This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hjt will not run

95 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

You're welcome.


that avg program was running when i had the problem last time. any suggestions?


I can suggest another free AntiVirus instead of AVG if you want.



Also please post the ComboFix log.
sorry , i thought i posted the combofix log. here it is

yes, i would like for you to suggest another anti virus program,

j-a



ComboFix 08-12-28.04 - HP_Owner 2008-12-29 18:37:36.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.108 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\HP_Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated)
* Created a new restore point

FILE ::
c:\documents and settings\HP_Owner\Application Data\Microsoft\Windows\rjdyn.exe
c:\windows\system32\cccIknmp.ini
c:\windows\system32\cccIknmp.ini2
c:\windows\system32\dcarboet.dll
c:\windows\system32\digeste.dll
c:\windows\system32\hgGvtUKA.dll
c:\windows\system32\mlJYoppQ.dll
c:\windows\system32\npqgatst.dll
c:\windows\system32\pmnkIccc.dll
c:\windows\system32\ssqNDvwW.dll
c:\windows\system32\tstagqpn.ini
c:\windows\system32\vmdtms.dll
c:\windows\tasks\uymozobr.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\HP_Owner\Application Data\gadcom
c:\documents and settings\HP_Owner\Application Data\gadcom\gadcom.exe
c:\documents and settings\HP_Owner\Application Data\SpeedRunner
c:\documents and settings\HP_Owner\Application Data\SpeedRunner\config.cfg
c:\documents and settings\HP_Owner\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\system32\cccIknmp.ini
c:\windows\system32\cccIknmp.ini2
c:\windows\system32\dcarboet.dll
c:\windows\system32\digeste.dll
c:\windows\system32\dqwejy.dll
c:\windows\system32\gscruhjj.dll
c:\windows\system32\hgGvtUKA.dll
c:\windows\system32\huamoclo.ini
c:\windows\system32\mlJYoppQ.dll
c:\windows\system32\olcomauh.dll
c:\windows\system32\pmnkIccc.dll
c:\windows\system32\ssqNDvwW.dll
c:\windows\system32\tstagqpn.ini
c:\windows\system32\vmdtms.dll
c:\windows\tasks\uymozobr.job
c:\windows\wiaserviv.log

—– BITS: Possible infected sites —–

hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.

2008-12-22 08:11 . 2008-12-22 08:11 d——– c:\program files\SUPERAntiSpyware
2008-12-22 08:11 . 2008-12-22 08:11 d——– c:\documents and settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2008-12-22 08:11 . 2008-12-22 08:11 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-21 13:42 . 2008-12-21 13:42 d——– C:\_OTMoveIt
2008-12-20 11:18 . 2008-12-27 20:10 d——– C:\rsit
2008-12-20 11:18 . 2008-12-27 20:04 d——– c:\program files\trend micro
2008-12-18 08:37 . 2008-12-18 08:37 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-18 08:37 . 2008-12-18 08:37 d——– c:\documents and settings\HP_Owner\Application Data\Malwarebytes
2008-12-18 08:37 . 2008-12-18 08:37 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-18 08:37 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-18 08:37 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-16 19:35 . 2008-12-16 19:58 d——– c:\documents and settings\HP_Owner\DoctorWeb
2008-12-11 10:13 . 2008-12-11 10:13 d——– c:\program files\Microsoft Silverlight
2008-12-10 20:39 . 2008-12-29 18:16 d–h—– C:\$AVG8.VAULT$
2008-12-10 20:28 . 2008-12-10 20:28 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-12-10 20:28 . 2008-12-10 20:28 76,040 –a—— c:\windows\system32\drivers\avgtdix.sys
2008-12-10 20:28 . 2008-12-10 20:28 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-12-10 19:31 . 2008-12-11 09:32 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-10 19:30 . 2008-12-11 09:29 d——– c:\program files\SpywareBlaster
2008-12-10 12:49 . 2008-12-10 12:49 d——– c:\documents and settings\HP_Owner\Application Data\Webroot
2008-12-10 11:57 . 2008-12-10 20:28 d——– c:\windows\system32\drivers\Avg
2008-12-10 11:57 . 2008-12-10 11:57 d——– c:\program files\AVG
2008-12-10 11:57 . 2008-12-10 20:30 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-10 11:19 . 2008-12-10 11:19 d——– c:\program files\Webroot
2008-12-06 15:13 . 2008-12-06 15:13 d——– c:\documents and settings\HP_Owner\Application Data\LaCie
2008-12-06 15:02 . 2008-12-06 15:02 d——– c:\program files\LaCie
2008-12-05 21:13 . 2008-12-05 21:13 d——– c:\program files\Common Files\Scanner
2008-12-05 21:13 . 2008-12-05 22:04 d——– c:\program files\CA Yahoo! Anti-Spy
2008-12-05 19:00 . 2008-12-05 19:00 d——– c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-05 19:00 . 2008-12-05 19:00 262,144 –a—— C:\ntuser.dat
2008-12-05 18:59 . 2008-12-05 19:00 d——– c:\documents and settings\HP_Owner\Application Data\Yahoo!
2008-12-05 18:59 . 2008-12-05 18:59 d——– c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-12-04 22:41 . 2005-10-18 20:36 d——– c:\documents and settings\Administrator\WINDOWS
2008-12-04 22:41 . 2008-12-04 22:41 d——– c:\documents and settings\Administrator
2008-12-03 22:26 . 2008-12-03 23:04 d——– c:\windows\SxsCaPendDel
2008-12-02 22:01 . 2008-12-02 22:04 d——– c:\program files\Windows Live Safety Center
2008-12-02 11:17 . 2008-12-02 11:20 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-01 21:12 . 2008-12-15 13:49 d——– c:\documents and settings\HP_Owner\Application Data\Twain

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 23:58 ——— d—–w c:\program files\Symantec AntiVirus
2008-12-22 13:09 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-21 18:37 ——— d—–w c:\program files\Java
2008-12-21 15:31 ——— d—–w c:\program files\Symantec
2008-12-21 15:22 ——— d—–w c:\program files\AIM
2008-12-21 15:22 ——— d—–w c:\documents and settings\HP_Owner\Application Data\Aim
2008-12-06 00:00 ——— d—–w c:\program files\Yahoo!
2008-12-04 03:25 ——— d—–w c:\program files\OpenOffice.org 3
2008-12-02 16:18 ——— d—–w c:\program files\Lavasoft
2008-12-02 16:18 ——— d—–w c:\documents and settings\HP_Owner\Application Data\Lavasoft
2008-12-01 23:16 ——— d—–w c:\program files\IntelliMover Data Transfer Demo
2008-12-01 23:14 ——— d—–w c:\program files\Bonjour
2008-12-01 21:06 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-30 22:21 ——— d–h–w c:\documents and settings\HP_Owner\Application Data\Move Networks
2008-11-26 21:32 ——— d—–w c:\program files\AIM6
2008-11-26 20:43 ——— d—–w c:\program files\Common Files\Software Update Utility
2008-11-26 20:43 ——— d—–w c:\documents and settings\All Users\Application Data\acccore
2008-11-26 20:42 ——— d—–w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-22 17:03 ——— d—–w c:\program files\Common Files\Adobe
2008-11-22 15:38 ——— d—–w c:\documents and settings\HP_Owner\Application Data\OpenOffice.org
2008-11-12 11:52 ——— d—–w c:\program files\Apple Software Update
2008-11-11 15:01 ——— d—–w c:\program files\iTunes
2008-11-11 15:01 ——— d—–w c:\program files\iPod
2008-11-11 15:01 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-11 14:59 ——— d—–w c:\program files\QuickTime
2008-11-11 14:58 ——— d—–w c:\program files\Common Files\Apple
2008-11-07 23:02 ——— d—–w c:\program files\DivX
2005-10-19 03:14 158 —-a-w c:\documents and settings\HP_Owner\Application Data\wklnhst.dat
2008-12-22 13:05 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-22 13:05 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-22 13:05 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-22 13:05 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-22 13:05 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( snapshot@2008-12-15_14.03.49.73 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-22 09:47:25 62,976 —-a-w c:\windows\$hf_mig$\KB955839\SP2QFE\tzchange.exe
+ 2008-10-23 10:06:59 62,976 —-a-w c:\windows\$hf_mig$\KB955839\SP3GDR\tzchange.exe
+ 2008-10-23 10:17:49 62,976 —-a-w c:\windows\$hf_mig$\KB955839\SP3QFE\tzchange.exe
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB955839\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB955839\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB955839\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB955839\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB955839\update\updspapi.dll
+ 2008-10-23 12:51:04 284,160 —-a-w c:\windows\$hf_mig$\KB956802\SP2QFE\gdi32.dll
+ 2008-10-23 12:36:14 286,720 —-a-w c:\windows\$hf_mig$\KB956802\SP3GDR\gdi32.dll
+ 2008-10-23 12:43:42 286,720 —-a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
+ 2008-07-08 13:02:01 17,272 —-a-w c:\windows\$hf_mig$\KB956802\spmsg.dll
+ 2008-07-08 13:02:02 231,288 —-a-w c:\windows\$hf_mig$\KB956802\spuninst.exe
+ 2008-07-08 13:02:01 26,488 —-a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w c:\windows\$hf_mig$\KB956802\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll
+ 2008-08-26 07:24:28 124,928 -c—-w c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2008-08-26 07:24:28 347,136 -c—-w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2008-08-26 07:24:28 214,528 -c—-w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2008-08-26 07:24:28 133,120 -c—-w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2008-08-26 07:24:28 63,488 -c—-w c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2008-08-25 08:37:59 70,656 -c—-w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2008-08-26 07:24:28 153,088 -c—-w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2008-08-26 07:24:28 230,400 -c—-w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2008-08-23 05:54:51 161,792 -c—-w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2008-08-26 07:24:28 383,488 -c—-w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2008-08-26 07:24:29 384,512 -c—-w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2008-10-03 17:41:15 6,066,176 -c—-w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2008-08-26 07:24:29 44,544 -c—-w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2008-08-26 07:24:29 267,776 -c—-w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2008-08-25 08:38:00 13,824 -c—-w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2008-08-23 05:56:15 635,848 -c—-w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2008-08-26 07:24:30 27,648 -c—-w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2008-08-26 07:24:30 459,264 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2008-08-26 07:24:30 52,224 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2008-08-27 08:24:32 3,593,216 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtml.dll
+ 2008-08-26 07:24:30 477,696 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2008-08-26 07:24:30 193,024 -c—-w c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2008-08-26 07:24:30 671,232 -c—-w c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2008-08-26 07:24:30 102,912 -c—-w c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2008-08-26 07:24:30 44,544 -c—-w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2008-08-26 07:24:30 105,984 -c—-w c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2008-08-26 07:24:31 1,159,680 -c—-w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2008-08-26 07:24:31 233,472 -c—-w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2008-08-26 07:24:31 826,368 -c—-w c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2008-10-17 07:08:40 3,593,216 -c—-w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c—-w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
+ 2008-12-22 13:11:31 18,944 —-a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-12-22 13:11:31 65,024 —-a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
- 2008-08-26 07:24:28 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2008-10-16 20:38:34 124,928 —-a-w c:\windows\system32\advpack.dll
- 2008-12-15 18:36:46 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-28 18:00:55 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-15 18:36:46 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-28 18:00:44 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-27 17:01:38 78,924 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
+ 2008-12-28 18:00:44 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-08-26 07:24:28 124,928 ——w c:\windows\system32\dllcache\advpack.dll
+ 2008-10-16 20:38:34 124,928 —-a-w c:\windows\system32\dllcache\advpack.dll
- 2008-08-26 07:24:28 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 —-a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 —-a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-26 07:24:28 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 20:38:35 133,120 —-a-w c:\windows\system32\dllcache\extmgr.dll
- 2008-02-20 06:51:05 282,624 —-a-w c:\windows\system32\dllcache\gdi32.dll
+ 2008-10-23 13:01:36 283,648 —-a-w c:\windows\system32\dllcache\gdi32.dll
- 2008-08-26 07:24:28 63,488 ——w c:\windows\system32\dllcache\icardie.dll
+ 2008-10-16 20:38:35 63,488 —-a-w c:\windows\system32\dllcache\icardie.dll
- 2008-08-25 08:37:59 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 —-a-w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 —-a-w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-26 07:24:28 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 —-a-w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-23 05:54:51 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
+ 2008-10-15 07:04:53 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
- 2008-08-26 07:24:28 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 —-a-w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 —-a-w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 —-a-w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-26 07:24:29 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
+ 2008-10-16 20:38:37 44,544 —-a-w c:\windows\system32\dllcache\iernonce.dll
- 2008-08-26 07:24:29 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
+ 2008-10-16 20:38:37 267,776 —-a-w c:\windows\system32\dllcache\iertutil.dll
- 2008-08-25 08:38:00 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 —-a-w c:\windows\system32\dllcache\ieudinit.exe
- 2008-08-23 05:56:15 635,848 ——w c:\windows\system32\dllcache\iexplore.exe
+ 2008-10-15 07:06:26 633,632 —-a-w c:\windows\system32\dllcache\iexplore.exe
- 2008-08-26 07:24:30 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 —-a-w c:\windows\system32\dllcache\jsproxy.dll
- 2006-10-19 01:03:58 100,864 —-a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-18 06:09:22 100,864 —-a-w c:\windows\system32\dllcache\logagent.exe
- 2008-08-26 07:24:30 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 —-a-w c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-26 07:24:30 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 —-a-w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 —-a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-26 07:24:30 477,696 ——w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 —-a-w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-26 07:24:30 193,024 ——w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 20:38:38 193,024 —-a-w c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 07:24:30 671,232 ——w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 20:38:39 671,232 —-a-w c:\windows\system32\dllcache\mstime.dll
- 2008-08-26 07:24:30 102,912 ——w c:\windows\system32\dllcache\occache.dll
+ 2008-10-16 20:38:39 102,912 —-a-w c:\windows\system32\dllcache\occache.dll
- 2008-08-26 07:24:30 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 —-a-w c:\windows\system32\dllcache\pngfilt.dll
- 2006-08-21 14:52:08 246,814 —-a-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:15:47 247,326 —-a-w c:\windows\system32\dllcache\strmdll.dll
- 2008-08-26 07:24:30 105,984 ——w c:\windows\system32\dllcache\url.dll
+ 2008-10-16 20:38:39 105,984 —-a-w c:\windows\system32\dllcache\url.dll
- 2008-08-26 07:24:31 1,159,680 ——w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 —-a-w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-26 07:24:31 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
+ 2008-10-16 20:38:39 233,472 —-a-w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-26 07:24:31 826,368 ——w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 20:38:40 826,368 —-a-w c:\windows\system32\dllcache\wininet.dll
- 2006-10-19 02:47:20 937,984 —-a-w c:\windows\system32\dllcache\WMNetMgr.dll
+ 2008-06-18 10:03:08 938,496 —-a-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-10-19 02:47:22 2,450,944 —-a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 —-a-w c:\windows\system32\dllcache\WMVCore.dll
- 2008-08-26 07:24:28 347,136 ——w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 —-a-w c:\windows\system32\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 ——w c:\windows\system32\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 —-a-w c:\windows\system32\dxtrans.dll
- 2008-08-26 07:24:28 133,120 ——w c:\windows\system32\extmgr.dll
+ 2008-10-16 20:38:35 133,120 —-a-w c:\windows\system32\extmgr.dll
- 2008-11-23 15:17:15 329,096 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-22 12:59:26 329,096 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2008-02-20 06:51:05 282,624 —-a-w c:\windows\system32\gdi32.dll
+ 2008-10-23 13:01:36 283,648 —-a-w c:\windows\system32\gdi32.dll
- 2008-08-26 07:24:28 63,488 —-a-w c:\windows\system32\icardie.dll
+ 2008-10-16 20:38:35 63,488 —-a-w c:\windows\system32\icardie.dll
- 2008-08-25 08:37:59 70,656 ——w c:\windows\system32\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 —-a-w c:\windows\system32\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 ——w c:\windows\system32\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 —-a-w c:\windows\system32\ieakeng.dll
- 2008-08-26 07:24:28 230,400 ——w c:\windows\system32\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 —-a-w c:\windows\system32\ieaksie.dll
- 2008-08-23 05:54:51 161,792 ——w c:\windows\system32\ieakui.dll
+ 2008-10-15 07:04:53 161,792 —-a-w c:\windows\system32\ieakui.dll
- 2008-08-26 07:24:28 383,488 —-a-w c:\windows\system32\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 ——w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 —-a-w c:\windows\system32\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 —-a-w c:\windows\system32\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 —-a-w c:\windows\system32\ieframe.dll
- 2008-08-26 07:24:29 44,544 ——w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:38:37 44,544 —-a-w c:\windows\system32\iernonce.dll
- 2008-08-26 07:24:29 267,776 —-a-w c:\windows\system32\iertutil.dll
+ 2008-10-16 20:38:37 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2008-08-25 08:38:00 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 —-a-w c:\windows\system32\ieudinit.exe
- 2008-08-26 07:24:30 27,648 ——w c:\windows\system32\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 —-a-w c:\windows\system32\jsproxy.dll
- 2006-10-19 01:03:58 100,864 —-a-w c:\windows\system32\logagent.exe
+ 2008-06-18 06:09:22 100,864 —-a-w c:\windows\system32\logagent.exe
- 2008-08-26 07:24:30 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 —-a-w c:\windows\system32\msfeeds.dll
- 2008-08-26 07:24:30 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 —-a-w c:\windows\system32\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 —-a-w c:\windows\system32\mshtml.dll
- 2008-08-26 07:24:30 477,696 ——w c:\windows\system32\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 —-a-w c:\windows\system32\mshtmled.dll
- 2008-08-26 07:24:30 193,024 ——w c:\windows\system32\msrating.dll
+ 2008-10-16 20:38:38 193,024 —-a-w c:\windows\system32\msrating.dll
- 2008-08-26 07:24:30 671,232 ——w c:\windows\system32\mstime.dll
+ 2008-10-16 20:38:39 671,232 —-a-w c:\windows\system32\mstime.dll
- 2008-08-26 07:24:30 102,912 ——w c:\windows\system32\occache.dll
+ 2008-10-16 20:38:39 102,912 —-a-w c:\windows\system32\occache.dll
- 2008-08-26 07:24:30 44,544 ——w c:\windows\system32\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 —-a-w c:\windows\system32\pngfilt.dll
- 2008-07-08 13:02:01 17,272 ——w c:\windows\system32\spmsg.dll
+ 2007-07-27 14:41:40 16,760 —-a-w c:\windows\system32\spmsg.dll
- 2006-08-21 14:52:08 246,814 —-a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:15:47 247,326 —-a-w c:\windows\system32\strmdll.dll
- 2008-07-14 11:09:18 62,976 ——w c:\windows\system32\tzchange.exe
+ 2008-10-22 09:47:07 62,976 —-a-w c:\windows\system32\tzchange.exe
- 2008-08-26 07:24:30 105,984 —-a-w c:\windows\system32\url.dll
+ 2008-10-16 20:38:39 105,984 —-a-w c:\windows\system32\url.dll
- 2008-08-26 07:24:31 1,159,680 —-a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 —-a-w c:\windows\system32\urlmon.dll
- 2008-08-26 07:24:31 233,472 —-a-w c:\windows\system32\webcheck.dll
+ 2008-10-16 20:38:39 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2008-08-26 07:24:31 826,368 —-a-w c:\windows\system32\wininet.dll
+ 2008-10-16 20:38:40 826,368 —-a-w c:\windows\system32\wininet.dll
- 2006-10-19 02:47:20 937,984 —-a-w c:\windows\system32\wmnetmgr.dll
+ 2008-06-18 10:03:08 938,496 —-a-w c:\windows\system32\WMNetmgr.dll
- 2006-10-19 02:47:22 2,450,944 —-a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 —-a-w c:\windows\system32\WMVCore.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 50,760 2006-05-10 00:24:16 c:\program files\Common Files\AOL\1129690640\ee\bak\AOLSoftware.exe

—-a-w 124,520 2006-02-17 16:59:46 c:\program files\Common Files\AOL\IPHSend\bak\IPHSend.exe

—-a-w 180,269 2005-10-19 00:37:51 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe

—-a-w 48,752 2005-04-08 22:52:30 c:\program files\Common Files\Symantec Shared\bak\ccApp.exe
—-a-w 48,752 2005-04-08 19:52:30 c:\program files\Common Files\Symantec Shared\ccApp.exe

—-a-w 68,856 2007-06-26 02:57:05 c:\program files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe

—-a-w 245,760 2005-02-25 22:34:02 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe

—-a-w 271,672 2007-07-31 22:44:42 c:\program files\iTunes\bak\iTunesHelper.exe
—-a-w 289,576 2008-10-01 23:57:12 c:\program files\iTunes\iTunesHelper.exe

—-a-w 491,520 2005-03-25 15:13:20 c:\program files\NETGEAR\WG111v2 Configuration Utility\bak\RtWLan.exe

—-a-w 286,720 2007-06-29 10:24:52 c:\program files\QuickTime\bak\qttask.exe
—-a-w 413,696 2008-09-06 20:09:14 c:\program files\QuickTime\QTTask.exe

—-a-w 85,184 2005-04-17 19:30:48 c:\program files\Symantec AntiVirus\bak\VPTray.exe
—-a-w 85,184 2005-04-17 16:30:48 c:\program files\Symantec AntiVirus\VPTray.exe

—-a-w 15,360 2004-08-04 04:00:00 c:\windows\system32\bak\ctfmon.exe
—-a-w 15,360 2004-08-04 04:00:00 c:\windows\system32\ctfmon.exe

—-a-w 126,976 2005-01-23 17:31:34 c:\windows\system32\bak\hkcmd.exe

—-a-w 659,456 2004-06-07 18:42:30 c:\windows\system32\bak\hphmon06.exe

—-a-w 98,304 2005-03-08 03:00:00 c:\windows\system32\spool\drivers\w32x86\3\bak\E_FATIAEA.EXE
—-a-w 98,304 2005-03-08 03:00:00 c:\windows\system32\spool\drivers\w32x86\3\E_FATIAEA.EXE

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-11-20 16:21 160496 –a—— c:\program files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus CX4200 Series (Copy 2)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE" [2005-03-07 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [N/A]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"EPSON Stylus CX4200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE" [2005-03-07 98304]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-10 1261336]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-03 158208]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
WG111v2 Smart Wizard Wireless Setting.lnk - c:\program files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2006-06-12 745472]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-03-09 11:09 63712 c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
–a—— 2008-12-10 11:57 1261336 c:\progra~1\AVG\AVG8\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
c:\program files\Common Files\AOL\1129690640\ee\AOLSoftware.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-10-01 18:57 289576 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
–a—— 2004-10-14 15:54 253952 c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
–a—— 2008-10-07 10:23 111856 c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6wIP]
c:\documents and settings\HP_Owner\Application Data\Microsoft\Windows\rjdyn.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedRunner]
c:\documents and settings\HP_Owner\Application Data\SpeedRunner\SpeedRunner.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
–a—— 2004-07-20 13:48 3210752 c:\program files\Webroot\Spy Sweeper\SpySweeper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Virtual PDF Printer]
c:\program files\Virtual PDF Printer\VirtualPDFPrinter.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
–a—— 2008-10-07 10:23 111856 c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1129690640\\ee\\aim6.exe"=
"c:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-10 97928]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-10 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-10 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-10 76040]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [2006-05-12 59136]
R2 YahooAUService;Yahoo! Updater;"c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe" [2008-11-09 602392]
R3 EraserUtilDrv10733;EraserUtilDrv10733;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10733.sys [2007-10-12 112688]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2006-06-12 108160]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2005-04-17 124608]
S3 SUSTUCAM;Susteen USB Cable Modem Driver;c:\windows\system32\DRIVERS\sustucam.sys [2007-04-04 38272]
S3 SUSTUCAP;Susteen USB Cable Port Driver;c:\windows\system32\DRIVERS\sustucap.sys [2007-04-04 38272]
S3 SUSTUCAU;Susteen USB Cable USB Driver;c:\windows\system32\DRIVERS\sustucau.sys [2007-04-04 21376]
.
Contents of the 'Scheduled Tasks' folder

2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{18F32C3A-1037-491D-A118-5719F2F4AE41} - c:\windows\system32\pmnkIccc.dll
BHO-{937add2e-7664-4911-87f8-fcae2ba65286} - c:\windows\system32\dqwejy.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\hc7ttvx3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 18:57:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(720)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-29 19:08:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-30 00:07:58
ComboFix2.txt 2008-12-16 01:48:29
ComboFix3.txt 2008-12-15 19:10:38

Pre-Run: 91,509,575,680 bytes free
Post-Run: 92,307,664,896 bytes free

510 — E O F — 2008-12-19 04:37:19
No problem!

Here is another free alternative to AVG:

AntiVir Personal

Make sure you uninstall AVG first.



1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

AWF::
c:\program files\iTunes\bak\iTunesHelper.exe
c:\program files\QuickTime\bak\qttask.exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedRunner]


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.



Download SDFix and save it to your desktop.
Double click SDFix.exe and it will extract the files to %systemdrive%
(this is the drive that contains the Windows Directory, typically C:\SDFix). DO NOT use it just yet.

Reboot your computer in SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup [but before the Windows icon appears] press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Finally copy and paste the contents of the results file Report.txt in your next reply along with the ComboFix Log.
ok, here are the two logs, first combofix, the SDFix



thanks again sooooooooooo much.

happy new year

j-a


PS: can i run a few of these programs on my other computers or should i go through the formality of this forum?




COMBOFIX:


ComboFix 08-12-30.02 - HP_Owner 2008-12-31 10:45:37.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.137 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\HP_Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.

2008-12-22 08:11 . 2008-12-22 08:11 d——– c:\program files\SUPERAntiSpyware
2008-12-22 08:11 . 2008-12-22 08:11 d——– c:\documents and settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2008-12-22 08:11 . 2008-12-22 08:11 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-21 13:42 . 2008-12-21 13:42 d——– C:\_OTMoveIt
2008-12-20 11:18 . 2008-12-27 20:10 d——– C:\rsit
2008-12-20 11:18 . 2008-12-27 20:04 d——– c:\program files\trend micro
2008-12-18 08:37 . 2008-12-18 08:37 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-18 08:37 . 2008-12-18 08:37 d——– c:\documents and settings\HP_Owner\Application Data\Malwarebytes
2008-12-18 08:37 . 2008-12-18 08:37 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-18 08:37 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-18 08:37 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-16 19:35 . 2008-12-16 19:58 d——– c:\documents and settings\HP_Owner\DoctorWeb
2008-12-11 10:13 . 2008-12-11 10:13 d——– c:\program files\Microsoft Silverlight
2008-12-10 20:39 . 2008-12-29 18:16 d–h—– C:\$AVG8.VAULT$
2008-12-10 20:28 . 2008-12-10 20:28 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-12-10 20:28 . 2008-12-10 20:28 76,040 –a—— c:\windows\system32\drivers\avgtdix.sys
2008-12-10 20:28 . 2008-12-10 20:28 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-12-10 19:31 . 2008-12-11 09:32 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-10 19:30 . 2008-12-11 09:29 d——– c:\program files\SpywareBlaster
2008-12-10 12:49 . 2008-12-10 12:49 d——– c:\documents and settings\HP_Owner\Application Data\Webroot
2008-12-10 11:57 . 2008-12-10 20:28 d——– c:\windows\system32\drivers\Avg
2008-12-10 11:57 . 2008-12-10 11:57 d——– c:\program files\AVG
2008-12-10 11:57 . 2008-12-10 20:30 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-10 11:19 . 2008-12-10 11:19 d——– c:\program files\Webroot
2008-12-06 15:13 . 2008-12-06 15:13 d——– c:\documents and settings\HP_Owner\Application Data\LaCie
2008-12-06 15:02 . 2008-12-06 15:02 d——– c:\program files\LaCie
2008-12-05 21:13 . 2008-12-05 21:13 d——– c:\program files\Common Files\Scanner
2008-12-05 21:13 . 2008-12-05 22:04 d——– c:\program files\CA Yahoo! Anti-Spy
2008-12-05 19:00 . 2008-12-05 19:00 d——– c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-05 19:00 . 2008-12-05 19:00 262,144 –a—— C:\ntuser.dat
2008-12-05 18:59 . 2008-12-05 19:00 d——– c:\documents and settings\HP_Owner\Application Data\Yahoo!
2008-12-05 18:59 . 2008-12-05 18:59 d——– c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-12-04 22:41 . 2005-10-18 20:36 d——– c:\documents and settings\Administrator\WINDOWS
2008-12-04 22:41 . 2008-12-04 22:41 d——– c:\documents and settings\Administrator
2008-12-03 22:26 . 2008-12-03 23:04 d——– c:\windows\SxsCaPendDel
2008-12-02 22:01 . 2008-12-02 22:04 d——– c:\program files\Windows Live Safety Center
2008-12-02 11:17 . 2008-12-02 11:20 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-01 21:12 . 2008-12-15 13:49 d——– c:\documents and settings\HP_Owner\Application Data\Twain
2008-11-26 15:43 . 2008-11-26 15:43 d——– c:\program files\Common Files\Software Update Utility
2008-11-26 15:43 . 2008-11-26 15:43 d——– c:\documents and settings\All Users\Application Data\acccore
2008-11-22 10:38 . 2008-11-22 10:38 d——– c:\documents and settings\HP_Owner\Application Data\OpenOffice.org
2008-11-22 10:32 . 2008-12-03 22:25 d——– c:\program files\OpenOffice.org 3
2008-11-22 10:32 . 2008-06-10 02:32 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-11 10:01 . 2008-11-11 10:01 d——– c:\program files\iPod
2008-11-11 10:01 . 2008-11-11 10:01 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-11 09:45 . 2008-12-01 18:14 d——– c:\program files\Bonjour

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-31 15:45 ——— d—–w c:\program files\QuickTime
2008-12-31 15:45 ——— d—–w c:\program files\iTunes
2008-12-31 11:54 ——— d—–w c:\program files\Symantec AntiVirus
2008-12-22 13:09 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-21 18:37 ——— d—–w c:\program files\Java
2008-12-21 15:31 ——— d—–w c:\program files\Symantec
2008-12-21 15:22 ——— d—–w c:\program files\AIM
2008-12-21 15:22 ——— d—–w c:\documents and settings\HP_Owner\Application Data\Aim
2008-12-13 06:40 3,593,216 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-06 00:00 ——— d—–w c:\program files\Yahoo!
2008-12-02 16:18 ——— d—–w c:\program files\Lavasoft
2008-12-02 16:18 ——— d—–w c:\documents and settings\HP_Owner\Application Data\Lavasoft
2008-12-01 23:16 ——— d—–w c:\program files\IntelliMover Data Transfer Demo
2008-12-01 21:06 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-30 22:21 ——— d–h–w c:\documents and settings\HP_Owner\Application Data\Move Networks
2008-11-26 21:32 ——— d—–w c:\program files\AIM6
2008-11-26 20:42 ——— d—–w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-22 17:03 ——— d—–w c:\program files\Common Files\Adobe
2008-11-12 11:52 ——— d—–w c:\program files\Apple Software Update
2008-11-11 14:58 ——— d—–w c:\program files\Common Files\Apple
2008-11-07 23:02 ——— d—–w c:\program files\DivX
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 13:11 70,656 —-a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 —-a-w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:57 332,800 —-a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 —-a-w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:15 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-03 10:15 247,326 —-a-w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-19 21:55 200,704 —-a-w c:\windows\system32\ssldivx.dll
2008-09-19 21:55 1,044,480 —-a-w c:\windows\system32\libdivx.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\dllcache\msxml3.dll
2005-10-19 03:14 158 —-a-w c:\documents and settings\HP_Owner\Application Data\wklnhst.dat
2008-12-22 13:05 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-22 13:05 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-22 13:05 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-22 13:05 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-22 13:05 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 50,760 2006-05-10 00:24:16 c:\program files\Common Files\AOL\1129690640\ee\bak\AOLSoftware.exe

—-a-w 124,520 2006-02-17 16:59:46 c:\program files\Common Files\AOL\IPHSend\bak\IPHSend.exe

—-a-w 180,269 2005-10-19 00:37:51 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe

—-a-w 48,752 2005-04-08 22:52:30 c:\program files\Common Files\Symantec Shared\bak\ccApp.exe
—-a-w 48,752 2005-04-08 19:52:30 c:\program files\Common Files\Symantec Shared\ccApp.exe

—-a-w 68,856 2007-06-26 02:57:05 c:\program files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe

—-a-w 245,760 2005-02-25 22:34:02 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe

—-a-w 491,520 2005-03-25 15:13:20 c:\program files\NETGEAR\WG111v2 Configuration Utility\bak\RtWLan.exe

—-a-w 85,184 2005-04-17 19:30:48 c:\program files\Symantec AntiVirus\bak\VPTray.exe
—-a-w 85,184 2005-04-17 16:30:48 c:\program files\Symantec AntiVirus\VPTray.exe

—-a-w 15,360 2004-08-04 04:00:00 c:\windows\system32\bak\ctfmon.exe
—-a-w 15,360 2004-08-04 04:00:00 c:\windows\system32\ctfmon.exe

—-a-w 126,976 2005-01-23 17:31:34 c:\windows\system32\bak\hkcmd.exe

—-a-w 659,456 2004-06-07 18:42:30 c:\windows\system32\bak\hphmon06.exe

—-a-w 98,304 2005-03-08 03:00:00 c:\windows\system32\spool\drivers\w32x86\3\bak\E_FATIAEA.EXE
—-a-w 98,304 2005-03-08 03:00:00 c:\windows\system32\spool\drivers\w32x86\3\E_FATIAEA.EXE

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-11-20 16:21 160496 –a—— c:\program files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus CX4200 Series (Copy 2)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE" [2005-03-07 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [N/A]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"EPSON Stylus CX4200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE" [2005-03-07 98304]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-10 1261336]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
WG111v2 Smart Wizard Wireless Setting.lnk - c:\program files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2006-06-12 745472]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-03-09 11:09 63712 c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
–a—— 2008-12-10 11:57 1261336 c:\progra~1\AVG\AVG8\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
c:\program files\Common Files\AOL\1129690640\ee\AOLSoftware.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2007-07-31 17:44 271672 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
–a—— 2004-10-14 15:54 253952 c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-06-29 05:24 286720 c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
–a—— 2008-10-07 10:23 111856 c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6wIP]
c:\documents and settings\HP_Owner\Application Data\Microsoft\Windows\rjdyn.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
–a—— 2004-07-20 13:48 3210752 c:\program files\Webroot\Spy Sweeper\SpySweeper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Virtual PDF Printer]
c:\program files\Virtual PDF Printer\VirtualPDFPrinter.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
–a—— 2008-10-07 10:23 111856 c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1129690640\\ee\\aim6.exe"=
"c:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-10 97928]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-10 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-10 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-10 76040]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [2006-05-12 59136]
R2 YahooAUService;Yahoo! Updater;"c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe" [2008-11-09 602392]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2006-06-12 108160]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2005-04-17 124608]
S3 SUSTUCAM;Susteen USB Cable Modem Driver;c:\windows\system32\DRIVERS\sustucam.sys [2007-04-04 38272]
S3 SUSTUCAP;Susteen USB Cable Port Driver;c:\windows\system32\DRIVERS\sustucap.sys [2007-04-04 38272]
S3 SUSTUCAU;Susteen USB Cable USB Driver;c:\windows\system32\DRIVERS\sustucau.sys [2007-04-04 21376]
.
Contents of the 'Scheduled Tasks' folder

2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\hc7ttvx3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-31 10:51:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(716)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2008-12-31 10:56:05
ComboFix-quarantined-files.txt 2008-12-31 15:56:00
ComboFix2.txt 2008-12-30 00:08:14
ComboFix3.txt 2008-12-16 01:48:29
ComboFix4.txt 2008-12-15 19:10:38

Pre-Run: 92,256,276,480 bytes free
Post-Run: 92,284,170,240 bytes free

273 — E O F — 2008-12-19 04:37:19








SDFIX:




SDFix: Version 1.240
Run by [removed] on Wed 12/31/2008 at 11:34 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-31 12:13:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe:*:Enabled:BackWeb for Pavilion"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1129690640\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1129690640\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\\iTunes\\iTunes.exe"="%ProgramFiles%\\iTunes\\iTunes.exe:*:enabled:iTunes"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :



Files with Hidden Attributes :

Tue 18 Oct 2005 213 A.SHR — "C:\BOOT.BAK"
Sun 23 Oct 2005 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 29 Mar 2007 35,840 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0001.tmp"
Thu 29 Mar 2007 31,744 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0004.tmp"
Thu 29 Mar 2007 38,912 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0058.tmp"
Fri 30 Mar 2007 40,960 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0189.tmp"
Fri 30 Mar 2007 43,008 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0212.tmp"
Fri 30 Mar 2007 42,496 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0361.tmp"
Thu 29 Mar 2007 35,840 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0488.tmp"
Thu 29 Mar 2007 36,352 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0497.tmp"
Fri 30 Mar 2007 40,448 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0541.tmp"
Thu 29 Mar 2007 31,744 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0576.tmp"
Thu 29 Mar 2007 37,376 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0726.tmp"
Thu 29 Mar 2007 37,888 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0817.tmp"
Fri 30 Mar 2007 42,496 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0856.tmp"
Fri 30 Mar 2007 43,520 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL0871.tmp"
Thu 29 Mar 2007 33,280 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1071.tmp"
Fri 30 Mar 2007 42,496 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1072.tmp"
Fri 30 Mar 2007 42,496 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1314.tmp"
Thu 29 Mar 2007 33,280 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1329.tmp"
Fri 30 Mar 2007 41,984 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1339.tmp"
Fri 30 Mar 2007 40,960 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1366.tmp"
Thu 29 Mar 2007 37,376 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1412.tmp"
Thu 29 Mar 2007 35,328 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1474.tmp"
Thu 29 Mar 2007 33,280 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1514.tmp"
Thu 29 Mar 2007 36,352 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1562.tmp"
Fri 30 Mar 2007 41,984 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1664.tmp"
Thu 29 Mar 2007 36,352 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1690.tmp"
Thu 29 Mar 2007 31,744 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1701.tmp"
Thu 29 Mar 2007 38,912 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1789.tmp"
Thu 29 Mar 2007 32,768 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1792.tmp"
Fri 30 Mar 2007 44,032 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1813.tmp"
Thu 29 Mar 2007 39,936 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1860.tmp"
Thu 29 Mar 2007 36,864 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1899.tmp"
Thu 29 Mar 2007 33,792 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1918.tmp"
Thu 29 Mar 2007 38,912 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL1954.tmp"
Fri 30 Mar 2007 40,448 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2014.tmp"
Thu 29 Mar 2007 38,912 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2142.tmp"
Thu 29 Mar 2007 37,888 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2180.tmp"
Fri 30 Mar 2007 41,984 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2182.tmp"
Fri 30 Mar 2007 41,984 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2204.tmp"
Fri 30 Mar 2007 41,984 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2227.tmp"
Fri 30 Mar 2007 40,960 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2393.tmp"
Fri 30 Mar 2007 39,936 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2425.tmp"
Fri 30 Mar 2007 43,520 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2455.tmp"
Thu 29 Mar 2007 31,744 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2555.tmp"
Fri 30 Mar 2007 43,008 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2671.tmp"
Thu 29 Mar 2007 37,376 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2756.tmp"
Thu 29 Mar 2007 38,912 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2775.tmp"
Thu 29 Mar 2007 39,936 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL2781.tmp"
Fri 30 Mar 2007 44,032 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3047.tmp"
Thu 29 Mar 2007 33,792 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3063.tmp"
Thu 29 Mar 2007 34,304 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3082.tmp"
Thu 29 Mar 2007 32,768 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3156.tmp"
Thu 29 Mar 2007 32,768 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3285.tmp"
Thu 29 Mar 2007 38,912 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3415.tmp"
Thu 29 Mar 2007 36,352 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3494.tmp"
Fri 30 Mar 2007 40,448 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3508.tmp"
Fri 30 Mar 2007 41,984 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3519.tmp"
Thu 29 Mar 2007 32,768 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3546.tmp"
Thu 29 Mar 2007 38,912 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3619.tmp"
Thu 29 Mar 2007 38,912 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3650.tmp"
Thu 29 Mar 2007 33,280 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3740.tmp"
Thu 29 Mar 2007 34,816 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3814.tmp"
Thu 29 Mar 2007 33,280 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL3971.tmp"
Thu 29 Mar 2007 33,792 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL4034.tmp"
Fri 30 Mar 2007 44,032 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL4047.tmp"
Thu 29 Mar 2007 39,936 …H. — "C:\Documents and Settings\HP_Owner\Desktop\~WRL4072.tmp"
Mon 6 Mar 2006 19,968 …H. — "C:\Documents and Settings\HP_Owner\My Documents\~WRL0004.tmp"
Tue 7 Mar 2006 20,992 …H. — "C:\Documents and Settings\HP_Owner\My Documents\~WRL1929.tmp"
Wed 13 Dec 2006 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 11 Jun 2007 828 A..H. — "C:\Program Files\Common Files\AOL\IPHSend\IPH.BAK"

Finished!

oh, btw…. last night the computer was running fine and this morning also.

just updating.


Thanks for the update.

happy new year to you as well ;)



Your logs look clean, Great Job :thumbsup:


Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]


Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.


Your Adobe Acrobat Reader is out of date. Older versions are vulnerable to attack.

Please go to the link below to update.

http://www.adobe.com/products/acrobat/readstep2.html



Now for some cleanup..
Please download OTCleanIt and save it to Desktop.
  • Please make sure you are connecting to the Internet
  • Double-click OTCleanIt.exe
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

    No Firewall Onboard

    You don't seem to have a firewall program installed. Using a firewall will allow you to allow/deny access for applications that want to go online. Select one of these, or another of your choice:

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Install SpywareGuard - SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

    A tutorial on installing & using this product can be found here:

    Using SpywareGuard to protect your computer from Spyware/Hijacker


  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

here are some additional utilities that will enhance your safety

  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software
i do want to thank you for the clean bill of health. wow, took a long time. i guess that is what happens when you dont take this stuff seriously. i will learn about firewalls and get one. at least our wireless connection needs a password to access it. i will update all of these files and install all that you have recommended. thank you again. you have a wonderful and healthy new year. j-a
me again….. i was just about to start doing those items, when i looked and saw the firewall icon on the tray and it had an "X" on it. so i went into the window for it and it was telling me that the firewall was active and it was not off. i am not sure what to do, so this puter does have a firewall, it just wont activate???? should i try to get this one to work or d/l a different one after i learn about them???? :) j-a
me again… this spywareguard that you asked me to d/l, this is not the one that i had trouble getting rid of? it was spywareguard 2008. that was such a mess. thanks again j-a
It is probably windows firewall. Go ahead and leave it deactivated and choose one that I have provided for you.


this spywareguard that you asked me to d/l, this is not the one that i had trouble getting rid of? it was spywareguard 2008. that was such a mess.


No SpywareGuard is good.

SpywareGuard 2008 is rogue/bad.

wow, took a long time. i guess that is what happens when you dont take this stuff seriously


Yes you had a few very serious infections including:

  • TDSS Rootkit
  • Vundo
  • AWF


thank you again.

you have a wonderful and healthy new year.


You are welcome. Same to you!
just an update…… did most of the things on the "to do" list uninstalled combofix tried to install javara.exe, but it would not install updated adobe acrobat did the otcleanit made IE more secure d/l sunbelt presonal firewall…………………………… not sure, but i think this slowed down my computer. everything is loading really slow now, i am updating XP with service pack 3. i have tried to install 4 times so far. keep getting several error messages. like…. service pack failed…. access denied…. install not complete… and a few other errors. i think i have to install as administrator. that i will do in a little while……… the other 2 installs, i have not done yet. after i get service pack 3 installed. just wanted to give you an update…. have a happy new year day. j-a
update i am the administrator and it still wont let me d/l service pack 3. i will figure this out. also, i removed the firewall that i installed i think it was sunbelt, it really slowed down this computer. took about 2 minutes to open a web page and took about 2 minutes to surf a page. j-a
thanks much, i will have to do this on monday, yesterday i worked and today off to a broadway play. have a great day, will update later j-a

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI