This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unknown!? (not sure how I should know name of virus?)

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:05:06 PM, on 6/25/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
c:\Toshiba\Ivp\Swupdate\swupdtmr.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Najohodo\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O15 - Trusted Zone: http://*.advancedmd.com
O16 - DPF: {6A6E7E91-B6EB-46B5-A545-12B8EDDD261E} (AMDSControls50.XGroupCategory) - https://a-sl1-app02.advancedmd.com/practice…scontrols50.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1356494676337
O16 - DPF: {9602B3CE-BC91-417D-B4FD-F6538C2ABB3B} (AMDSWSCheck.WSCheck) - http://www.advancedmd.com/ws-test/files/AMDSWSCheck.CAB
O16 - DPF: {CC99A86F-EA5D-414A-8231-7C3F1B10A644} (AMDSAudio.XAudio) - https://a-sl1-app02.advancedmd.com/practice…s/amdsaudio.cab
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s…el_4.4.24.0.cab
O16 - DPF: {EE8CEFA4-1F91-11D4-B31E-00C04F1D37E6} (PPMDVBDownload.XShowReady) - https://a-sl1-app02.advancedmd.com/practice…dvbdownload.cab
O18 - Protocol: bw+0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: offline-8876480 - {489CC08C-362E-44E8-9530-2DD2B88EE5C0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\Ivp\Swupdate\swupdtmr.exe

–
End of file - 21743 bytes
Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-06-2013 02
Ran by [removed] (administrator) on 25-06-2013 21:26:27
Running from C:\Documents and Settings\[removed]\Desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe
(Intel Corporation ) C:\WINDOWS\System32\S24EvMon.exe
() c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(Matsushita Electric Industrial Co., Ltd.) C:\WINDOWS\System32\DVDRAMSV.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe
(Intel Corporation) C:\WINDOWS\System32\RegSrvc.exe
() c:\Toshiba\Ivp\Swupdate\swupdtmr.exe
(Intel Corporation) C:\WINDOWS\system32\ZCfgSvc.exe
(Intel) C:\WINDOWS\System32\1XConfig.exe
(Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
(Sonic Solutions) C:\WINDOWS\system32\dla\tfswctrl.exe
() C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe [118843 2004-03-26] (Sonic Solutions)
HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\…\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
Winlogon\Notify\igfxcui: igfxsrvc.dll (Intel Corporation)
Winlogon\Notify\Sebring: c:\WINDOWS\System32\LgNotify.dll (Intel Corporation)
HKCU\…\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2013-06-23] (Google Inc.)
HKCU\…\Runonce: [JavaInstallRetry] RUNONCE=1 SPONSORS=0 [x]
HKU\Default User\…\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe [ 2003-09-05] (TOSHIBA)
HKU\Default User\…\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [ 2008-04-13] (Microsoft Corporation)
BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.yahoo.com/?ilc=17
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: No Name - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {6A6E7E91-B6EB-46B5-A545-12B8EDDD261E} https://a-sl1-app02.advancedmd.com/practice…scontrols50.cab
DPF: {9602B3CE-BC91-417D-B4FD-F6538C2ABB3B} http://www.advancedmd.com/ws-test/files/AMDSWSCheck.CAB
DPF: {CC99A86F-EA5D-414A-8231-7C3F1B10A644} https://a-sl1-app02.advancedmd.com/practice…s/amdsaudio.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s…el_4.4.24.0.cab
DPF: {EE8CEFA4-1F91-11D4-B31E-00C04F1D37E6} https://a-sl1-app02.advancedmd.com/practice…dvbdownload.cab
Handler: ipp - No CLSID Value -
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Najohodo\Application Data\Mozilla\Firefox\Profiles\dqw0abg4.default
FF user.js: detected! => C:\Documents and Settings\Najohodo\Application Data\Mozilla\Firefox\Profiles\dqw0abg4.default\user.js
FF SearchEngine: Amazon.com
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @sony.com/eBookLibrary - C:\Program Files\Sony\Reader\Data\bin\npebldetectmoz.dll (Sony Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @viewpoint.com/VMP - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\23.0.1271.97\pdf.dll No File
CHR Plugin: (Google Talk Plugin) - C:\Documents and Settings\Najohodo\Application Data\Mozilla\plugins\npgoogletalk.dll No File
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Documents and Settings\Najohodo\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Documents and Settings\Najohodo\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Reader Library) - C:\Program Files\Sony\Reader\Data\bin\npebldetectmoz.dll (Sony Corporation)
CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Documents and Settings\Najohodo\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0

========================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4937264 2013-05-14] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-04-18] (AVG Technologies CZ, s.r.o.)
R2 DVD-RAM_Service; C:\WINDOWS\System32\DVDRAMSV.exe [106496 2003-05-23] (Matsushita Electric Industrial Co., Ltd.)
R2 RegSrvc; C:\WINDOWS\System32\RegSrvc.exe [122880 2003-12-16] (Intel Corporation)
R2 S24EventMonitor; C:\WINDOWS\System32\S24EvMon.exe [311363 2003-12-16] (Intel Corporation )
R2 Swupdtmr; c:\Toshiba\Ivp\Swupdate\swupdtmr.exe [53248 2004-05-13] ()
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
R2 LVPrcSrv; c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe [x]

==================== Drivers (Whitelisted) ====================

S3 AR5211; C:\Windows\System32\DRIVERS\ar5211.sys [380160 2004-04-18] (Atheros Communications, Inc.)
R2 ASCTRM; C:\Windows\System32\Drivers\ASCTRM.sys [8552 2004-04-07] (Windows ® 2000 DDK provider)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-03-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-03-01] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [170808 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [245048 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2009-12-18] ()
R2 drvnddm; C:\Windows\System32\drivers\drvnddm.sys [40480 2004-01-14] (Sonic Solutions)
S3 gv3; C:\Windows\System32\DRIVERS\gv3.sys [30976 2002-11-18] (Microsoft Corporation)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
R3 ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [95579 2004-01-26] (Intel Corporation)
R2 MDC8021X; C:\Windows\System32\DRIVERS\mdc8021x.sys [14037 2000-01-04] (Meetinghouse Data Communications)
R1 meiudf; C:\Windows\System32\Drivers\meiudf.sys [90416 2003-10-24] (Matsushita Electric Industrial Co.,Ltd.)
S3 NABTSFEC; C:\Windows\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R2 Netdevio; C:\Windows\System32\DRIVERS\netdevio.sys [12032 2003-01-29] (TOSHIBA Corporation.)
R3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [9856 2002-10-01] (Padus, Inc.)
R2 s24trans; C:\Windows\System32\DRIVERS\s24trans.sys [11258 2003-09-15] (Intel Corporation)
S3 SLIP; C:\Windows\System32\DRIVERS\SLIP.sys [11136 2008-04-13] (Microsoft Corporation)
R1 sscdbhk5; C:\Windows\System32\drivers\sscdbhk5.sys [5621 2004-01-14] (Sonic Solutions)
R1 ssrtln; C:\Windows\System32\drivers\ssrtln.sys [23219 2004-01-14] (Sonic Solutions)
R3 STAC97; C:\Windows\System32\drivers\stac97.sys [230416 2003-07-17] (SigmaTel, Inc.)
S3 streamip; C:\Windows\System32\DRIVERS\StreamIP.sys [15232 2008-04-13] (Microsoft Corporation)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [12984 2013-06-23] ()
R2 TBiosDrv; C:\WINDOWS\System32\drivers\TBiosDrv.sys [6867 2003-06-11] ()
R2 tfsnboio; C:\Windows\System32\dla\tfsnboio.sys [25691 2004-03-26] (Sonic Solutions)
R2 tfsncofs; C:\Windows\System32\dla\tfsncofs.sys [34843 2004-03-26] (Sonic Solutions)
R2 tfsndrct; C:\Windows\System32\dla\tfsndrct.sys [4123 2004-03-26] (Sonic Solutions)
R2 tfsndres; C:\Windows\System32\dla\tfsndres.sys [2239 2004-03-26] (Sonic Solutions)
R2 tfsnifs; C:\Windows\System32\dla\tfsnifs.sys [85722 2004-03-26] (Sonic Solutions)
R2 tfsnopio; C:\Windows\System32\dla\tfsnopio.sys [14235 2004-03-26] (Sonic Solutions)
R2 tfsnpool; C:\Windows\System32\dla\tfsnpool.sys [6363 2004-03-26] (Sonic Solutions)
R2 tfsnudf; C:\Windows\System32\dla\tfsnudf.sys [98522 2004-03-26] (Sonic Solutions)
R2 tfsnudfa; C:\Windows\System32\dla\tfsnudfa.sys [100603 2004-03-26] (Sonic Solutions)
R2 tossmbnt; C:\Windows\System32\Drivers\tossmbnt.sys [19607 2002-04-06] ()
S3 V0420VID; C:\Windows\System32\DRIVERS\V0420Vid.sys [99648 2007-05-30] (Creative Technology Ltd.)
S3 w22n51; C:\Windows\System32\DRIVERS\w22n51.sys [1646720 2004-01-02] (Intel® Corporation)
R3 w29n51; C:\Windows\System32\DRIVERS\w29n51.sys [2216064 2009-11-11] (Intel® Corporation)
S3 WSTCODEC; C:\Windows\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-13] (Microsoft Corporation)
R3 {6080A529-897E-4629-A488-ABA0C29B635E}; C:\Windows\System32\drivers\ialmsbw.sys [122110 2004-01-26] (Intel Corporation)
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}; C:\Windows\System32\drivers\ialmkchw.sys [99002 2004-01-26] (Intel Corporation)
R3 {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}; C:\Windows\System32\drivers\wA301a.sys [33847 2004-01-26] (Intel Corporation)
S4 Abiosdsk; No ImagePath
S4 abp480n5; No ImagePath
S4 adpu160m; No ImagePath
S4 Aha154x; No ImagePath
S4 aic78u2; No ImagePath
S4 aic78xx; No ImagePath
S4 AliIde; No ImagePath
S4 amsint; No ImagePath
S4 asc; No ImagePath
S4 asc3350p; No ImagePath
S4 asc3550; No ImagePath
S4 Atdisk; No ImagePath
S4 cd20xrnt; No ImagePath
S1 Cdr4_xp; No ImagePath
S1 Cdralw2k; No ImagePath
S1 Changer; No ImagePath
S4 CmdIde; No ImagePath
S4 Cpqarray; No ImagePath
U4 dac2w2k; No ImagePath
S4 dac960nt; No ImagePath
S4 dpti2o; No ImagePath
S4 hpn; No ImagePath
S1 i2omgmt; No ImagePath
S4 i2omp; No ImagePath
S4 ini910u; No ImagePath
S1 lbrtfdc; No ImagePath
S3 LVcKap; system32\DRIVERS\LVcKap.sys [x]
S3 LVMVDrv; system32\DRIVERS\LVMVDrv.sys [x]
R3 LVPr2Mon; system32\drivers\LVPr2Mon.sys [x]
S3 LVUSBSta; system32\drivers\lvusbsta.sys [x]
S4 mraid35x; No ImagePath
S2 mrtRate; No ImagePath
S1 PCIDump; No ImagePath
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
S3 pepifilter; system32\DRIVERS\lv302af.sys [x]
S4 perc2; No ImagePath
S4 perc2hib; No ImagePath
S3 PID_08A0; system32\DRIVERS\LV302AV.SYS [x]
S4 ql1080; No ImagePath
S4 Ql10wnt; No ImagePath
S4 ql12160; No ImagePath
S4 ql1240; No ImagePath
S4 ql1280; No ImagePath
S4 Simbad; No ImagePath
S4 Sparrow; No ImagePath
S4 symc810; No ImagePath
S4 symc8xx; No ImagePath
S4 sym_hi; No ImagePath
S4 sym_u3; No ImagePath
S4 TosIde; No ImagePath
S4 ultra; No ImagePath
S4 ViaIde; No ImagePath
S3 wanatw; System32\DRIVERS\wanatw4.sys [x]
S3 WDICA; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-25 21:26 - 2013-06-25 21:26 - 00000000 ____D C:\FRST
2013-06-25 21:25 - 2013-06-25 21:26 - 01370251 ____A (Farbar) C:\Documents and Settings\Najohodo\Desktop\FRST.exe
2013-06-25 21:08 - 2013-06-25 21:08 - 00001009 ____A C:\Windows\setupapi.log
2013-06-25 20:33 - 2013-06-25 20:57 - 00000000 ____D C:\Documents and Settings\Najohodo\Application Data\IObit
2013-06-25 20:33 - 2013-06-25 20:35 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\IObit
2013-06-25 20:33 - 2013-06-25 20:33 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-06-25 20:32 - 2013-06-25 20:32 - 00000000 ____D C:\Program Files\IObit
2013-06-25 19:05 - 2013-06-25 19:05 - 00021745 ____A C:\Documents and Settings\Najohodo\Desktop\hijackthis.log
2013-06-25 19:02 - 2013-06-25 19:02 - 00388608 ____A (Trend Micro Inc.) C:\Documents and Settings\Najohodo\Desktop\HiJackThis.exe
2013-06-24 19:02 - 2013-06-24 19:02 - 00001542 ____A C:\Documents and Settings\All Users\Desktop\iTunes.lnk
2013-06-24 19:01 - 2013-06-24 19:02 - 00000000 ____D C:\Program Files\iTunes
2013-06-24 19:01 - 2013-06-24 19:02 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-06-24 19:01 - 2013-06-24 19:01 - 00000000 ____D C:\Program Files\iPod
2013-06-24 18:16 - 2013-06-24 18:16 - 00001604 ____A C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
2013-06-24 18:16 - 2013-06-24 18:16 - 00000000 ____D C:\Program Files\QuickTime
2013-06-24 16:43 - 2013-06-24 16:43 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\Sun
2013-06-23 22:26 - 2013-06-25 20:31 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-23 22:26 - 2013-06-25 17:41 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-23 17:00 - 2013-06-23 17:00 - 00000578 ____A C:\Documents and Settings\Najohodo\My Documents\AutoFix_2013-06-23_17-00-14.txt
2013-06-11 22:12 - 2013-06-11 22:12 - 09089416 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2013-06-10 22:41 - 2013-06-10 22:41 - 04717935 ____A C:\Documents and Settings\Najohodo\My Documents\Attachments_2013_06_10.zip
2013-06-08 14:22 - 2013-06-08 14:36 - 00000000 ____D C:\Documents and Settings\Najohodo\My Documents\Nate's Army Certificates
2013-06-06 22:16 - 2013-06-25 18:54 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-01 19:02 - 2013-06-01 19:02 - 00000000 ____D C:\Documents and Settings\Najohodo\My Documents\Live! Cam Center
2013-05-30 21:13 - 2013-05-30 21:13 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
2013-05-30 21:12 - 2013-05-30 21:12 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
2013-05-26 20:29 - 2013-06-19 18:04 - 00000000 ____D C:\Documents and Settings\Najohodo\My Documents\Resume Related
2013-05-26 20:27 - 2013-05-26 20:28 - 00000000 ____D C:\Documents and Settings\Najohodo\My Documents\taxes 11, 12

==================== One Month Modified Files and Folders ========

2013-06-25 21:26 - 2013-06-25 21:26 - 00000000 ____D C:\FRST
2013-06-25 21:26 - 2013-06-25 21:25 - 01370251 ____A (Farbar) C:\Documents and Settings\Najohodo\Desktop\FRST.exe
2013-06-25 21:26 - 2010-06-22 04:20 - 00000436 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{1D98A4D2-7DB1-48FB-B7AE-8B55CE506E04}.job
2013-06-25 21:20 - 2004-04-07 12:47 - 00001158 ____A C:\Windows\System32\wpa.dbl
2013-06-25 21:12 - 2012-04-14 10:47 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-25 21:10 - 2000-01-04 05:32 - 01154999 ____A C:\Windows\WindowsUpdate.log
2013-06-25 21:08 - 2013-06-25 21:08 - 00001009 ____A C:\Windows\setupapi.log
2013-06-25 21:08 - 2011-10-13 17:27 - 00000000 ____D C:\Program Files\Common Files\Logitech
2013-06-25 21:08 - 2004-04-07 06:14 - 00000174 ____A C:\Windows\wiadebug.log
2013-06-25 21:05 - 2004-04-07 17:43 - 00000000 ____D C:\Program Files\Common Files\Java
2013-06-25 21:02 - 2010-06-03 02:02 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-25 20:57 - 2013-06-25 20:33 - 00000000 ____D C:\Documents and Settings\Najohodo\Application Data\IObit
2013-06-25 20:35 - 2013-06-25 20:33 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\IObit
2013-06-25 20:33 - 2013-06-25 20:33 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-06-25 20:32 - 2013-06-25 20:32 - 00000000 ____D C:\Program Files\IObit
2013-06-25 20:31 - 2013-06-23 22:26 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-25 19:50 - 2012-01-13 04:02 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\MFAData
2013-06-25 19:05 - 2013-06-25 19:05 - 00021745 ____A C:\Documents and Settings\Najohodo\Desktop\hijackthis.log
2013-06-25 19:02 - 2013-06-25 19:02 - 00388608 ____A (Trend Micro Inc.) C:\Documents and Settings\Najohodo\Desktop\HiJackThis.exe
2013-06-25 18:54 - 2013-06-06 22:16 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-25 17:41 - 2013-06-23 22:26 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-25 17:41 - 1999-12-31 17:01 - 00000062 __ASH C:\Documents and Settings\Najohodo\Local Settings\desktop.ini
2013-06-25 17:16 - 2004-04-07 13:23 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2013-06-25 17:16 - 2004-04-07 13:23 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2013-06-25 17:16 - 2004-04-07 13:19 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-25 17:16 - 2004-04-07 06:14 - 00000049 ____N C:\Windows\wiaservc.log
2013-06-25 17:14 - 2004-04-07 13:23 - 00032390 ____N C:\Windows\SchedLgU.Txt
2013-06-25 17:14 - 1999-12-31 17:01 - 00000278 ___SH C:\Documents and Settings\Najohodo\ntuser.ini
2013-06-24 23:13 - 1999-12-31 17:01 - 00070608 ___AC C:\Documents and Settings\Najohodo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2013-06-24 21:41 - 2011-01-09 23:40 - 00000000 ____D C:\Windows\Minidump
2013-06-24 21:39 - 2013-05-14 23:47 - 00000000 __HDC C:\Windows\$NtUninstallKB2829361$
2013-06-24 21:39 - 2013-04-09 23:01 - 00000000 __HDC C:\Windows\$NtUninstallKB2820917$
2013-06-24 21:39 - 2013-04-09 23:01 - 00000000 __HDC C:\Windows\$NtUninstallKB2808735$
2013-06-24 21:39 - 2013-03-21 22:34 - 00000000 __HDC C:\Windows\$NtUninstallKB2807986$
2013-06-24 21:39 - 2013-02-14 23:37 - 00000000 __HDC C:\Windows\$NtUninstallKB2778344$
2013-06-24 21:39 - 2012-12-12 00:24 - 00000000 __HDC C:\Windows\$NtUninstallKB2779030$
2013-06-24 21:39 - 2012-11-14 00:08 - 00000000 __HDC C:\Windows\$NtUninstallKB2761226$
2013-06-24 21:39 - 2012-11-14 00:08 - 00000000 __HDC C:\Windows\$NtUninstallKB2727528$
2013-06-24 21:39 - 2012-10-10 23:03 - 00000000 __HDC C:\Windows\$NtUninstallKB2749655$
2013-06-24 21:39 - 2012-08-16 00:49 - 00000000 __HDC C:\Windows\$NtUninstallKB2731847$
2013-06-24 21:39 - 2012-07-11 01:00 - 00000000 __HDC C:\Windows\$NtUninstallKB2718523$
2013-06-24 21:38 - 2011-11-10 02:50 - 00000000 __HDC C:\Windows\$NtUninstallWdf01005$
2013-06-24 21:38 - 2010-06-25 13:46 - 00000000 __HDC C:\Windows\$NtUninstallMSCompPackV1$
2013-06-24 21:38 - 2010-06-25 13:43 - 00000000 __HDC C:\Windows\$NtUninstallWudf01000$
2013-06-24 20:51 - 2004-04-07 06:10 - 00267800 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-24 20:38 - 2004-04-07 13:55 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-06-24 20:35 - 2010-06-13 08:31 - 00000000 ____D C:\Program Files\Creative
2013-06-24 19:02 - 2013-06-24 19:02 - 00001542 ____A C:\Documents and Settings\All Users\Desktop\iTunes.lnk
2013-06-24 19:02 - 2013-06-24 19:01 - 00000000 ____D C:\Program Files\iTunes
2013-06-24 19:02 - 2013-06-24 19:01 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-06-24 19:01 - 2013-06-24 19:01 - 00000000 ____D C:\Program Files\iPod
2013-06-24 18:16 - 2013-06-24 18:16 - 00001604 ____A C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
2013-06-24 18:16 - 2013-06-24 18:16 - 00000000 ____D C:\Program Files\QuickTime
2013-06-24 16:43 - 2013-06-24 16:43 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\Sun
2013-06-24 16:12 - 2011-12-02 02:19 - 00000284 ____A C:\Windows\Tasks\AppleSoftwareUpdate.job
2013-06-23 22:27 - 2011-09-29 22:34 - 00000000 ____D C:\Program Files\Google
2013-06-23 22:27 - 2011-09-29 22:34 - 00000000 ____D C:\Documents and Settings\Najohodo\Local Settings\Application Data\Google
2013-06-23 22:27 - 2011-09-29 22:34 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Google
2013-06-23 17:00 - 2013-06-23 17:00 - 00000578 ____A C:\Documents and Settings\Najohodo\My Documents\AutoFix_2013-06-23_17-00-14.txt
2013-06-23 16:41 - 2004-04-07 17:33 - 00000000 ____D C:\Program Files\Notebook Maximizer
2013-06-23 16:40 - 2004-04-07 14:36 - 00000000 ____D C:\Windows\occache
2013-06-23 16:11 - 2010-09-09 07:53 - 00000000 ____D C:\Program Files\Sony
2013-06-23 16:07 - 2012-01-13 04:32 - 00000000 ____D C:\Program Files\AVG
2013-06-23 15:55 - 2012-04-01 20:14 - 00000000 ____D C:\Windows\pss
2013-06-23 15:55 - 2004-04-07 12:48 - 00000211 _RASH C:\boot.ini
2013-06-23 15:55 - 2004-04-07 12:47 - 00000704 ____A C:\Windows\win.ini
2013-06-23 15:55 - 2004-04-07 12:47 - 00000227 ____A C:\Windows\system.ini
2013-06-23 12:56 - 2012-07-03 22:55 - 00012984 ____A C:\Windows\System32\Drivers\SWDUMon.sys
2013-06-19 18:04 - 2013-05-26 20:29 - 00000000 ____D C:\Documents and Settings\Najohodo\My Documents\Resume Related
2013-06-13 13:39 - 2012-12-15 12:48 - 00000000 ____D C:\Documents and Settings\Najohodo\Application Data\Mozilla
2013-06-13 13:35 - 2010-02-27 18:14 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2013-06-13 13:34 - 2011-07-25 01:15 - 00000000 ____D C:\Documents and Settings\Najohodo\Application Data\Skype
2013-06-12 12:06 - 2013-01-19 20:25 - 00000702 ____A C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
2013-06-11 22:40 - 2011-12-14 22:42 - 00000000 ____D C:\Documents and Settings\Najohodo\Application Data\HpUpdate
2013-06-11 22:12 - 2013-06-11 22:12 - 09089416 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2013-06-11 22:12 - 2012-04-14 10:47 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-11 22:12 - 2011-07-25 01:03 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-11 18:19 - 2010-02-27 18:57 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-11 18:18 - 2010-06-08 19:42 - 00000000 ____D C:\Windows\ie8updates
2013-06-11 16:21 - 2012-12-30 21:30 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-06-10 22:41 - 2013-06-10 22:41 - 04717935 ____A C:\Documents and Settings\Najohodo\My Documents\Attachments_2013_06_10.zip
2013-06-09 22:13 - 2011-10-13 12:57 - 00664064 __ASH C:\Documents and Settings\Najohodo\My Documents\Thumbs.db
2013-06-08 17:08 - 2011-12-22 00:05 - 00000000 ____D C:\Documents and Settings\Najohodo\My Documents\MISC
2013-06-08 14:36 - 2013-06-08 14:22 - 00000000 ____D C:\Documents and Settings\Najohodo\My Documents\Nate's Army Certificates
2013-06-01 19:02 - 2013-06-01 19:02 - 00000000 ____D C:\Documents and Settings\Najohodo\My Documents\Live! Cam Center
2013-06-01 19:00 - 2011-12-22 00:04 - 00000000 ____D C:\Documents and Settings\Najohodo\Application Data\Creative
2013-05-30 21:13 - 2013-05-30 21:13 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
2013-05-30 21:12 - 2013-05-30 21:12 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
2013-05-26 20:28 - 2013-05-26 20:27 - 00000000 ____D C:\Documents and Settings\Najohodo\My Documents\taxes 11, 12

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================

Attachments:

Please run the following:

Download ComboFix from the following location:
Link

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 13-06-26.01 - Najohodo 06/26/2013 14:05:15.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.751.472 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG AntiVirus 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Najohodo\WINDOWS
c:\windows\help\wmplayer.bak
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\SET8B.tmp
c:\windows\system32\SET90.tmp
c:\windows\system32\SETDF.tmp
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2013-05-26 to 2013-06-26 )))))))))))))))))))))))))))))))
.
.
2013-06-26 05:18 . 2012-08-23 15:31 32120 —-a-w- c:\windows\system32\TURegOpt.exe
2013-06-26 05:17 . 2013-06-26 05:18 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG
2013-06-26 04:53 . 2013-06-26 04:53 ——– d-sh–w- c:\documents and settings\All Users\Application Data\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-06-26 04:16 . 2008-04-13 16:44 2560 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2013-06-26 04:01 . 2013-06-26 04:01 ——– d—–w- c:\documents and settings\Najohodo\Application Data\SpeedyPC Software
2013-06-26 04:00 . 2013-06-26 04:00 ——– d—–w- c:\program files\Common Files\SpeedyPC Software
2013-06-26 04:00 . 2013-06-26 04:00 ——– d—–w- c:\documents and settings\All Users\Application Data\SpeedyPC Software
2013-06-26 02:37 . 2013-06-26 02:37 ——– d—–w- c:\documents and settings\Najohodo\Application Data\DriverCure
2013-06-26 02:37 . 2013-06-26 02:37 ——– d—–w- c:\documents and settings\Najohodo\Application Data\Foresight Software
2013-06-26 02:37 . 2013-06-26 02:37 ——– d—–w- c:\program files\Common Files\Foresight Software
2013-06-26 02:37 . 2013-06-26 02:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Foresight Software
2013-06-26 01:26 . 2013-06-26 01:26 ——– d—–w- C:\FRST
2013-06-26 00:33 . 2013-06-26 00:33 ——– d—–w- c:\documents and settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-06-26 00:33 . 2013-06-26 00:33 ——– d—–w- c:\documents and settings\Najohodo\AppData
2013-06-26 00:33 . 2013-06-26 00:35 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2013-06-26 00:33 . 2013-06-26 00:57 ——– d—–w- c:\documents and settings\Najohodo\Application Data\IObit
2013-06-26 00:32 . 2013-06-26 00:32 ——– d—–w- c:\program files\IObit
2013-06-24 23:01 . 2013-06-24 23:01 ——– d—–w- c:\program files\iPod
2013-06-24 23:01 . 2013-06-24 23:02 ——– d—–w- c:\program files\iTunes
2013-06-24 23:01 . 2013-06-24 23:02 ——– d—–w- c:\documents and settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-06-24 22:17 . 2013-06-24 22:17 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2013-06-24 22:17 . 2013-06-24 22:16 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2013-06-24 22:17 . 2013-06-24 22:16 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2013-06-24 22:17 . 2013-06-24 22:16 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2013-06-24 22:17 . 2013-06-24 22:16 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2013-06-24 22:16 . 2013-06-24 22:16 ——– d—–w- c:\program files\QuickTime
2013-06-24 20:43 . 2013-06-24 20:43 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Sun
2013-06-12 02:12 . 2013-06-12 02:12 9089416 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-05-31 01:13 . 2013-05-31 01:13 ——– d—–w- c:\documents and settings\All Users\Application Data\SSScanAppDataDir
2013-05-31 01:12 . 2013-05-31 01:12 ——– d—–w- c:\documents and settings\All Users\Application Data\MSScanAppDataDir
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-23 16:56 . 2012-07-04 02:55 12984 —-a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-06-12 02:12 . 2012-04-14 14:47 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 02:12 . 2011-07-25 05:03 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-07 22:30 . 2006-06-23 19:33 920064 —-a-w- c:\windows\system32\wininet.dll
2013-05-07 22:30 . 2004-04-07 16:46 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-05-07 22:30 . 2004-04-07 16:46 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-05-07 21:53 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2013-05-03 01:26 . 2004-04-07 16:47 2193536 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-05-03 00:38 . 2002-08-29 01:04 2070144 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-01 07:59 . 2013-05-01 07:59 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2013-05-01 07:59 . 2013-05-01 07:59 69632 —-a-w- c:\windows\system32\QuickTime.qts
2013-04-10 01:31 . 2004-04-07 16:47 1876352 —-a-w- c:\windows\system32\win32k.sys
2013-04-04 09:36 . 2013-02-16 03:41 866720 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-04-04 09:35 . 2013-02-16 03:41 788896 —-a-w- c:\windows\system32\deployJava1.dll
2013-03-29 06:53 . 2011-12-23 17:32 208184 —-a-w- c:\windows\system32\drivers\avgidsdriverx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2013-06-24 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-01-27 118784]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-26 118843]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2003-12-17 00:49 110592 —-a-w- c:\windows\system32\LgNotify.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2013\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk
backup=c:\windows\pss\RAMASST.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\000StTHK]
2001-06-24 03:28 24576 —-a-w- c:\windows\system32\000StTHK.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00THotkey]
2004-02-25 21:12 258048 —-a-w- c:\windows\system32\00THotkey.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2003-04-18 18:20 88363 —-a-w- c:\windows\agrsmmsg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2003-10-30 23:46 192512 —-a-w- c:\program files\Apoint2K\Apoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-11-02 13:51 59240 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_UI]
2013-04-29 04:58 4408368 —-a-w- c:\program files\AVG\AVG2013\avgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-15 02:17 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-01-27 02:03 155648 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2013-05-31 15:56 152392 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
2003-01-02 23:16 172032 —-a-w- c:\program files\ltmoh\ltmoh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Photobucket Backup]
2013-01-29 18:35 320000 —-a-w- c:\program files\Photobucket Backup\Photobucket.App.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinger]
2005-03-18 00:37 151552 —-a-w- c:\toshiba\Ivp\ISM\pinger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
2003-12-10 10:36 86016 —-a-w- c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2013-05-01 07:59 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reader Library Launcher]
2010-07-12 22:34 906648 —-a-w- c:\program files\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmaTel StacMon]
2003-08-03 23:01 86073 —-a-w- c:\program files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2013-06-24 02:27 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFNF5]
2003-12-02 21:15 73728 —-a-w- c:\windows\system32\TFNF5.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
2003-09-05 10:24 65536 —-a-w- c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TouchED]
2003-01-22 01:00 126976 —-a-w- c:\program files\TOSHIBA\TouchED\TouchED.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
2004-03-03 19:57 278528 —-a-w- c:\windows\system32\TPSMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\V0420Mon.exe]
2007-04-30 01:00 32768 —-a-w- c:\windows\V0420Mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SightSpeed\\SightSpeed.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgdiagex.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 4:50 AM 60216]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [9/21/2012 4:46 AM 245048]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/13/2011 7:30 AM 39224]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 1:32 PM 208184]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 1:32 PM 22328]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/7/2011 7:23 AM 170808]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 2:14 AM 182072]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [4/18/2013 4:34 AM 283136]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service;c:\program files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [8/23/2012 11:31 AM 1532280]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [7/4/2012 3:26 PM 10088]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [5/14/2013 12:54 AM 4937264]
S2 mrtRate;mrtRate; [x]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [12/18/2009 12:58 PM 11336]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [5/13/2011 3:21 AM 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [5/13/2011 3:21 AM 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [5/13/2011 3:21 AM 136808]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [7/3/2012 10:55 PM 12984]
S3 V0420VID;Live! Cam Vista IM (VF0420);c:\windows\system32\drivers\V0420Vid.sys [6/13/2010 8:45 AM 99648]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 02:12]
.
2013-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 23:57]
.
2013-06-26 c:\windows\Tasks\Foresight Software Registration3.job
- c:\program files\Common Files\Foresight Software\UUS3\UUS3.dll [2013-01-15 21:40]
.
2013-06-26 c:\windows\Tasks\Foresight Software Update3.job
- c:\program files\Common Files\Foresight Software\UUS3\Update3.exe [2013-01-15 21:40]
.
2013-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-24 02:26]
.
2013-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-24 02:26]
.
2013-06-26 c:\windows\Tasks\SpeedyPC Pro.job
- c:\documents and settings\Najohodo\My Documents\SpeedyPC\SpeedyPC.exe [2013-05-03 19:38]
.
2013-06-26 c:\windows\Tasks\SpeedyPC Registration3.job
- c:\program files\Common Files\SpeedyPC Software\UUS3\UUS3.dll [2013-05-03 19:38]
.
2013-06-26 c:\windows\Tasks\SpeedyPC Update Version3 Startup Task.job
- c:\program files\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe [2013-05-03 19:38]
.
2013-06-26 c:\windows\Tasks\SpeedyPC Update Version3.job
- c:\program files\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe [2013-05-03 19:38]
.
2013-06-26 c:\windows\Tasks\User_Feed_Synchronization-{1D98A4D2-7DB1-48FB-B7AE-8B55CE506E04}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: advancedmd.com
Trusted Zone: facebook.com\www
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Najohodo\Application Data\Mozilla\Firefox\Profiles\dqw0abg4.default\
FF - prefs.js: browser.search.selectedEngine - Amazon.com
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.switch.threshold - 1000000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: dom.disable_window_status_change - true
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-APSDaemon - c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
MSConfigStartUp-ContentTransferWMDetector - c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe
MSConfigStartUp-DriverUpdate - c:\program files\DriverUpdate\DriverUpdate.exe
MSConfigStartUp-LDM - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
MSConfigStartUp-LogitechQuickCamRibbon - c:\program files\Logitech\QuickCam10\QuickCam10.exe
MSConfigStartUp-LVCOMSX - c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe
MSConfigStartUp-PadTouch - c:\program files\TOSHIBA\Touch and Launch\PadExe.exe
MSConfigStartUp-SmoothView - c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
MSConfigStartUp-TFncKy - TFncKy.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-26 14:11
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(224)
c:\windows\System32\LgNotify.dll
.
Completion time: 2013-06-26 14:13:22
ComboFix-quarantined-files.txt 2013-06-26 18:13
.
Pre-Run: 42,527,055,872 bytes free
Post-Run: 42,999,365,632 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 14857DEA4F081F44D5277D3F927259E8
671B81004FDD1588FA9ED1331C9CECA9
Please run the following:

Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message


NEXT


Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
just want to add that besides being slow, the images on the Facebook site do not load–very strange, just getting the white boxes with the little red x's..seems to be only that site–is there a quick fix for that? thanks!
internet explorer browser and firefox, and yes does it with both–seemed to happen overnight along with the slowing of ev else! here is the log from the JRT: (and now I will do the next item on your list) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Microsoft Windows XP x86 Ran by [removed] on Wed 06/26/2013 at 15:48:35.42 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctl Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctl.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctlsecondary Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctlsecondary.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd} ~~~ Files Successfully deleted: [File] "C:\WINDOWS\system32\turegopt.exe" ~~~ Folders Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\speedypc software" Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\viewpoint" Successfully deleted: [Folder] "C:\Documents and Settings\Najohodo\Application Data\drivercure" Successfully deleted: [Folder] "C:\Documents and Settings\Najohodo\Application Data\speedypc software" Successfully deleted: [Folder] "C:\Program Files\viewpoint" Successfully deleted: [Folder] "C:\Program Files\Common Files\speedypc software" Successfully deleted: [Folder] "C:\Documents and Settings\Najohodo\start menu\programs\speedypc software" ~~~ FireFox Successfully deleted: [File] C:\Documents and Settings\Najohodo\Application Data\mozilla\firefox\profiles\dqw0abg4.default\user.js ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Wed 06/26/2013 at 15:51:28.30 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I clicked download AdwCleaner on that page, then nothing happened.. it opened to another page which was like a magazine page with lots of articles on it–no indication of download–can I just find it via google?
and the second page is in another language!!!–I guess I'll look for that on google–I've been sitting at my pc for 2 1/2 days–I'm so ready to be done, especially since nothing has improved after all the researchand work…aaaAAH! frustrated!!
got it! # AdwCleaner v2.303 - Logfile created 06/26/2013 at 16:34:00 # Updated 08/06/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Najohodo - LITTLELAPTOP # Boot Mode : Normal # Running from : C:\Documents and Settings\Najohodo\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\Software\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9DBB28C1-1925-11D3-A498-00104B6EB52E} Key Deleted : HKLM\Software\MetaStream Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP Key Deleted : HKLM\Software\Viewpoint ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Mozilla Firefox v21.0 (en-US) File : C:\Documents and Settings\Najohodo\Application Data\Mozilla\Firefox\Profiles\dqw0abg4.default\prefs.js [OK] File is clean. -\\ Google Chrome v [Unable to get version] File : C:\Documents and Settings\Najohodo\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [2356 octets] - [26/06/2013 16:34:00] ########## EOF - C:\AdwCleaner[S1].txt - [2416 octets] ##########
OK, for the next direction you gave me,,,I dont have "MalwareBytes AntiMalware" was this supposed to have been downloaded somewhere along the line?? please tell me what to do next,.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI