quicken6
2012-09-14 13:03 . 2012-09-14 21:19 ——– d—–w- C:\desktop
2012-09-12 19:09 . 2012-09-12 19:09 ——– d—a-w- C:\swsetup
2012-09-12 19:09 . 2012-09-12 19:09 ——– d—–w- C:\SYSTEM.SAV
2012-09-12 01:08 . 2012-09-12 01:10 ——– d—–w- C:\softpaq
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-06 13:58 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-03 13:40 . 2006-02-28 12:00 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2006-02-28 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2006-02-28 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2006-02-28 12:00 385024 ——w- c:\windows\system32\html.iec
2012-06-28 21:33 . 2012-06-28 21:33 81920 ——w- c:\windows\system32\ieencode.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6}]
2012-02-10 15:28 1307928 —-a-w- c:\program files\Microsoft\BingBar\7.1.361.0\BingExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCShowServer"="c:\documents and settings\Lew\Local Settings\Application Data\DIRECTV Player\PCShowServerPMWrapper.exe" [2012-08-16 524976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-09 86016]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2012-09-12 296096]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE [2/10/2012 11:28 AM 193816]
R2 Browser Manager;Browser Manager;c:\documents and settings\All Users\Application Data\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [9/14/2012 5:48 PM 1701400]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [9/14/2012 6:58 PM 399432]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/14/2012 6:58 PM 676936]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/14/2012 6:58 PM 22856]
S1 MpKsl3b7994bc;MpKsl3b7994bc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C59A58CE-24EB-4AF7-AE59-A17C35BD643A}\MpKsl3b7994bc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C59A58CE-24EB-4AF7-AE59-A17C35BD643A}\MpKsl3b7994bc.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [9/12/2012 2:50 PM 250568]
S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE [2/10/2012 11:28 AM 240408]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-12 13:25]
.
2012-09-19 c:\windows\Tasks\At1.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-17 01:12]
.
2012-09-20 c:\windows\Tasks\At2.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-17 01:12]
.
2012-09-19 c:\windows\Tasks\At3.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-17 01:12]
.
2012-09-19 c:\windows\Tasks\At4.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-17 01:12]
.
2012-09-20 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
2012-09-20 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
2012-09-20 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 18:27]
.
2012-09-20 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 18:27]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-LSI Soft Modem - c:\windows\agrsmdel
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-09-19 22:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3576)
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\documents and settings\All Users\Application Data\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\rundll32.exe
c:\documents and settings\Lew\Local Settings\Application Data\DIRECTV Player\NDSPCShowServer.exe
.
**************************************************************************
.
Completion time: 2012-09-19 22:10:53 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-20 02:10
.
Pre-Run: 488,292,429,824 bytes free
Post-Run: 488,191,324,160 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - EF27154DBDC251FF8315E524BDD1D33E
That looks good… let's get an online scan. It takes a long time - probably hours.

Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Tomk, 6 threats here! C:\Documents and Settings\All Users\Application Data\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Program Files\Coupon Companion\Coupon Companion.dll Win32/Toolbar.CrossRider application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP15\A0007380.dll a variant of Win32/Toolbar.Babylon application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP15\A0007383.exe probably a variant of Win32/Toolbar.Babylon application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP16\A0007391.dll a variant of Win32/Adware.Yontoo.A application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP16\A0007393.dll a variant of Win32/Adware.Yontoo.B application
Actually just two and they are remnants left over from the "fix" we did with OTL. The others are "ghosts" of the infection that are still held in your restore points.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Documents and Settings\All Users\Application Data\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll
    C:\Program Files\Coupon Companion\Coupon Companion.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Also, please let me know how things seem to be running.
PC not performing correctly at present……..


ComboFix 12-09-18.07 - Lew 09/20/2012 10:26:14.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.508 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Lew\Desktop\cfscript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\All Users\Application Data\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll"
"c:\program files\Coupon Companion\Coupon Companion.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll
c:\program files\Coupon Companion\Coupon Companion.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-08-20 to 2012-09-20 )))))))))))))))))))))))))))))))
.
.
2012-09-19 14:46 . 2012-09-19 14:46 ——– d—–w- C:\c57b15f097730dbd27a55ca19911
2012-09-19 14:05 . 2012-09-19 14:05 ——– d—–w- C:\_OTL
2012-09-18 17:25 . 2012-09-18 17:25 ——– d—–w- C:\HP
2012-09-18 17:24 . 2012-09-18 17:24 ——– d—–w- C:\temp
2012-09-14 15:59 . 2012-09-18 18:28 ——– d—–w- C:\QUICKENW
2012-09-14 15:57 . 2012-09-14 15:58 ——– d—–w- C:\Quicken6
2012-09-14 13:03 . 2012-09-14 21:19 ——– d—–w- C:\desktop
2012-09-12 19:09 . 2012-09-12 19:09 ——– d—a-w- C:\swsetup
2012-09-12 19:09 . 2012-09-12 19:09 ——– d—–w- C:\SYSTEM.SAV
2012-09-12 01:08 . 2012-09-12 01:10 ——– d—–w- C:\softpaq
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-06 13:58 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-03 13:40 . 2006-02-28 12:00 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2006-02-28 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2006-02-28 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2006-02-28 12:00 385024 ——w- c:\windows\system32\html.iec
2012-06-28 21:33 . 2012-06-28 21:33 81920 ——w- c:\windows\system32\ieencode.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-09-20_02.08.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-09-20 14:16 . 2012-09-20 14:16 16384 c:\windows\Temp\Perflib_Perfdata_1a0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6}]
2012-02-10 15:28 1307928 —-a-w- c:\program files\Microsoft\BingBar\7.1.361.0\BingExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCShowServer"="c:\documents and settings\Lew\Local Settings\Application Data\DIRECTV Player\PCShowServerPMWrapper.exe" [2012-08-16 524976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-09 86016]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2012-09-12 296096]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE [2/10/2012 11:28 AM 193816]
R2 Browser Manager;Browser Manager;c:\documents and settings\All Users\Application Data\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [9/14/2012 5:48 PM 1701400]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [9/14/2012 6:58 PM 399432]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/14/2012 6:58 PM 676936]
R3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE [2/10/2012 11:28 AM 240408]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/14/2012 6:58 PM 22856]
S1 MpKsl3b7994bc;MpKsl3b7994bc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C59A58CE-24EB-4AF7-AE59-A17C35BD643A}\MpKsl3b7994bc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C59A58CE-24EB-4AF7-AE59-A17C35BD643A}\MpKsl3b7994bc.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [9/12/2012 2:50 PM 250568]
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-12 13:25]
.
2012-09-20 c:\windows\Tasks\At1.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-17 01:12]
.
2012-09-20 c:\windows\Tasks\At2.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-17 01:12]
.
2012-09-19 c:\windows\Tasks\At3.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-17 01:12]
.
2012-09-19 c:\windows\Tasks\At4.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-17 01:12]
.
2012-09-20 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
2012-09-20 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
2012-09-20 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 18:27]
.
2012-09-20 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 18:27]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 192.168.2.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-09-20 10:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2012-09-20 10:32:24
ComboFix-quarantined-files.txt 2012-09-20 14:32
ComboFix2.txt 2012-09-20 02:10
.
Pre-Run: 487,988,543,488 bytes free
Post-Run: 487,999,102,976 bytes free
.
- - End Of File - - DC787AB06827C4CC465C6164F1C8391B
Since I have not heard back from you. I have to go out of town for the weekend….Be home Tuesday and if you will let's continue with our session…..My PC will not go online from any of my desktop icons…….I ran eset again and 8 threats are listed. The log is below. C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application C:\Qoobox\Quarantine\C\Program Files\Coupon Companion\Coupon Companion.dll.vir Win32/Toolbar.CrossRider application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP15\A0007380.dll a variant of Win32/Toolbar.Babylon application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP15\A0007383.exe probably a variant of Win32/Toolbar.Babylon application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP16\A0007391.dll a variant of Win32/Adware.Yontoo.A application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP16\A0007393.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP29\A0017724.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP29\A0017725.dll Win32/Toolbar.CrossRider application
Those are all fine where they are.

When you get the chance… please run me a set of DDS logs.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI