This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer Slowing & Search Engine Use Affected

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thank you for taking the time to look at my post. My computer operation and internet activity has been slowing. And in addition, any use of search engines (Google.com, Yahoo.com) seem affected as well. The lists of search results generated by the engines are mainly comprised of descriptions accurate to my search criteria, however the actual links are very different from the results descriptions.

I'm running XP and primarily use Firefox. I've also run Ad-Aware and Spybot, but neither have seemed to help.

My logfile is as follows:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:33:15 PM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HPAiODevice(hp officejet k series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 8591 bytes
[external image: Posted Image]

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.




Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Malwarebytes log:

Malwarebytes' Anti-Malware 1.31
Database version: 1563
Windows 5.1.2600 Service Pack 3

12/28/2008 2:01:26 PM
mbam-log-2008-12-28 (14-01-26).txt

Scan type: Quick Scan
Objects scanned: 82262
Time elapsed: 8 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 15
Files Infected: 32

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Chana Roschyk\Application Data\Starware (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\BrowserSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\ErrorSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Layouts (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Manager (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\PopupBlocker (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Reference (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\RelatedSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Screensavers (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\SearchMatch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Toolbar (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\ToolbarLogo (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\ToolbarSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\TravelSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Weather (Adware.Starware) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\BrowserSearch\BrowserSearch.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Layouts\PreferencesLayout.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Layouts\PreferencesLayout.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Layouts\ToolbarLayout.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Layouts\ToolbarLayout.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Manager\ManagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Manager\ManagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Reference\ReferenceOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Reference\ReferenceOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Screensavers\ScreensaversOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Screensavers\ScreensaversOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\SearchMatch\SearchMatchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Toolbar\TBProductsOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\TravelSearch\TravelSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Weather\AlertArchive.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Weather\WeatherOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chana Roschyk\Application Data\Starware\Weather\WeatherOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\sysaudio.sys (Rootkit.Agent) -> Quarantined and deleted successfully.


HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:21:15 PM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HPAiODevice(hp officejet k series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 8590 bytes


Computer seems to be operatig no differently than before, slower than normal. Internet searches are still inacurate as well. For example, a Google search for "sprout learn grow" brings up the description for www.sproutlearngrow.com, however clicking on the link takes me to www.allculinaryschools.com. The internet use is still pretty slow as well.
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Okay, here's the ComboFix log:

ComboFix 08-12-28.01 - Jeremy Roschyk 2008-12-28 21:56:28.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.486 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG 7.5.552 *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common Files\SLMSS
c:\program files\INSTALL.LOG
c:\windows\bundles
c:\windows\bundles\32wu54rd.exe
c:\windows\bundles\bs5-cvuacy.exe
c:\windows\bundles\Tvm_b5_269.exe
c:\windows\bundles\VT02.exe
c:\windows\bundles\WebRebates_Auto_InstallSilent.exe
c:\windows\system32\ntnet.drv

.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.

2008-12-28 13:46 . 2008-12-28 13:46 d——– c:\documents and settings\Jeremy Roschyk\Application Data\Malwarebytes
2008-12-28 13:46 . 2008-12-03 19:52 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2008-12-28 13:45 . 2008-12-28 13:46 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-28 13:45 . 2008-12-28 13:45 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-28 13:45 . 2008-12-03 19:52 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-12-27 23:58 . 2008-12-27 23:58 d——– c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-12-27 23:58 . 2008-12-27 23:58 d——– c:\program files\SDHelper (Spybot - Search & Destroy)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 02:47 ——— d—–w c:\documents and settings\Jeremy Roschyk\Application Data\AVG7
2008-12-29 02:00 ——— d—–w c:\documents and settings\All Users\Application Data\AVG7
2008-12-17 05:53 ——— d—–w c:\program files\QUICKENW
2008-12-17 04:52 ——— d—–w c:\documents and settings\Jeremy Roschyk\Application Data\ZoomBrowser EX
2008-12-16 00:25 ——— d—–w c:\documents and settings\All Users\Application Data\ZoomBrowser
2008-12-12 17:01 3,067,904 ——w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2008-12-11 22:02 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-10 05:05 ——— d—–w c:\documents and settings\Jeremy Roschyk\Application Data\FileZilla
2008-11-02 12:56 ——— d—–w c:\program files\MagicDVDRipper
2008-10-29 17:11 126,808 —-a-w c:\documents and settings\Chana Roschyk_2\Application Data\GDIPFONTCACHEV1.DAT
2008-10-24 11:21 455,296 ——w c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-10-23 12:36 286,720 —-a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720 ——w c:\windows\SYSTEM32\DLLCACHE\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\SYSTEM32\DLLCACHE\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\SYSTEM32\DLLCACHE\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\SYSTEM32\DLLCACHE\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\SYSTEM32\DLLCACHE\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\SYSTEM32\DLLCACHE\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\SYSTEM32\DLLCACHE\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\SYSTEM32\DLLCACHE\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\SYSTEM32\muweb.dll
2008-10-16 01:00 666,112 —-a-w c:\windows\SYSTEM32\wininet.dll
2008-10-16 01:00 666,112 ——w c:\windows\SYSTEM32\DLLCACHE\wininet.dll
2008-10-16 01:00 619,520 ——w c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
2008-10-16 01:00 1,499,136 ——w c:\windows\SYSTEM32\DLLCACHE\shdocvw.dll
2008-10-15 16:34 337,408 ——w c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\SYSTEM32\strmdll.dll
2008-10-03 10:02 247,326 ——w c:\windows\SYSTEM32\DLLCACHE\strmdll.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\SYSTEM32\msxml4.dll
2008-08-11 02:26 24,192 —-a-w c:\documents and settings\Jeremy Roschyk\usbsermptxp.sys
2008-08-11 02:26 22,768 —-a-w c:\documents and settings\Jeremy Roschyk\usbsermpt.sys
2007-03-28 19:02 121,096 —-a-w c:\documents and settings\Chana Roschyk\Application Data\GDIPFONTCACHEV1.DAT
2005-02-15 05:11 69,992 —-a-w c:\documents and settings\Jeremy Roschyk\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"PPWebCap"="c:\progra~1\ScanSoft\PAPERP~1\PPWebCap.exe" [2000-09-06 40960]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-10-02 684032]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-09-24 290816]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-10-16 590848]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QAGENT"="c:\program files\QUICKENW\QAGENT.EXE" [2001-08-01 94208]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\SYSTEM32\Ati2mdxx.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2007-10-22 219136]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-08 113664]
HPAiODevice(hp officejet k series) - 1.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe [2002-11-20 151552]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-12-16 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\System32\ctmp3.acm
"VIDC.NSVI"= nsvideo.dll
"aux"= wdmaud.sys

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [2005-01-16 11264]
R2 mrtRate;mrtRate;c:\windows\system32\drivers\mrtRate.sys [2003-01-05 34712]
S3 MosIrUsb;MosIrUsb.sys;c:\windows\system32\DRIVERS\MosIrUsb.sys [2006-02-19 48128]

*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-12-29 c:\windows\Tasks\AC2794C5918407A9.job
- c:\progra~1\mapiar~1\title hope extra.exe []

2008-12-29 c:\windows\Tasks\AC84CCA791A77F0B.job
- c:\progra~1\mapiar~1\title hope extra.exe []

2008-11-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Jeremy Roschyk\Application Data\Mozilla\Firefox\Profiles\viz7vst9.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://wolff.football.sportsline.com/
FF - plugin: c:\documents and settings\Jeremy Roschyk\Application Data\Mozilla\Firefox\Profiles\viz7vst9.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll

ATTENTION: FIREFOX POLICES IS IN FORCE
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("general.useragent.vendorComment", "ax");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.xpconnect.activex.global.hosting_flags", 9);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.classID.allowByDefault", false);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6BF52A52-394A-11D3-B153-00C04F79FAA6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID22D6F312-B0F6-11D0-94AB-0080C74C7E95", "AllAccess");
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-28 21:58:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(752)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2008-12-28 22:00:15
ComboFix-quarantined-files.txt 2008-12-29 02:59:44

Pre-Run: 2,807,193,600 bytes free
Post-Run: 2,984,316,928 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

192 — E O F — 2008-12-18 22:01:54


And Here's the most recent HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:53 PM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HPAiODevice(hp officejet k series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 8517 bytes


As far as the operation of the computer goes, it seems to be running faster now, at least Firefox does, but the internet searches are still 'jacked'. I did not restart the computer though, I will do that after posting this and if anything is different I'll add another post.
Option #1:Please download GooredFix and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.
Goored.exe log is as follows: GooredFix v1.6 by jpshortstuff Log created at 22:07 on 29/12/2008 running Option #1 Firefox version 3.0.5 (en-US) =====Suspect Goored Entries===== =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.5\extensions] "Plugins"="C:\Program Files\Mozilla Firefox\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.5\extensions] "Components"="C:\Program Files\Mozilla Firefox\components"
Same thing happens regardless of FireFox or IE. If you refer to the attachment below, you'll see that a search for DLZ, brings up the description and title of the DLZ webpage (www.dlz.com), however using the link actually takes you to a different site (e.g. www.monstermarketplace.com, freescan.antivirus.com, etc) 📎example.doc Any thoughts?
Can't say I've ever seen that. Note: You may want to save any passwords in FF. Lets empty the cache in firefox 1. click on tools > options 2. click on the Privacy button on the left side of the window 3. click the "Clear All" button to clear all cached items or select individual items to clear by clicking on individual "Clear" buttons (History, Saved Information, Download Manager History, Cookies, Cache)
Try this:

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)

===========================================================
Below is the log file:

——————–\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 2.40GHz )
BIOS : Default System BIOS
USER : Jeremy Roschyk ( Administrator )
BOOT : Normal boot
Antivirus : AVG 7.5.552 7.5.552 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:111 Go (Free:2 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Fri 01/02/2009| 9:57 )

——————–\\ Listing folders in APPLIC~1

[01/05/2003|12:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft

[02/08/2003|12:34] C:\DOCUME~1\ADMINI~1.GON\APPLIC~1\ Microsoft

[01/05/2003|11:35] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\ Identities
[01/05/2003|12:05] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\ Microsoft
[01/05/2003|12:09] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\ Roxio

[10/14/2008|09:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[06/08/2008|10:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[06/08/2008|10:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[12/21/2005|11:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Avery
[01/02/2009|09:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AVG7
[08/10/2008|09:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ BVRP Software
[07/11/2008|10:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Comcast
[01/05/2003|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Creative
[01/25/2008|01:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Dell
[01/16/2005|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Grisoft
[05/21/2005|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GTek
[03/11/2007|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[12/29/2008|01:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ IsolatedStorage
[10/11/2003|11:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Knowledge Adventure
[03/29/2008|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ LogiShrd
[03/11/2007|07:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Logitech
[12/28/2008|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[08/17/2004|12:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee.com
[08/25/2004|09:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[12/11/2008|05:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft Help
[01/15/2003|10:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MSN6
[01/15/2003|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Palo Alto Software Inc
[01/05/2003|12:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[01/05/2003|12:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Roxio
[01/05/2003|12:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[05/05/2007|11:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[07/07/2005|07:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Support.com
[08/25/2007|03:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SupportSoft
[10/17/2004|10:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[02/17/2007|09:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[12/28/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ZoomBrowser

[09/02/2008|10:10] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ Adobe
[01/29/2006|12:56] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ AVG7
[04/29/2003|06:05] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ COREL
[07/18/2008|03:24] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ Gtek
[12/13/2003|07:18] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ Help
[01/05/2003|11:35] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ Identities
[07/15/2008|09:27] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ Logitech
[09/02/2008|10:10] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ Macromedia
[02/10/2004|12:03] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ Microsoft
[09/27/2008|10:08] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ Mozilla
[01/05/2003|12:09] C:\DOCUME~1\ANAYAR~1\APPLIC~1\ Roxio

[02/08/2007|12:58] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Adobe
[02/19/2006|10:43] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Apple Computer
[11/02/2005|02:33] C:\DOCUME~1\CHANAR~1\APPLIC~1\ AVG7
[01/13/2003|01:06] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Corel
[02/01/2003|09:08] C:\DOCUME~1\CHANAR~1\APPLIC~1\ CyberLink
[04/09/2007|01:36] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Gtek
[02/25/2003|12:44] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Help
[01/05/2003|11:35] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Identities
[08/17/2004|12:34] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Lavasoft
[03/12/2007|04:30] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Logitech
[02/23/2004|11:20] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Macromedia
[01/10/2006|07:39] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Microsoft
[04/10/2005|09:40] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Mozilla
[01/15/2003|10:20] C:\DOCUME~1\CHANAR~1\APPLIC~1\ MSN6
[01/15/2003|07:54] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Palo Alto Software Inc
[01/05/2003|12:09] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Roxio
[11/21/2006|08:59] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Snapfish
[07/08/2005|02:34] C:\DOCUME~1\CHANAR~1\APPLIC~1\ Sun

[02/01/2008|04:35] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Adobe
[06/08/2008|10:10] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Apple Computer
[07/17/2006|07:51] C:\DOCUME~1\CHANAR~2\APPLIC~1\ AVG7
[12/30/2008|12:30] C:\DOCUME~1\CHANAR~2\APPLIC~1\ bppenu11
[07/28/2007|03:35] C:\DOCUME~1\CHANAR~2\APPLIC~1\ CyberLink
[08/07/2008|08:24] C:\DOCUME~1\CHANAR~2\APPLIC~1\ FileZilla
[07/22/2007|08:14] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Gtek
[11/12/2008|01:35] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Help
[01/05/2003|11:35] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Identities
[08/22/2007|08:45] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Intuit
[12/06/2007|03:06] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Leadertech
[07/22/2007|08:12] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Logitech
[03/14/2004|10:43] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Macromedia
[10/28/2008|12:02] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Microsoft
[09/06/2008|07:00] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Mozilla
[01/05/2003|12:09] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Roxio
[01/18/2007|02:58] C:\DOCUME~1\CHANAR~2\APPLIC~1\ Sun
[09/10/2008|09:26] C:\DOCUME~1\CHANAR~2\APPLIC~1\ ZoomBrowser EX

[09/02/2008|09:44] C:\DOCUME~1\CREEDR~1\APPLIC~1\ Adobe
[09/02/2008|09:10] C:\DOCUME~1\CREEDR~1\APPLIC~1\ AVG7
[09/02/2008|09:34] C:\DOCUME~1\CREEDR~1\APPLIC~1\ GTek
[01/05/2003|11:35] C:\DOCUME~1\CREEDR~1\APPLIC~1\ Identities
[09/02/2008|09:10] C:\DOCUME~1\CREEDR~1\APPLIC~1\ Logitech
[09/02/2008|09:44] C:\DOCUME~1\CREEDR~1\APPLIC~1\ Macromedia
[09/02/2008|09:59] C:\DOCUME~1\CREEDR~1\APPLIC~1\ Microsoft
[09/20/2008|06:20] C:\DOCUME~1\CREEDR~1\APPLIC~1\ Mozilla
[01/05/2003|12:09] C:\DOCUME~1\CREEDR~1\APPLIC~1\ Roxio

[01/05/2003|11:35] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[01/05/2003|12:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[01/05/2003|12:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Roxio

[02/19/2008|11:17] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Adobe
[12/20/2007|01:25] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Apple Computer
[12/28/2008|09:47] C:\DOCUME~1\JEREMY~1\APPLIC~1\ AVG7
[04/29/2003|05:59] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Corel
[01/10/2003|12:27] C:\DOCUME~1\JEREMY~1\APPLIC~1\ CyberLink
[11/10/2008|12:05] C:\DOCUME~1\JEREMY~1\APPLIC~1\ FileZilla
[04/09/2007|08:08] C:\DOCUME~1\JEREMY~1\APPLIC~1\ GTek
[01/11/2003|10:28] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Help
[01/05/2003|11:35] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Identities
[03/29/2008|10:57] C:\DOCUME~1\JEREMY~1\APPLIC~1\ InstallShield
[01/12/2003|07:57] C:\DOCUME~1\JEREMY~1\APPLIC~1\ InterTrust
[03/11/2007|08:13] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Intuit
[01/25/2006|03:02] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Lavasoft
[07/02/2003|09:50] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Leadertech
[03/11/2007|07:37] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Logitech
[02/24/2004|12:45] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Macromedia
[12/28/2008|01:46] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Malwarebytes
[12/16/2008|07:58] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Microsoft
[03/20/2004|11:32] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Microsoft Web Folders
[04/16/2008|09:31] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Move Networks
[09/04/2008|04:59] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Mozilla
[08/05/2006|01:18] C:\DOCUME~1\JEREMY~1\APPLIC~1\ MSN6
[03/13/2004|03:33] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Roxio
[04/04/2005|12:18] C:\DOCUME~1\JEREMY~1\APPLIC~1\ Sun
[12/28/2008|11:14] C:\DOCUME~1\JEREMY~1\APPLIC~1\ ZoomBrowser EX

[09/02/2008|10:02] C:\DOCUME~1\KALERO~1\APPLIC~1\ Adobe
[09/02/2008|10:01] C:\DOCUME~1\KALERO~1\APPLIC~1\ AVG7
[09/02/2008|10:03] C:\DOCUME~1\KALERO~1\APPLIC~1\ GTek
[01/05/2003|11:35] C:\DOCUME~1\KALERO~1\APPLIC~1\ Identities
[09/02/2008|10:01] C:\DOCUME~1\KALERO~1\APPLIC~1\ Logitech
[09/02/2008|10:02] C:\DOCUME~1\KALERO~1\APPLIC~1\ Macromedia
[09/02/2008|10:07] C:\DOCUME~1\KALERO~1\APPLIC~1\ Microsoft
[09/27/2008|10:20] C:\DOCUME~1\KALERO~1\APPLIC~1\ Mozilla
[01/05/2003|12:09] C:\DOCUME~1\KALERO~1\APPLIC~1\ Roxio

[12/06/2005|03:43] C:\DOCUME~1\LOCALS~1\APPLIC~1\ AVG7
[02/17/2007|09:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[03/18/2008|10:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Mozilla

[01/05/2003|11:35] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft


——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[12/29/2008 07:36 AM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[01/02/2009 09:00 AM][–ah—–] C:\WINDOWS\tasks\AC84CCA791A77F0B.job
[01/02/2009 09:00 AM][–ah—–] C:\WINDOWS\tasks\AC2794C5918407A9.job
[12/31/2008 11:26 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/29/2002 06:00 AM][-r-h—–] C:\WINDOWS\tasks\DESKTOP.INI

( AC2794C5918407A9.job )=( c:\progra~1\mapiar~1\titlehopeextra.exe )
( AC84CCA791A77F0B.job )=( c:\progra~1\mapiar~1\titlehopeextra.exe )

——————–\\ Listing Folders in C:\Program Files

[02/08/2007|12:52] C:\Program Files\ Adobe
[08/19/2003|10:51] C:\Program Files\ America Online 7.0
[09/02/2008|08:05] C:\Program Files\ Apple Software Update
[01/05/2003|12:05] C:\Program Files\ ATI Technologies
[10/01/2008|10:07] C:\Program Files\ Avanquest update
[12/21/2005|11:38] C:\Program Files\ Avery Dennison
[03/12/2007|08:33] C:\Program Files\ Beston
[10/14/2008|09:54] C:\Program Files\ Bonjour
[08/12/2006|04:20] C:\Program Files\ brighter child
[01/05/2003|12:20] C:\Program Files\ Britannica
[12/29/2008|01:23] C:\Program Files\ Business Plan Pro
[10/17/2006|08:48] C:\Program Files\ Canon
[04/12/2004|01:47] C:\Program Files\ CAT
[12/30/2008|09:43] C:\Program Files\ CCleaner
[07/15/2008|09:36] C:\Program Files\ Clan Thompson
[10/10/2005|10:27] C:\Program Files\ Classic PhoneTools
[08/06/2004|07:10] C:\Program Files\ ClipGenie
[08/25/2007|03:27] C:\Program Files\ Comcast
[12/28/2008|09:57] C:\Program Files\ Common Files
[01/05/2003|11:36] C:\Program Files\ ComPlus Applications
[12/23/2004|02:11] C:\Program Files\ Corel
[01/05/2003|12:08] C:\Program Files\ Creative
[01/05/2003|12:09] C:\Program Files\ CyberLink
[05/27/2005|01:09] C:\Program Files\ Dell
[01/05/2003|12:19] C:\Program Files\ Dell Computer
[10/20/2005|03:13] C:\Program Files\ Dell Modem-On-Hold
[04/08/2007|08:01] C:\Program Files\ DellSupport
[01/10/2006|07:26] C:\Program Files\ Deltec
[01/05/2003|12:07] C:\Program Files\ Digital Line Detect
[05/18/2008|12:09] C:\Program Files\ Disney Interactive
[03/12/2007|08:14] C:\Program Files\ Ezonics
[01/16/2005|11:07] C:\Program Files\ Fellowes
[08/07/2008|12:12] C:\Program Files\ FileZilla FTP Client
[03/01/2007|06:19] C:\Program Files\ Grisoft
[03/29/2004|11:04] C:\Program Files\ Hewlett-Packard
[03/01/2006|04:56] C:\Program Files\ iFoundry Systems
[08/10/2008|09:29] C:\Program Files\ InstallShield Installation Information
[01/05/2003|12:05] C:\Program Files\ intel
[02/10/2004|12:38] C:\Program Files\ InterActual
[07/01/2008|01:22] C:\Program Files\ Internet Explorer
[10/14/2008|09:55] C:\Program Files\ iPod
[10/14/2008|09:56] C:\Program Files\ iTunes
[01/05/2003|12:15] C:\Program Files\ Jasc Software Inc
[08/09/2008|01:03] C:\Program Files\ Java
[08/06/2005|07:59] C:\Program Files\ JumpStart
[10/10/2005|10:27] C:\Program Files\ KFPSetup
[03/09/2004|02:21] C:\Program Files\ Kinko's
[01/25/2006|03:02] C:\Program Files\ Lavasoft
[03/11/2007|07:29] C:\Program Files\ Logitech
[11/02/2008|07:56] C:\Program Files\ MagicDVDRipper
[12/28/2008|01:46] C:\Program Files\ Malwarebytes' Anti-Malware
[08/15/2008|04:02] C:\Program Files\ Messenger
[02/20/2003|09:58] C:\Program Files\ Microsoft ActiveSync
[10/26/2008|08:57] C:\Program Files\ Microsoft Expression
[01/05/2003|11:36] C:\Program Files\ microsoft frontpage
[03/20/2004|11:32] C:\Program Files\ Microsoft Office
[10/26/2008|09:26] C:\Program Files\ Microsoft Silverlight
[03/20/2004|11:33] C:\Program Files\ Microsoft Visual Studio
[10/26/2008|09:01] C:\Program Files\ Microsoft Visual Studio 8
[10/26/2008|09:01] C:\Program Files\ Microsoft Works
[10/26/2008|08:59] C:\Program Files\ Microsoft.NET
[10/20/2005|03:13] C:\Program Files\ Modem Helper
[10/01/2008|10:07] C:\Program Files\ Motorola Phone Tools
[07/01/2008|01:10] C:\Program Files\ Movie Maker
[01/02/2009|09:54] C:\Program Files\ Mozilla Firefox
[01/10/2006|07:39] C:\Program Files\ MP3 Player Utilities V1.28
[10/26/2008|08:30] C:\Program Files\ MSBuild
[01/05/2003|12:19] C:\Program Files\ MSN
[01/05/2003|11:36] C:\Program Files\ MSN Gaming Zone
[11/16/2006|11:37] C:\Program Files\ MSXML 4.0
[07/23/2007|05:53] C:\Program Files\ MTV Networks
[10/10/2005|10:27] C:\Program Files\ MUSICMATCH
[07/01/2008|01:05] C:\Program Files\ NetMeeting
[01/05/2003|11:36] C:\Program Files\ Online Services
[07/01/2008|01:05] C:\Program Files\ Outlook Express
[01/15/2003|07:50] C:\Program Files\ PAS
[12/31/2008|02:40] C:\Program Files\ QUICKENW
[10/14/2008|09:53] C:\Program Files\ QuickTime
[01/05/2003|12:18] C:\Program Files\ Real
[10/26/2008|08:29] C:\Program Files\ Reference Assemblies
[01/05/2003|12:28] C:\Program Files\ Roxio
[06/19/2004|07:52] C:\Program Files\ ScanSoft
[12/27/2008|11:58] C:\Program Files\ SDHelper (Spybot - Search & Destroy)
[01/05/2003|12:13] C:\Program Files\ Sonic
[01/14/2008|11:03] C:\Program Files\ Spybot - Search & Destroy
[08/09/2008|01:03] C:\Program Files\ Sun
[08/04/2006|03:55] C:\Program Files\ support.com
[12/27/2008|11:58] C:\Program Files\ TeaTimer (Spybot - Search & Destroy)
[07/15/2008|09:48] C:\Program Files\ Trend Micro
[01/10/2006|07:26] C:\Program Files\ Uninstall Information
[08/26/2004|12:07] C:\Program Files\ Viewpoint
[03/25/2007|08:50] C:\Program Files\ Visioneer OneTouch
[01/16/2005|11:09] C:\Program Files\ VOB
[03/06/2007|01:31] C:\Program Files\ Windows Media Components
[03/11/2007|08:44] C:\Program Files\ Windows Media Connect 2
[07/01/2008|01:05] C:\Program Files\ Windows Media Player
[07/01/2008|01:05] C:\Program Files\ Windows NT
[08/19/2004|01:47] C:\Program Files\ WindowsUpdate
[03/06/2007|01:38] C:\Program Files\ wmv_vcm
[01/05/2003|11:36] C:\Program Files\ XEROX
[03/29/2008|11:00] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[01/05/2003|12:28] C:\Program Files\Common Files\ Adaptec Shared
[02/08/2007|12:52] C:\Program Files\Common Files\ Adobe
[01/05/2003|12:19] C:\Program Files\Common Files\ aolshare
[10/14/2008|09:53] C:\Program Files\Common Files\ Apple
[02/08/2003|12:37] C:\Program Files\Common Files\ Borland Shared(2)
[10/17/2006|08:46] C:\Program Files\Common Files\ Canon
[01/10/2006|07:26] C:\Program Files\Common Files\ Crystal Decisions
[01/05/2003|12:05] C:\Program Files\Common Files\ Dell
[02/20/2003|09:58] C:\Program Files\Common Files\ Designer
[01/10/2006|07:25] C:\Program Files\Common Files\ InstallShield
[03/11/2007|08:11] C:\Program Files\Common Files\ Intuit
[04/04/2005|12:12] C:\Program Files\Common Files\ Java
[08/06/2005|07:59] C:\Program Files\Common Files\ Knowledge Adventure
[03/29/2008|10:58] C:\Program Files\Common Files\ Logishrd
[03/29/2008|10:58] C:\Program Files\Common Files\ Logitech
[10/26/2008|09:01] C:\Program Files\Common Files\ Microsoft Shared
[01/05/2003|11:35] C:\Program Files\Common Files\ MSSoap
[01/05/2003|11:35] C:\Program Files\Common Files\ ODBC
[12/29/2008|01:24] C:\Program Files\Common Files\ Palo Alto Software
[01/05/2003|12:16] C:\Program Files\Common Files\ Palo Alto Software Inc
[01/05/2003|12:18] C:\Program Files\Common Files\ Real
[01/05/2003|12:09] C:\Program Files\Common Files\ Roxio Shared
[03/29/2008|11:00] C:\Program Files\Common Files\ Scanner
[06/19/2004|07:52] C:\Program Files\Common Files\ ScanSoft Shared
[01/05/2003|11:35] C:\Program Files\Common Files\ Services
[01/05/2003|12:14] C:\Program Files\Common Files\ Sonic Shared
[01/05/2003|11:35] C:\Program Files\Common Files\ SpeechEngines
[08/25/2007|03:28] C:\Program Files\Common Files\ SupportSoft
[01/13/2003|08:04] C:\Program Files\Common Files\ SWF Studio
[07/01/2008|01:05] C:\Program Files\Common Files\ System

——————–\\ Process

( 48 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\WINDOWS\Tasks\AC2794C5918407A9.job
C:\WINDOWS\Tasks\AC84CCA791A77F0B.job

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-02 09:59:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections


No other infections found !

[F:7][D:1]-> C:\DOCUME~1\JEREMY~1\LOCALS~1\Temp
[F:2][D:0]-> C:\DOCUME~1\JEREMY~1\Cookies
[F:52][D:7]-> C:\DOCUME~1\JEREMY~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Fri 01/02/2009|10:01 - Option : [1]

——————–\\ Scan completed at 10:01:36
Delete these files
C:\WINDOWS\Tasks\AC2794C5918407A9.job
C:\WINDOWS\Tasks\AC84CCA791A77F0B.job

Reboot and let me know how it's running now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI