This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Daughter's HP 5130 Grinding To A Halt...Again!

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HP DV5130US Laptop, AMD Turion 4, 1GB RAM, 120GB HD.


Once again, through questionable downloads and neglecting to run the appropriate scans, my daughter's HP Laptop is running at a snail's pace. Resources are being drained away and CPU usage stays at 100%. The keyboard is exhibiting unusual behavior, even though it's new and was operating just fine. An attempt to defrag the HD took more than 12 hours for a 120GB HD. I have run NOD Virus scan which I then shut down and ran Comcast's version of McAfee's Security Suite. I also ran Kaspersky's Online scan, Threatfire, Malwarebytes and other than minor cookie threats, they show no major problems. I've run CCleaner and Glary Registry repair with no noticeable improvement. Because the system is running so slowly, it's impossible at this point to upload the various Windows updates she may have neglected to install.

I've had her back up all her files in preparation for my having to do a reformat (which I had done not more than 8 months ago) and re-installation of Windows XP Media Edition. On the off chance someone might discover the source(s) of this mess before I do the reformat, I'm posting her computer's HJT log. Even if there is no fix, hopefully, I might be able to point out some security areas she needs to pay more attention to in the future.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:51:11 PM, on 1/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - Global Startup: AutorunsDisabled
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1213645232825
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1213645307356
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: McAfee Application Installer Cleanup (0251571231043138) (0251571231043138mcinstcleanup) - Unknown owner - C:\DOCUME~1\RACHEL~1\LOCALS~1\Temp\025157~1.EXE (file missing)
O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7395 bytes


Thank you in advance for any help, advice and assistance.

Gerry
Hi 1excop36,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 11…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u11-windows-i586-p.exe to install the newest version.


  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Tomk; Thank you for your response. I'm going to download the suggested programs from my desktop to a flashdrive as her system is running so incredibly slow. I'll follow your instructions and then post a new HJT log as you requested. Again, I appreciate the assistance. Gerry
Tomk;

I followed your instructions to the letter with one addition, that being I ran CCleaner after running ATF Cleaner. There is virtually no chnage in the system operation. From a restart, it takes 10 minutes to completely reboot. The Malwarebytes "Quick"scan took 35 minutes, which came up clean. It's taking over 5 minutes to shut down and sometimes longer. Also still having problems opening programs from the desktop by double clicking and often right clicking opens the recycle bin dialog. Also, my daughter left the laptop on overnight and the McAfee Security Suite ran both an update and a scan which came back clear.

Here's the lates HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:10:38 PM, on 1/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - Global Startup: AutorunsDisabled
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1213645232825
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1213645307356
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: McAfee Application Installer Cleanup (0251571231043138) (0251571231043138mcinstcleanup) - Unknown owner - C:\DOCUME~1\RACHEL~1\LOCALS~1\Temp\025157~1.EXE (file missing)
O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7429 bytes

As I said before, I appreciate you efforts in helping me avoid a reformat if at all possible. I just love being the family tech support :pullhair:

Gerry
1excop36,

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.



Viewpoint Manager is considered as foistware instead of malware since it is often installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
It is STRONGLY recommended that you remove the Viewpoint products; however, decide for yourself. To uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

  • Click Start, then Settings, then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, Remove the Viewpoint component
  • Do the same for each Viewpoint component.

Now let's dig a little deeper.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Tomk; Thanks once again. I have long been suspicious of Viewpoint from the bygone days of AOL, but being "Dad" I was just being paranoid. I suspect that before we finish this, there may be similar programs that have to go. On to the next phase. Gerry
1excop36, There are worse things out their than Viewpoint. So far, we haven't found anything really bad. ComboFix will give us a pretty in-depth look at the computer.
Tomk;

Well, that went surprisingly smooth. Here is the ComboFix log:

ComboFix 09-01-13.03 - Rachel Goldshine 2009-01-13 20:39:27.1 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\jestertb.dll

.
((((((((((((((((((((((((( Files Created from 2008-12-14 to 2009-01-14 )))))))))))))))))))))))))))))))
.

2009-01-13 14:03 . 2009-01-13 14:02 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-13 14:03 . 2009-01-13 14:02 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-07 20:13 . 2008-04-13 11:45 10,368 –a—— c:\windows\system32\drivers\hidusb.sys
2009-01-03 22:45 . 2009-01-03 22:45 d——– c:\program files\Glary Registry Repair
2009-01-03 21:10 . 2009-01-03 21:11 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-03 21:10 . 2009-01-03 21:10 d——– c:\documents and settings\Rachel Goldshine\Application Data\Malwarebytes
2009-01-03 21:10 . 2009-01-03 21:10 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-03 21:10 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-03 21:10 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-03 21:09 . 2009-01-03 21:09 d——– c:\program files\Defraggler
2009-01-03 20:34 . 2009-01-13 20:23 7,469 –a—— c:\windows\system32\Config.MPF
2009-01-03 20:33 . 2006-03-03 08:07 143,360 –a—— c:\windows\system32\dunzip32.dll
2009-01-03 20:26 . 2007-11-22 06:44 201,320 –a—— c:\windows\system32\drivers\mfehidk.sys
2009-01-03 20:26 . 2007-07-13 06:20 113,952 –a—— c:\windows\system32\drivers\Mpfp.sys
2009-01-03 20:26 . 2007-11-22 06:44 79,304 –a—— c:\windows\system32\drivers\mfeavfk.sys
2009-01-03 20:26 . 2007-12-02 12:51 40,488 –a—— c:\windows\system32\drivers\mfesmfk.sys
2009-01-03 20:26 . 2007-11-22 06:44 35,240 –a—— c:\windows\system32\drivers\mfebopk.sys
2009-01-03 20:26 . 2007-11-22 06:44 33,832 –a—— c:\windows\system32\drivers\mferkdk.sys
2009-01-03 20:24 . 2009-01-03 20:24 d——– c:\program files\McAfee.com
2009-01-03 20:23 . 2009-01-03 20:26 d——– c:\program files\Common Files\McAfee
2009-01-03 20:22 . 2009-01-03 20:34 d——– c:\program files\McAfee
2009-01-03 19:35 . 2007-12-06 17:41 220,032 –a—— c:\windows\system32\drivers\SynTP.sys
2009-01-03 19:35 . 2007-12-06 17:09 196,608 –a—— c:\windows\system32\SynCtrl.dll
2009-01-03 19:35 . 2007-12-06 17:08 163,840 –a—— c:\windows\system32\SynCOM.dll
2009-01-03 19:35 . 2007-12-06 17:20 147,456 –a—— c:\windows\system32\SynTPAPI.dll
2009-01-03 19:35 . 2007-12-06 18:12 110,592 –a—— c:\windows\system32\SynTPCo4.dll
2008-12-28 15:04 . 2008-12-28 15:04 268 –ah—– C:\sqmdata01.sqm
2008-12-28 15:04 . 2008-12-28 15:04 244 –ah—– C:\sqmnoopt01.sqm
2008-12-27 08:57 . 2008-12-27 08:57 d——– c:\program files\Delicious Add-on for Internet Explorer
2008-12-23 21:18 . 2008-12-23 21:18 268 –ah—– C:\sqmdata00.sqm
2008-12-23 21:18 . 2008-12-23 21:18 244 –ah—– C:\sqmnoopt00.sqm
2008-12-23 14:11 . 2008-12-28 15:04 d——– c:\documents and settings\Rachel Goldshine\Contacts
2008-12-23 14:04 . 2008-12-23 14:05 d——– c:\program files\MSN Messenger
2008-12-17 00:05 . 2008-12-17 00:13 d——– c:\program files\Rhapsody

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-14 04:19 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-01-13 22:01 ——— d—–w c:\program files\Java
2009-01-04 05:08 ——— d—–w c:\program files\CCleaner
2009-01-04 04:56 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-04 04:34 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2009-01-04 04:22 ——— d—–w c:\program files\Quick StartUp
2009-01-04 03:07 ——— d—–w c:\program files\SUPERAntiSpyware
2009-01-04 03:01 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\SUPERAntiSpyware.com
2008-12-30 23:51 ——— d—–w c:\program files\Shockwave.com
2008-12-20 16:39 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\PlayFirst
2008-12-20 16:39 ——— d—–w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-17 08:12 ——— d—–w c:\program files\Common Files\Real
2008-12-17 06:18 ——— d—–w c:\documents and settings\All Users\Application Data\Shockwave
2008-12-13 08:24 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\acccore
2008-12-13 08:14 ——— d—–w c:\documents and settings\All Users\Application Data\AOL OCP
2008-12-13 08:13 ——— d—–w c:\program files\Common Files\Software Update Utility
2008-12-13 08:13 ——— d—–w c:\program files\AIM6
2008-12-13 08:13 ——— d—–w c:\program files\AIM Toolbar
2008-12-13 08:13 ——— d—–w c:\documents and settings\All Users\Application Data\AIM Toolbar
2008-12-13 08:12 ——— d—–w c:\documents and settings\All Users\Application Data\acccore
2008-12-13 08:11 ——— d—–w c:\documents and settings\All Users\Application Data\AOL
2008-12-13 08:10 ——— d—–w c:\program files\Common Files\AOL
2008-12-12 06:34 ——— d—–w c:\documents and settings\All Users\Application Data\NevoSoft Games
2008-12-11 07:23 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\Pogo Games
2008-12-07 22:31 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\GameInvest
2008-12-03 09:29 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\Auslogics
2008-12-03 08:24 ——— d—–w c:\program files\Sonic
2008-12-03 08:16 ——— d—–w c:\program files\Yahoo!
2008-12-03 08:16 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-03 08:15 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\Yahoo!
2008-12-03 08:01 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-03 08:01 ——— d—–w c:\program files\Hp
2008-12-03 07:53 ——— d—–w c:\program files\Hewlett-Packard
2008-12-03 07:49 ——— d—–w c:\program files\Google
2008-12-03 07:44 ——— d—–w c:\program files\Canon
2008-12-03 03:16 ——— d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-03 03:10 53,252 —-a-w c:\windows\Marsu-Fix 2.5 Uninstaller.exe
2008-12-03 03:04 ——— d—–w c:\program files\ESET
2008-12-03 03:04 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2008-12-03 02:37 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\McAfee
2008-12-02 22:21 ——— d—–w c:\program files\Yahoo! Games
2008-11-25 22:25 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\MysteryStudio
2008-11-21 11:18 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\Pi Eye Games
2008-11-17 20:05 12,576 —-a-w c:\windows\system32\drivers\TfKbMon.sys
2008-10-27 18:04 70,992 —-a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 18:04 514,384 —-a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 18:04 235,856 —-a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 18:04 23,376 —-a-w c:\windows\system32\X3DAudio1_5.dll
2008-06-17 21:54 774,144 —-a-w c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1024000]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-13 136600]

c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
Creating Keepsakes Scrapbook Designer Event Reminder.lnk - c:\program files\Scrapbook Designer\scrapremind.exe [2005-01-11 339968]
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-10-21 09:09 50472 c:\program files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
–a—— 2004-08-10 12:00 208952 c:\windows\ime\IMJP8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrialReset]
–a—— 2008-07-03 10:57 285327 c:\windows\regx32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-08-30 16:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Cpqset"=c:\program files\HPQ\Default Settings\cpqset.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"mcagent_exe"=c:\program files\McAfee.com\Agent\mcagent.exe /runkey
"MBkLogOnHook"=c:\program files\McAfee\MBK\LogOnHook.exe
"AppleSyncNotifier"=c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2008-06-16 231424]
S4 0251571231043138mcinstcleanup;McAfee Application Installer Cleanup (0251571231043138);c:\docume~1\RACHEL~1\LOCALS~1\Temp\025157~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service –> c:\docume~1\RACHEL~1\LOCALS~1\Temp\025157~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-01-04 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2009-01-04 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_06\bin\jusched.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 20:42:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-01-13 20:47:38
ComboFix-quarantined-files.txt 2009-01-14 04:46:50

Pre-Run: 58,722,934,784 bytes free
Post-Run: 58,701,463,552 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect /usepmtimer

208


Gerry
1excop36,

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 11…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u11-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

TrialReset is a "crack" type program. It's purpose is to reset the usage history of trial programs. It is also considered malware.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\windows\regx32.exe
    
    Folder::
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrialReset]
    
    Driver::
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Rooter log
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Tomk; I'm a bit confused as I earlier removed Java version 6 update 6 and installed the latest version which was update 11 as you directed. Now, if I understand you right, apparently it has reverted back to update 6 again? In any event, I will print out your latest instructions and get on it tomorrow. Also keep in mind, I'm still having to download from my desktop to a flash drive then install it to her laptop. But, there has been one positive change, that being that the desktop icon are now working as they should. Have a nice night and thanks again. Gerry
1excop36,

I apologize. I forgot that you had already updated your java. You haven't reverted back to an old version. Old versions didn't cleanly uninstall so they still show. Please remove them as follows:

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.

You also won't be able to run Kaspersky online if you can't get online.

Just go ahead and run Javra, Combofix, and Rooter and give me their reports along with a new HijackThis log.
Tomk;

I did as requested; however, the Kaspersky Online Virus scan took an inordinate amount of time to write itself to the HD (the broadband connection was fine as I did a direct connect to the router) and is scanning at an even slower pace. I may not have those results, if at all, until tomorrow. Here are the ComboFix and Rooter.exe logs:



Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Turion™ 64 Mobile Technology ML-37 )
BIOS : Ver 1.00PARTTBL
USER : Rachel Goldshine ( Administrator )
BOOT : Normal boot

Antivirus : McAfee VirusScan (Not Activated)
Firewall : McAfee Personal Firewall (Not Activated)

C:\ (Local Disk) - NTFS - Total:111 Go (Free:54 Go)
D:\ (CD or DVD)

Wed 01/14/2009|18:27

———————-\\ Search..

No infections found !


1 - "C:\Rooter$\Rooter_1.txt" - Wed 01/14/2009|18:27

———————-\\ Scan completed at 18:27


ComboFix 09-01-13.04 - Rachel Goldshine 2009-01-14 18:14:47.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.662 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Rachel Goldshine\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*

FILE ::
c:\windows\regx32.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\regx32.exe

.
((((((((((((((((((((((((( Files Created from 2008-12-15 to 2009-01-15 )))))))))))))))))))))))))))))))
.

2009-01-14 17:59 . 2009-01-14 17:57 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-13 14:03 . 2009-01-14 17:57 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-07 20:13 . 2008-04-13 11:45 10,368 –a—— c:\windows\system32\drivers\hidusb.sys
2009-01-03 22:45 . 2009-01-03 22:45 d——– c:\program files\Glary Registry Repair
2009-01-03 21:10 . 2009-01-03 21:11 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-03 21:10 . 2009-01-03 21:10 d——– c:\documents and settings\Rachel Goldshine\Application Data\Malwarebytes
2009-01-03 21:10 . 2009-01-03 21:10 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-03 21:10 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-03 21:10 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-03 21:09 . 2009-01-03 21:09 d——– c:\program files\Defraggler
2009-01-03 20:34 . 2009-01-14 18:11 7,757 –a—— c:\windows\system32\Config.MPF
2009-01-03 20:33 . 2006-03-03 08:07 143,360 –a—— c:\windows\system32\dunzip32.dll
2009-01-03 20:26 . 2007-11-22 06:44 201,320 –a—— c:\windows\system32\drivers\mfehidk.sys
2009-01-03 20:26 . 2007-07-13 06:20 113,952 –a—— c:\windows\system32\drivers\Mpfp.sys
2009-01-03 20:26 . 2007-11-22 06:44 79,304 –a—— c:\windows\system32\drivers\mfeavfk.sys
2009-01-03 20:26 . 2007-12-02 12:51 40,488 –a—— c:\windows\system32\drivers\mfesmfk.sys
2009-01-03 20:26 . 2007-11-22 06:44 35,240 –a—— c:\windows\system32\drivers\mfebopk.sys
2009-01-03 20:26 . 2007-11-22 06:44 33,832 –a—— c:\windows\system32\drivers\mferkdk.sys
2009-01-03 20:24 . 2009-01-03 20:24 d——– c:\program files\McAfee.com
2009-01-03 20:23 . 2009-01-03 20:26 d——– c:\program files\Common Files\McAfee
2009-01-03 20:22 . 2009-01-03 20:34 d——– c:\program files\McAfee
2009-01-03 19:35 . 2007-12-06 17:41 220,032 –a—— c:\windows\system32\drivers\SynTP.sys
2009-01-03 19:35 . 2007-12-06 17:09 196,608 –a—— c:\windows\system32\SynCtrl.dll
2009-01-03 19:35 . 2007-12-06 17:08 163,840 –a—— c:\windows\system32\SynCOM.dll
2009-01-03 19:35 . 2007-12-06 17:20 147,456 –a—— c:\windows\system32\SynTPAPI.dll
2009-01-03 19:35 . 2007-12-06 18:12 110,592 –a—— c:\windows\system32\SynTPCo4.dll
2008-12-28 15:04 . 2008-12-28 15:04 268 –ah—– C:\sqmdata01.sqm
2008-12-28 15:04 . 2008-12-28 15:04 244 –ah—– C:\sqmnoopt01.sqm
2008-12-27 08:57 . 2008-12-27 08:57 d——– c:\program files\Delicious Add-on for Internet Explorer
2008-12-23 21:18 . 2008-12-23 21:18 268 –ah—– C:\sqmdata00.sqm
2008-12-23 21:18 . 2008-12-23 21:18 244 –ah—– C:\sqmnoopt00.sqm
2008-12-23 14:11 . 2008-12-28 15:04 d——– c:\documents and settings\Rachel Goldshine\Contacts
2008-12-23 14:04 . 2008-12-23 14:05 d——– c:\program files\MSN Messenger
2008-12-17 00:05 . 2008-12-17 00:13 d——– c:\program files\Rhapsody

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-15 01:57 ——— d—–w c:\program files\Java
2009-01-14 04:19 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-01-04 05:08 ——— d—–w c:\program files\CCleaner
2009-01-04 04:56 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-04 04:34 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2009-01-04 04:22 ——— d—–w c:\program files\Quick StartUp
2009-01-04 03:07 ——— d—–w c:\program files\SUPERAntiSpyware
2009-01-04 03:01 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\SUPERAntiSpyware.com
2008-12-30 23:51 ——— d—–w c:\program files\Shockwave.com
2008-12-20 16:39 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\PlayFirst
2008-12-20 16:39 ——— d—–w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-17 08:12 ——— d—–w c:\program files\Common Files\Real
2008-12-17 06:18 ——— d—–w c:\documents and settings\All Users\Application Data\Shockwave
2008-12-13 08:24 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\acccore
2008-12-13 08:14 ——— d—–w c:\documents and settings\All Users\Application Data\AOL OCP
2008-12-13 08:13 ——— d—–w c:\program files\Common Files\Software Update Utility
2008-12-13 08:13 ——— d—–w c:\program files\AIM6
2008-12-13 08:13 ——— d—–w c:\program files\AIM Toolbar
2008-12-13 08:13 ——— d—–w c:\documents and settings\All Users\Application Data\AIM Toolbar
2008-12-13 08:12 ——— d—–w c:\documents and settings\All Users\Application Data\acccore
2008-12-13 08:11 ——— d—–w c:\documents and settings\All Users\Application Data\AOL
2008-12-13 08:10 ——— d—–w c:\program files\Common Files\AOL
2008-12-12 06:34 ——— d—–w c:\documents and settings\All Users\Application Data\NevoSoft Games
2008-12-11 07:23 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\Pogo Games
2008-12-07 22:31 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\GameInvest
2008-12-03 09:29 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\Auslogics
2008-12-03 08:24 ——— d—–w c:\program files\Sonic
2008-12-03 08:16 ——— d—–w c:\program files\Yahoo!
2008-12-03 08:16 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-03 08:15 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\Yahoo!
2008-12-03 08:01 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-03 08:01 ——— d—–w c:\program files\Hp
2008-12-03 07:53 ——— d—–w c:\program files\Hewlett-Packard
2008-12-03 07:49 ——— d—–w c:\program files\Google
2008-12-03 07:44 ——— d—–w c:\program files\Canon
2008-12-03 03:16 ——— d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-03 03:10 53,252 —-a-w c:\windows\Marsu-Fix 2.5 Uninstaller.exe
2008-12-03 03:04 ——— d—–w c:\program files\ESET
2008-12-03 03:04 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2008-12-03 02:37 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\McAfee
2008-12-02 22:21 ——— d—–w c:\program files\Yahoo! Games
2008-11-25 22:25 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\MysteryStudio
2008-11-21 11:18 ——— d—–w c:\documents and settings\Rachel Goldshine\Application Data\Pi Eye Games
2008-11-17 20:05 12,576 —-a-w c:\windows\system32\drivers\TfKbMon.sys
2008-10-27 18:04 70,992 —-a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 18:04 514,384 —-a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 18:04 235,856 —-a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 18:04 23,376 —-a-w c:\windows\system32\X3DAudio1_5.dll
2008-06-17 21:54 774,144 —-a-w c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((( snapshot@2009-01-13_20.44.11.96 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-14 04:29:37 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-15 02:07:49 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-14 04:29:37 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-15 02:07:49 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-13 22:02:07 144,792 —-a-w c:\windows\system32\java.exe
+ 2009-01-15 01:57:54 144,792 —-a-w c:\windows\system32\java.exe
- 2009-01-13 22:02:07 144,792 —-a-w c:\windows\system32\javaw.exe
+ 2009-01-15 01:57:54 144,792 —-a-w c:\windows\system32\javaw.exe
- 2009-01-13 22:02:07 148,888 —-a-w c:\windows\system32\javaws.exe
+ 2009-01-15 01:57:54 148,888 —-a-w c:\windows\system32\javaws.exe
+ 2009-01-15 01:59:57 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_c38.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1024000]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-14 136600]

c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
Creating Keepsakes Scrapbook Designer Event Reminder.lnk - c:\program files\Scrapbook Designer\scrapremind.exe [2005-01-11 339968]
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-10-21 09:09 50472 c:\program files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
–a—— 2004-08-10 12:00 208952 c:\windows\ime\IMJP8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-08-30 16:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Cpqset"=c:\program files\HPQ\Default Settings\cpqset.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"mcagent_exe"=c:\program files\McAfee.com\Agent\mcagent.exe /runkey
"MBkLogOnHook"=c:\program files\McAfee\MBK\LogOnHook.exe
"AppleSyncNotifier"=c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2008-06-16 231424]
S4 0251571231043138mcinstcleanup;McAfee Application Installer Cleanup (0251571231043138);c:\docume~1\RACHEL~1\LOCALS~1\Temp\025157~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service –> c:\docume~1\RACHEL~1\LOCALS~1\Temp\025157~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - JAVAQUICKSTARTERSERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-01-04 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2009-01-04 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &AIM; Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Search;
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-14 18:19:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\wbem\fastprox.dll
.
Completion time: 2009-01-14 18:25:12
ComboFix-quarantined-files.txt 2009-01-15 02:24:16
ComboFix2.txt 2009-01-14 04:47:39

Pre-Run: 58,679,214,080 bytes free
Post-Run: 58,659,987,456 bytes free

217


There are a couple of programs that a guy my daughter dated, who was a self-proclaimed "computer whiz", installed in an effort to help fix her laptop, one of which is "SuperAntispyware" that I could not uninstall by the usual methods (prior to posting here). He is also the person behind where the "crack" entry came from. For other good reasons, she is no longer dating this fellow. :woot:

As an aside from this, what are your feelings about the program WinPatrol which was suggested (by someone else) as an additional peice of security software?

Once again, thank you for your patience and assistance. My daughter really does appreciate our help :thumbup:

Gerry
1excop36,

  • I don't know why Kaspersky took so long to start but I'd expect it to run for a couple hours. I've seen it longer.
  • I have a 19 year old daugter. Infected computers are easier.
  • "Guy's my daughter used to date" are the norm. It's amazing how many reasonable young men become total flakes as soon as my daughter starts thinking she might like to date them. A tip: I have three "Sports" I "play" with them when my daughter brings them home to meet me; paintball, skeet, and/or target shooting. 'Nuf said. :D
  • Winpatrol is good advice. :thumbup:
Tomk; Well, the scan took over 2 hours and found 1 bug. Here it is: ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Wednesday, January 14, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, January 15, 2009 02:16:51 Records in database: 1622996 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - Critical Areas: C:\Documents and Settings\All Users\Start Menu\Programs\Startup C:\Documents and Settings\Rachel Goldshine\Start Menu\Programs\Startup C:\Program Files C:\WINDOWS Scan statistics: Files scanned: 59103 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 02:28:09 File name / Threat name / Threats count C:\Program Files\Shockwave.com\OPERATION Mania\OPERATION Mania.exe Infected: Backdoor.Win32.Rbot.ydo 1 The selected area was scanned. With what limited knowledge I have, I suspect that some of the problem why her system is so slow is she has downloaded so many games and other questionable programs and as a result there are far too many processes running. As for your "fatherly" observations, when my daughter was younger, before I had to retire, I always threatened pick the time to be cleaning my duty weapon on the dining room table when her date arrived to pick her up :yeah: Have a good night. Gerry

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI