This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] baseline

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a worm calling itself worm.win32.netbooster. I get a white background on my desktop and continual popup ads on my browser telling me to download a spyware protection program. Also the start button only brings up a few items, missing are items like My computer and anything to do with seeing what is on your computer to fix this. I have run the fix you suggested with the anti-malware program listed and have been able to identify and log the removal of some malware. I have attached the 2 files you requested and would like your opinion of what to do now. Thanks for your forum and your help Mark
Hi mmcfi,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download HijackThis from Here .
  • If using Internet Explorer, Please select RUN
  • If Using Firefox, Download to your Desktop and then Double-Click on Icon to start installation.
  • Choose the default location of C:\Program Files\Trend Micro\HijackThis as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Click the Install button.
  • Accept the license agreement .
  • The progam will place a shortcut on your desktop. This will make it easier for you to access the tool when required.
  • Click Do a system scan and save a log file. A Notepad file will open.
  • To post the text, first you must highlight the entire text and then press the (Ctrl+C) keys which copies it to your clipboard.
  • Now paste the log into this thread using the (Ctrl + V) buttons.


DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS MOST OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER

From now on, please Copy/Paste your logs in this thread (don't attach them)
Thanks for your time. I am having to work through my laptop as the infected desktop is not logging on the internet.

Here is a copy of the hijack this report

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:46 PM, on 9/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking9\Ereg.ini
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB002" /M "Stylus CX5400"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1218425010500
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://www.winkflash.com/photo/loaders/ImageUploader3.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.2.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: txqcxa.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 7388 bytes
mmcfi,


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

MCAFEE ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Exit."
  • a popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard.
You succesfully disabled the McAfee Guard.





C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here are the reports you asked for. Just to clarify I am having to do all of this so far in safe mode as it will not let me access these files in normal mode, just in case this is coloring the outcome.

ComboFix 08-09-15.02 - Administrator 2008-09-16 22:01:20.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.830 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\edvk.exe

.
((((((((((((((((((((((((( Files Created from 2008-08-17 to 2008-09-17 )))))))))))))))))))))))))))))))
.

2008-09-16 21:17 . 2008-09-16 21:17 d——– C:\Program Files\Trend Micro
2008-09-16 18:47 . 2008-09-16 19:40 5,236 –a—— C:\WINDOWS\system32\tmp.reg
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Documents and Settings\Administrator.HOMEOFFICE\Application Data\Malwarebytes
2008-09-16 17:41 . 2008-09-08 00:11 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-16 17:41 . 2008-09-08 00:11 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-16 17:19 . 2008-09-16 18:43 d——– C:\Documents and Settings\Administrator.HOMEOFFICE
2008-09-16 17:07 . 2008-09-16 17:07 136,832 –a—— C:\WINDOWS\system32\suwhiycj.dll
2008-09-16 16:27 . 2008-09-16 17:01 d—s—- C:\Documents and Settings\Administrator
2008-09-16 14:45 . 2008-09-16 17:01 d——– C:\Program Files\Spyware Doctor
2008-09-16 14:32 . 2008-09-16 17:01 d——– C:\WINDOWS\privacy_danger(2)
2008-09-10 12:35 . 2008-09-10 12:35 9,662 –a—— C:\WINDOWS\EPISME00.SWB
2008-09-09 11:03 . 2008-09-09 11:03 d——– C:\CWONDERS
2008-09-09 11:03 . 1994-09-21 00:00 92,208 –a—— C:\WINDOWS\system\WING.DLL
2008-09-09 11:03 . 1994-09-21 00:00 12,800 –a—— C:\WINDOWS\system\WING32.DLL
2008-09-08 21:06 . 2008-09-08 21:13 d——– C:\Program Files\Celestia
2008-09-08 20:59 . 2008-09-08 21:00 d——– C:\Program Files\Stellarium
2008-08-28 11:11 . 2008-08-28 11:11 29 –a—— C:\WINDOWS\DEBUGSM.INI
2008-08-28 11:08 . 2008-08-28 11:08 d——– C:\Program Files\ABBYY FineReader 5.0 Sprint
2008-08-28 11:07 . 2008-08-28 11:07 d——– C:\Program Files\Common Files\Python
2008-08-28 11:07 . 2001-10-19 12:18 708,696 –a—— C:\WINDOWS\system32\python21.dll
2008-08-28 11:07 . 2001-10-19 12:18 290,919 –a—— C:\WINDOWS\system32\pythoncom21.dll
2008-08-28 11:07 . 2001-10-19 12:19 57,344 –a—— C:\WINDOWS\system32\PyWinTypes21.dll
2008-08-28 11:05 . 1999-06-15 11:31 96,768 –a—— C:\WINDOWS\SlantAdj.dll
2008-08-28 11:05 . 1999-12-07 02:03 73,216 –a—— C:\WINDOWS\ADE.DLL
2008-08-28 11:05 . 1999-04-27 00:17 3,136 –a—— C:\WINDOWS\Ade001.bin
2008-08-28 11:05 . 2000-09-08 13:31 72 ——— C:\WINDOWS\system32\epDPE.ini
2008-08-28 11:04 . 2008-08-28 11:07 d——– C:\Program Files\Smart Panel
2008-08-28 11:02 . 2008-08-28 11:08 d——– C:\Program Files\EPSON
2008-08-28 11:02 . 2003-04-02 00:00 217,088 –a—— C:\WINDOWS\system32\ESDTR.dll
2008-08-28 11:02 . 2003-05-28 19:01 91,648 –a—— C:\WINDOWS\system32\E_SAGSET.DLL
2008-08-28 11:02 . 2003-05-22 19:06 73,869 –a—— C:\WINDOWS\system32\EBPMON24.DLL
2008-08-28 11:02 . 2003-05-20 20:27 64,000 –a—— C:\WINDOWS\system32\ECBTEG.DLL
2008-08-28 11:02 . 2001-11-15 00:00 47,104 –a—— C:\WINDOWS\system32\escimgd.dll
2008-08-28 11:02 . 2000-06-06 19:01 34,304 –a—— C:\WINDOWS\system32\EBPCHP.DLL
2008-08-28 11:02 . 2002-06-20 00:00 32,256 –a—— C:\WINDOWS\system32\escwiad.dll
2008-08-28 11:02 . 2002-06-20 00:00 22,528 –a—— C:\WINDOWS\system32\esccmd.dll
2008-08-28 11:02 . 2008-08-28 11:03 19,308 –a—— C:\WINDOWS\EPSTPLOG.BAK
2008-08-28 11:02 . 2001-09-03 20:04 182 –a—— C:\WINDOWS\system32\EBPPORT4.DAT
2008-08-28 11:01 . 2008-08-28 11:02 162 –a—— C:\WINDOWS\EPSON Stylus CX5400.ini
2008-08-27 20:55 . 2008-08-27 20:55 d——– C:\TimezAttack
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\scripting
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\en
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\bits
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\l2schemas
2008-08-27 19:43 . 2008-08-27 19:43 d——– C:\WINDOWS\ServicePackFiles
2008-08-27 19:36 . 2008-08-27 19:36 d——– C:\WINDOWS\EHome
2008-08-27 12:34 . 2008-09-11 13:46 d——– C:\tlcwin
2008-08-27 12:34 . 1994-08-23 22:00 188,960 ——— C:\WINDOWS\system32\Wingde.dll
2008-08-27 12:34 . 1994-09-20 22:00 92,208 ——— C:\WINDOWS\system32\Wing.dll
2008-08-27 12:34 . 1994-09-20 22:00 12,800 ——— C:\WINDOWS\system32\Wing32.dll
2008-08-27 12:34 . 1994-09-20 22:00 6,736 ——— C:\WINDOWS\system32\Wingdib.drv
2008-08-27 12:34 . 1994-09-20 22:00 5,024 ——— C:\WINDOWS\system32\Wingpal.wnd
2008-08-27 12:34 . 2008-09-11 13:47 237 –a—— C:\WINDOWS\TLCAPPS.INI
2008-08-27 12:34 . 2008-08-27 12:41 105 –a—— C:\WINDOWS\E-REGTLC.INI
2008-08-26 08:56 . 2008-04-13 18:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-08-25 16:20 . 2008-08-25 16:20 d——– C:\Program Files\Transparent
2008-08-25 16:20 . 2008-08-25 16:20 d——– C:\Documents and Settings\All Users\Application Data\Transparent
2008-08-25 09:26 . 2008-08-25 09:26 d——– C:\Program Files\Seterra
2008-08-24 18:57 . 2008-08-24 18:57 280 –a—— C:\WINDOWS\EReg196.dat
2008-08-24 18:56 . 2008-08-24 18:56 d——– C:\Program Files\TLI
2008-08-24 15:02 . 2008-08-24 15:02 d——– C:\Program Files\Quickstart Immersion
2008-08-21 14:25 . 2008-08-21 14:25 d——– C:\Program Files\directx
2008-08-21 14:25 . 2008-08-21 14:25 0 –a—— C:\WINDOWS\PowerReg.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-13 21:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-28 17:07 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-25 00:54 ——— d—–w C:\Program Files\Quicken
2008-08-25 00:54 ——— d—–w C:\Program Files\Common Files\Intuit
2008-08-25 00:42 ——— d—–w C:\Program Files\ComcastToolbar
2008-08-20 02:20 ——— d—–w C:\Program Files\Java
2008-08-15 21:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Comcast
2008-08-11 14:41 ——— d—–w C:\Program Files\Google
2008-08-05 22:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-05 22:14 ——— d—–w C:\Program Files\Common Files\McAfee
2008-08-05 22:13 ——— d—–w C:\Program Files\McAfee.com
2008-08-05 18:30 ——— d—–w C:\Program Files\Common Files\Scanner
2008-08-05 16:51 ——— d—–w C:\Program Files\Comcast
2008-08-05 16:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-08-05 16:41 ——— d—–w C:\Program Files\Support.com
2006-06-07 17:00 56 –sh–r C:\WINDOWS\system32\C627C717F1.sys
2007-12-01 01:53 88 –sh–r C:\WINDOWS\system32\F117C727C6.sys
2007-12-01 01:53 4,184 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-04-18 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 8192]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-08 110592]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"WireLessKeyboard"="C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe" [2005-10-23 729088]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"DNS7reminder"="C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" [2006-11-27 255528]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE" [2003-05-26 99840]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 C:\WINDOWS\stsystra.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-18 24576]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-12-31 67128]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=txqcxa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R3 PowerManagerFilter;PowerManagerFilter;C:\WINDOWS\system32\Drivers\PowerManager.sys [2005-10-23 60607]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3437dbb0-7f9a-11dd-9604-001372c4f08f}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6bef156-2cbf-11db-91b1-001372c4f08f}]
\Shell\AutoRun\command - E:\Installer.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-MSKDetectorExe - C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
HKLM-Run-tgcmd - C:\Program Files\Support.com\bin\tgcmd.exe


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R0 -: HKLM-Main,Window Title = Windows Internet Explorer provided by Comcast
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-16 22:05:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-16 22:11:54 - machine was rebooted [Rolf Magnusson]
ComboFix-quarantined-files.txt 2008-09-17 04:11:51

Pre-Run: 136,013,119,488 bytes free
Post-Run: 134,518,530,048 bytes free

203 — E O F — 2008-09-09 21:31:31











Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:14, on 2008-09-16
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking9\Ereg.ini
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB002" /M "Stylus CX5400"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1218425010500
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://www.winkflash.com/photo/loaders/ImageUploader3.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.2.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: txqcxa.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - Unknown owner - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe (file missing)
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe (file missing)
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\Program Files\McAfee\VirusScan\McShield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\Program Files\McAfee\MPF\MPFSrv.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

–
End of file - 8984 bytes


Thanks again
mmcfi,

Please try to do the following in normal mode.

Disable your protection programs as we did before.

Please do the following :

Go to start -> control panel -> Display properties -> Desktop -> Customize Desktop… -> Web tab, then uncheck and delete everything you find in there (except for "My current home page"),

Also remove the checkmark from the the Lock Desktop Items box if it is checked.
Apply.
Apply and Exit Display properties.

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\WINDOWS\system32\tmp.reg
    C:\WINDOWS\system32\suwhiycj.dll
    
    Folder::
    C:\WINDOWS\privacy_danger(2)
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Here are the 3 test results

ComboFix 08-09-15.02 - Administrator 2008-09-16 22:01:20.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.830 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\edvk.exe

.
((((((((((((((((((((((((( Files Created from 2008-08-17 to 2008-09-17 )))))))))))))))))))))))))))))))
.

2008-09-16 21:17 . 2008-09-16 21:17 d——– C:\Program Files\Trend Micro
2008-09-16 18:47 . 2008-09-16 19:40 5,236 –a—— C:\WINDOWS\system32\tmp.reg
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Documents and Settings\Administrator.HOMEOFFICE\Application Data\Malwarebytes
2008-09-16 17:41 . 2008-09-08 00:11 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-16 17:41 . 2008-09-08 00:11 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-16 17:19 . 2008-09-16 18:43 d——– C:\Documents and Settings\Administrator.HOMEOFFICE
2008-09-16 17:07 . 2008-09-16 17:07 136,832 –a—— C:\WINDOWS\system32\suwhiycj.dll
2008-09-16 16:27 . 2008-09-16 17:01 d—s—- C:\Documents and Settings\Administrator
2008-09-16 14:45 . 2008-09-16 17:01 d——– C:\Program Files\Spyware Doctor
2008-09-16 14:32 . 2008-09-16 17:01 d——– C:\WINDOWS\privacy_danger(2)
2008-09-10 12:35 . 2008-09-10 12:35 9,662 –a—— C:\WINDOWS\EPISME00.SWB
2008-09-09 11:03 . 2008-09-09 11:03 d——– C:\CWONDERS
2008-09-09 11:03 . 1994-09-21 00:00 92,208 –a—— C:\WINDOWS\system\WING.DLL
2008-09-09 11:03 . 1994-09-21 00:00 12,800 –a—— C:\WINDOWS\system\WING32.DLL
2008-09-08 21:06 . 2008-09-08 21:13 d——– C:\Program Files\Celestia
2008-09-08 20:59 . 2008-09-08 21:00 d——– C:\Program Files\Stellarium
2008-08-28 11:11 . 2008-08-28 11:11 29 –a—— C:\WINDOWS\DEBUGSM.INI
2008-08-28 11:08 . 2008-08-28 11:08 d——– C:\Program Files\ABBYY FineReader 5.0 Sprint
2008-08-28 11:07 . 2008-08-28 11:07 d——– C:\Program Files\Common Files\Python
2008-08-28 11:07 . 2001-10-19 12:18 708,696 –a—— C:\WINDOWS\system32\python21.dll
2008-08-28 11:07 . 2001-10-19 12:18 290,919 –a—— C:\WINDOWS\system32\pythoncom21.dll
2008-08-28 11:07 . 2001-10-19 12:19 57,344 –a—— C:\WINDOWS\system32\PyWinTypes21.dll
2008-08-28 11:05 . 1999-06-15 11:31 96,768 –a—— C:\WINDOWS\SlantAdj.dll
2008-08-28 11:05 . 1999-12-07 02:03 73,216 –a—— C:\WINDOWS\ADE.DLL
2008-08-28 11:05 . 1999-04-27 00:17 3,136 –a—— C:\WINDOWS\Ade001.bin
2008-08-28 11:05 . 2000-09-08 13:31 72 ——— C:\WINDOWS\system32\epDPE.ini
2008-08-28 11:04 . 2008-08-28 11:07 d——– C:\Program Files\Smart Panel
2008-08-28 11:02 . 2008-08-28 11:08 d——– C:\Program Files\EPSON
2008-08-28 11:02 . 2003-04-02 00:00 217,088 –a—— C:\WINDOWS\system32\ESDTR.dll
2008-08-28 11:02 . 2003-05-28 19:01 91,648 –a—— C:\WINDOWS\system32\E_SAGSET.DLL
2008-08-28 11:02 . 2003-05-22 19:06 73,869 –a—— C:\WINDOWS\system32\EBPMON24.DLL
2008-08-28 11:02 . 2003-05-20 20:27 64,000 –a—— C:\WINDOWS\system32\ECBTEG.DLL
2008-08-28 11:02 . 2001-11-15 00:00 47,104 –a—— C:\WINDOWS\system32\escimgd.dll
2008-08-28 11:02 . 2000-06-06 19:01 34,304 –a—— C:\WINDOWS\system32\EBPCHP.DLL
2008-08-28 11:02 . 2002-06-20 00:00 32,256 –a—— C:\WINDOWS\system32\escwiad.dll
2008-08-28 11:02 . 2002-06-20 00:00 22,528 –a—— C:\WINDOWS\system32\esccmd.dll
2008-08-28 11:02 . 2008-08-28 11:03 19,308 –a—— C:\WINDOWS\EPSTPLOG.BAK
2008-08-28 11:02 . 2001-09-03 20:04 182 –a—— C:\WINDOWS\system32\EBPPORT4.DAT
2008-08-28 11:01 . 2008-08-28 11:02 162 –a—— C:\WINDOWS\EPSON Stylus CX5400.ini
2008-08-27 20:55 . 2008-08-27 20:55 d——– C:\TimezAttack
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\scripting
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\en
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\bits
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\l2schemas
2008-08-27 19:43 . 2008-08-27 19:43 d——– C:\WINDOWS\ServicePackFiles
2008-08-27 19:36 . 2008-08-27 19:36 d——– C:\WINDOWS\EHome
2008-08-27 12:34 . 2008-09-11 13:46 d——– C:\tlcwin
2008-08-27 12:34 . 1994-08-23 22:00 188,960 ——— C:\WINDOWS\system32\Wingde.dll
2008-08-27 12:34 . 1994-09-20 22:00 92,208 ——— C:\WINDOWS\system32\Wing.dll
2008-08-27 12:34 . 1994-09-20 22:00 12,800 ——— C:\WINDOWS\system32\Wing32.dll
2008-08-27 12:34 . 1994-09-20 22:00 6,736 ——— C:\WINDOWS\system32\Wingdib.drv
2008-08-27 12:34 . 1994-09-20 22:00 5,024 ——— C:\WINDOWS\system32\Wingpal.wnd
2008-08-27 12:34 . 2008-09-11 13:47 237 –a—— C:\WINDOWS\TLCAPPS.INI
2008-08-27 12:34 . 2008-08-27 12:41 105 –a—— C:\WINDOWS\E-REGTLC.INI
2008-08-26 08:56 . 2008-04-13 18:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-08-25 16:20 . 2008-08-25 16:20 d——– C:\Program Files\Transparent
2008-08-25 16:20 . 2008-08-25 16:20 d——– C:\Documents and Settings\All Users\Application Data\Transparent
2008-08-25 09:26 . 2008-08-25 09:26 d——– C:\Program Files\Seterra
2008-08-24 18:57 . 2008-08-24 18:57 280 –a—— C:\WINDOWS\EReg196.dat
2008-08-24 18:56 . 2008-08-24 18:56 d——– C:\Program Files\TLI
2008-08-24 15:02 . 2008-08-24 15:02 d——– C:\Program Files\Quickstart Immersion
2008-08-21 14:25 . 2008-08-21 14:25 d——– C:\Program Files\directx
2008-08-21 14:25 . 2008-08-21 14:25 0 –a—— C:\WINDOWS\PowerReg.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-13 21:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-28 17:07 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-25 00:54 ——— d—–w C:\Program Files\Quicken
2008-08-25 00:54 ——— d—–w C:\Program Files\Common Files\Intuit
2008-08-25 00:42 ——— d—–w C:\Program Files\ComcastToolbar
2008-08-20 02:20 ——— d—–w C:\Program Files\Java
2008-08-15 21:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Comcast
2008-08-11 14:41 ——— d—–w C:\Program Files\Google
2008-08-05 22:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-05 22:14 ——— d—–w C:\Program Files\Common Files\McAfee
2008-08-05 22:13 ——— d—–w C:\Program Files\McAfee.com
2008-08-05 18:30 ——— d—–w C:\Program Files\Common Files\Scanner
2008-08-05 16:51 ——— d—–w C:\Program Files\Comcast
2008-08-05 16:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-08-05 16:41 ——— d—–w C:\Program Files\Support.com
2006-06-07 17:00 56 –sh–r C:\WINDOWS\system32\C627C717F1.sys
2007-12-01 01:53 88 –sh–r C:\WINDOWS\system32\F117C727C6.sys
2007-12-01 01:53 4,184 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-04-18 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 8192]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-08 110592]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"WireLessKeyboard"="C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe" [2005-10-23 729088]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"DNS7reminder"="C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" [2006-11-27 255528]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE" [2003-05-26 99840]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 C:\WINDOWS\stsystra.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-18 24576]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-12-31 67128]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=txqcxa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R3 PowerManagerFilter;PowerManagerFilter;C:\WINDOWS\system32\Drivers\PowerManager.sys [2005-10-23 60607]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3437dbb0-7f9a-11dd-9604-001372c4f08f}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6bef156-2cbf-11db-91b1-001372c4f08f}]
\Shell\AutoRun\command - E:\Installer.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-MSKDetectorExe - C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
HKLM-Run-tgcmd - C:\Program Files\Support.com\bin\tgcmd.exe


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R0 -: HKLM-Main,Window Title = Windows Internet Explorer provided by Comcast
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-16 22:05:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-16 22:11:54 - machine was rebooted [Rolf Magnusson]
ComboFix-quarantined-files.txt 2008-09-17 04:11:51

Pre-Run: 136,013,119,488 bytes free
Post-Run: 134,518,530,048 bytes free

203 — E O F — 2008-09-09 21:31:31






——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, September 17, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, September 17, 2008 19:12:25
Records in database: 1246182
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 80960
Threat name: 2
Infected objects: 5
Suspicious objects: 0
Duration of the scan: 01:19:01


File name / Threat name / Threats count
C:\Documents and Settings\Administrator.HOMEOFFICE\Desktop\Fix backups\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Administrator.HOMEOFFICE\Desktop\Fix backups\SmitfraudFix.zip Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Program Files\MUSICMATCH\Common\ComponentMgr\HoldingArea\WebSys2\WebSys.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\WebSys\offline.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
E:\SmitfraudFix.zip Infected: not-a-virus:RiskTool.Win32.Reboot.f 1

The selected area was scanned.





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:47, on 2008-09-17
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking9\Ereg.ini
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB002" /M "Stylus CX5400"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1218425010500
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://www.winkflash.com/photo/loaders/ImageUploader3.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.2.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - Unknown owner - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe (file missing)
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe (file missing)
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\Program Files\McAfee\VirusScan\McShield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\Program Files\McAfee\MPF\MPFSrv.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 8859 bytes
I did run it the way you said to, I am not sure what happened so I ran it again. i am in the process of running the other 2 if you need them. sorry



ComboFix 08-09-16.05 - Rolf Magnusson 2008-09-17 18:48:18.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.677 [GMT -6:00]
Running from: E:\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rolf Magnusson\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-08-18 to 2008-09-18 )))))))))))))))))))))))))))))))
.

2008-09-16 21:17 . 2008-09-16 21:17 d——– C:\Program Files\Trend Micro
2008-09-16 17:59 . 2008-09-16 17:59 d——– C:\Documents and Settings\Rolf Magnusson\Application Data\Malwarebytes
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Documents and Settings\Administrator.HOMEOFFICE\Application Data\Malwarebytes
2008-09-16 17:41 . 2008-09-08 00:11 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-16 17:41 . 2008-09-08 00:11 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-16 17:19 . 2008-09-16 18:43 d——– C:\Documents and Settings\Administrator.HOMEOFFICE
2008-09-16 16:27 . 2008-09-16 17:01 d—s—- C:\Documents and Settings\Administrator
2008-09-16 14:45 . 2008-09-16 17:01 d——– C:\Program Files\Spyware Doctor
2008-09-10 18:44 . 2008-09-10 18:45 d——– C:\Documents and Settings\Rolf Magnusson\Application Data\U3
2008-09-10 12:35 . 2008-09-10 12:35 9,662 –a—— C:\WINDOWS\EPISME00.SWB
2008-09-09 11:03 . 2008-09-09 11:03 d——– C:\CWONDERS
2008-09-09 11:03 . 1994-09-21 00:00 92,208 –a—— C:\WINDOWS\system\WING.DLL
2008-09-09 11:03 . 1994-09-21 00:00 12,800 –a—— C:\WINDOWS\system\WING32.DLL
2008-09-08 21:06 . 2008-09-08 21:13 d——– C:\Program Files\Celestia
2008-09-08 21:01 . 2008-09-08 21:01 d——– C:\Documents and Settings\Rolf Magnusson\Application Data\Stellarium
2008-09-08 20:59 . 2008-09-08 21:00 d——– C:\Program Files\Stellarium
2008-08-28 11:11 . 2008-08-28 11:11 d——– C:\Documents and Settings\Rolf Magnusson\Application Data\Smart Panel
2008-08-28 11:11 . 2008-08-28 11:11 29 –a—— C:\WINDOWS\DEBUGSM.INI
2008-08-28 11:08 . 2008-08-28 11:08 d——– C:\Program Files\ABBYY FineReader 5.0 Sprint
2008-08-28 11:07 . 2008-08-28 11:07 d——– C:\Program Files\Common Files\Python
2008-08-28 11:07 . 2001-10-19 12:18 708,696 –a—— C:\WINDOWS\system32\python21.dll
2008-08-28 11:07 . 2001-10-19 12:18 290,919 –a—— C:\WINDOWS\system32\pythoncom21.dll
2008-08-28 11:07 . 2001-10-19 12:19 57,344 –a—— C:\WINDOWS\system32\PyWinTypes21.dll
2008-08-28 11:05 . 1999-06-15 11:31 96,768 –a—— C:\WINDOWS\SlantAdj.dll
2008-08-28 11:05 . 1999-12-07 02:03 73,216 –a—— C:\WINDOWS\ADE.DLL
2008-08-28 11:05 . 1999-04-27 00:17 3,136 –a—— C:\WINDOWS\Ade001.bin
2008-08-28 11:05 . 2000-09-08 13:31 72 ——— C:\WINDOWS\system32\epDPE.ini
2008-08-28 11:04 . 2008-08-28 11:07 d——– C:\Program Files\Smart Panel
2008-08-28 11:02 . 2008-08-28 11:08 d——– C:\Program Files\EPSON
2008-08-28 11:02 . 2003-04-02 00:00 217,088 –a—— C:\WINDOWS\system32\ESDTR.dll
2008-08-28 11:02 . 2003-05-28 19:01 91,648 –a—— C:\WINDOWS\system32\E_SAGSET.DLL
2008-08-28 11:02 . 2003-05-22 19:06 73,869 –a—— C:\WINDOWS\system32\EBPMON24.DLL
2008-08-28 11:02 . 2003-05-20 20:27 64,000 –a—— C:\WINDOWS\system32\ECBTEG.DLL
2008-08-28 11:02 . 2001-11-15 00:00 47,104 –a—— C:\WINDOWS\system32\escimgd.dll
2008-08-28 11:02 . 2000-06-06 19:01 34,304 –a—— C:\WINDOWS\system32\EBPCHP.DLL
2008-08-28 11:02 . 2002-06-20 00:00 32,256 –a—— C:\WINDOWS\system32\escwiad.dll
2008-08-28 11:02 . 2002-06-20 00:00 22,528 –a—— C:\WINDOWS\system32\esccmd.dll
2008-08-28 11:02 . 2008-08-28 11:03 19,308 –a—— C:\WINDOWS\EPSTPLOG.BAK
2008-08-28 11:02 . 2001-09-03 20:04 182 –a—— C:\WINDOWS\system32\EBPPORT4.DAT
2008-08-28 11:01 . 2008-08-28 11:02 162 –a—— C:\WINDOWS\EPSON Stylus CX5400.ini
2008-08-27 20:55 . 2008-08-27 20:55 d——– C:\TimezAttack
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\scripting
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\en
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\bits
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\l2schemas
2008-08-27 19:43 . 2008-08-27 19:43 d——– C:\WINDOWS\ServicePackFiles
2008-08-27 19:36 . 2008-08-27 19:36 d——– C:\WINDOWS\EHome
2008-08-27 12:34 . 2008-09-11 13:46 d——– C:\tlcwin
2008-08-27 12:34 . 1994-08-23 22:00 188,960 ——— C:\WINDOWS\system32\Wingde.dll
2008-08-27 12:34 . 1994-09-20 22:00 92,208 ——— C:\WINDOWS\system32\Wing.dll
2008-08-27 12:34 . 1994-09-20 22:00 12,800 ——— C:\WINDOWS\system32\Wing32.dll
2008-08-27 12:34 . 1994-09-20 22:00 6,736 ——— C:\WINDOWS\system32\Wingdib.drv
2008-08-27 12:34 . 1994-09-20 22:00 5,024 ——— C:\WINDOWS\system32\Wingpal.wnd
2008-08-27 12:34 . 2008-09-11 13:47 237 –a—— C:\WINDOWS\TLCAPPS.INI
2008-08-27 12:34 . 2008-08-27 12:41 105 –a—— C:\WINDOWS\E-REGTLC.INI
2008-08-26 08:56 . 2008-04-13 18:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-08-25 16:20 . 2008-08-25 16:20 d——– C:\Program Files\Transparent
2008-08-25 16:20 . 2008-08-25 16:20 d——– C:\Documents and Settings\All Users\Application Data\Transparent
2008-08-25 09:26 . 2008-08-25 09:26 d——– C:\Program Files\Seterra
2008-08-24 18:57 . 2008-08-24 18:57 280 –a—— C:\WINDOWS\EReg196.dat
2008-08-24 18:56 . 2008-08-24 18:56 d——– C:\Program Files\TLI
2008-08-24 15:02 . 2008-08-24 15:02 d——– C:\Program Files\Quickstart Immersion
2008-08-21 14:25 . 2008-08-21 14:25 d——– C:\Program Files\directx
2008-08-21 14:25 . 2008-08-21 14:25 0 –a—— C:\WINDOWS\PowerReg.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 18:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-28 17:07 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-25 00:54 ——— d—–w C:\Program Files\Quicken
2008-08-25 00:54 ——— d—–w C:\Program Files\Common Files\Intuit
2008-08-25 00:42 ——— d—–w C:\Program Files\ComcastToolbar
2008-08-20 02:20 ——— d—–w C:\Program Files\Java
2008-08-15 21:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Comcast
2008-08-11 14:41 ——— d—–w C:\Program Files\Google
2008-08-05 22:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-05 22:14 ——— d—–w C:\Program Files\Common Files\McAfee
2008-08-05 22:13 ——— d—–w C:\Program Files\McAfee.com
2008-08-05 18:30 ——— d—–w C:\Program Files\Common Files\Scanner
2008-08-05 17:15 ——— d—–w C:\Documents and Settings\Rolf Magnusson\Application Data\McAfee
2008-08-05 16:51 ——— d—–w C:\Program Files\Comcast
2008-08-05 16:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-08-05 16:41 ——— d—–w C:\Program Files\Support.com
2008-07-19 04:10 94,920 —-a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 04:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 04:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 04:10 53,448 —-a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 04:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 04:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 04:10 36,552 —-a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 04:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 04:09 563,912 —-a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 04:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 04:09 325,832 —-a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 04:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 04:09 205,000 —-a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 04:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 04:09 1,811,656 —-a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 04:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 04:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:26 253,952 ——w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:57 3,592,192 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-24 16:43 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ——w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-23 09:20 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:46 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46 245,248 ——w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46 147,968 ——w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ——w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ——w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-01-25 17:11 1,995 —-a-w C:\Documents and Settings\Rolf Magnusson\Application Data\SAS7_000.DAT
2006-06-07 17:00 56 –sh–r C:\WINDOWS\system32\C627C717F1.sys
2007-12-01 01:53 88 –sh–r C:\WINDOWS\system32\F117C727C6.sys
2007-12-01 01:53 4,184 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-04-18 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 8192]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-08 110592]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"WireLessKeyboard"="C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe" [2005-10-23 729088]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"DNS7reminder"="C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" [2006-11-27 255528]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE" [2003-05-26 99840]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 C:\WINDOWS\stsystra.exe]

C:\Documents and Settings\Rolf Magnusson\Start Menu\Programs\Startup\
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1996-11-17 111376]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1996-11-17 51984]
PowerReg Scheduler.exe [2008-08-21 256000]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-18 24576]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-12-31 67128]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R3 PowerManagerFilter;PowerManagerFilter;C:\WINDOWS\system32\Drivers\PowerManager.sys [2005-10-23 60607]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3437dbb0-7f9a-11dd-9604-001372c4f08f}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6bef156-2cbf-11db-91b1-001372c4f08f}]
\Shell\AutoRun\command - E:\Installer.exe
.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-17 18:51:30
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


C:\WINDOWS\TEMP\znj20jd2.TMP

scan completed successfully
hidden files: 1

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-17 18:57:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-18 00:57:04
ComboFix2.txt 2008-09-17 18:17:15
ComboFix3.txt 2008-09-17 04:11:55

Pre-Run: 134,545,731,584 bytes free
Post-Run: 134,585,454,592 bytes free

224 — E O F — 2008-09-09 21:31:31
mmcfi, The first two logs both are dated the same date and time and say they are the first run of ComboFix. The last one you posted is a different date and says it is the third time Combofix has been run. The important thing is the entries are now gone and you look clean. How's it running? If it looks good to you I'll give you some housekeeping directions.
Things seem to be going well right now. Thanks for all your help. This is a new computer for us and I have not been able to set up much protection items yet. Just relying on the Mcafee which I do not particularly care for. I would love some suggestions. Secondly, Is there any value to running something like what we have just done to another computer that does not have this problem but is running slower than expected? Thanks again for your time and help
mmcfi,

I would love some suggestions.

Here are 3 free anti-virus programs that are considered very good.
1) Antivir PersonalEditionClassic
-Free anti-virus software for Windows.
-Detects and removes more than 50,000 viruses. Free support.
2) avast! 4 Home Edition
-Anti-virus program for Windows.
-The home edition is freeware for noncommercial user
3) AVG Anti-Virus Free Edition
- Free edition of the AVG anti-virus program for Windows.
- Available for single computer use for home and non commercial use.

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.

To first finish up with your current computer:


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please re-enable any security that was disabled.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Secondly, Is there any value to running something like what we have just done to another computer that does not have this problem but is running slower than expected?

Please don't. ComboFix can absolutely ruin your computer if you do the wrong thing with it. Other tools we ran are OK.

I would suggest that you post a HijackThis log here from your other computer and let me have a look at it.
I finished up with the first computer and am currently installing AVG and other suggested items on it.

Here is a hijack this log of my laptop, thanks for taking a look.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:23 PM, on 9/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\PROGRA~1\Comodo\CBOClean\BOC424.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lds.org/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [BOC-424] C:\PROGRA~1\Comodo\CBOClean\BOC424.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400 (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P28 "EPSON Stylus CX5400 (Copy 1)" /O20 "\\HOMEOFFICE\Printer" /M "Stylus CX5400"
O4 - HKLM\..\Run: [EPSON Stylus CX5400 direct link] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P31 "EPSON Stylus CX5400 direct link" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [\\family\EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P28 "\\family\EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [EPSON Stylus CX5400 direct link] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P31 "EPSON Stylus CX5400 direct link" /M "Stylus CX5400" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=laptop
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support2.charter.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1131562252015
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9294206B-A9B2-4F73-938E-89F694F48101} - http://xlonhcld.xlontech.net/100348/movemi…4/ldsdlprod.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://www.winkflash.com/photo/loaders/ImageUploader3.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://kingsoopers.digitalcameradeveloping…ploadClient.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {C6D25826-96AE-462F-A852-BB33B882B723} (SFImageUpload1_4.ImageUpload) - http://kingsoopers.storefront.com/images/g…geUpload1_4.CAB
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) - http://entriq.vo.llnwd.net/o1/NBCUniversal…eck_1_0_0_4.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - http://entriq.vo.llnwd.net/o1/NBCUniversal…0_15_Silent.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://xlonhcld.xlontech.net/100348/qmpbet…2ie05100202.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://wwemail.support.hp.com/fd2/objects/SysQuery.cab
O16 - DPF: {FC6703A7-5B7E-4f58-BE6D-2693AA3906AE} (HP Content Update) - http://h30043.www3.hp.com/netassist/en/che…hp.cab?1,0,0,94
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 10479 bytes
mmcfi,

I'm not seeing alot bad going on there. Lets run a couple of basic tools.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment. Is it only slow or do you have any other symptoms?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI