This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HijackThis log - clean confirmation needed

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was getting uncontrollable amounts of popups to the point that I had to use another computer to search the internet for answers. I've found help to stop the popups but I don't think I'm done. I've used Malwarebytes' Anti-Malware and that seemed to make a big difference. I then did the online scan with Kaspersky and this is the scan report:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, December 31, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, December 30, 2008 23:44:17
Records in database: 1534331
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 155173
Threat name: 15
Infected objects: 19
Suspicious objects: 0
Duration of the scan: 02:53:43


File name / Threat name / Threats count
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: Trojan-Downloader.Win32.Agent.alr 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.ct 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.gv 2
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.bm 2
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.au 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.am 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.ar 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: Trojan.Win32.BHO.gos 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.ao 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.k 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.x 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\25.tmp Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\26.tmp Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\WINDOWS\BBStore\DSS\DSSAGENT.EXE Infected: not-a-virus:AdWare.Win32.Background 1

The selected area was scanned.





I've run the ComboFix.exe and this is the log:



ComboFix 08-12-30.02 - Kimberly 2008-12-31 15:11:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.138 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro PC-cillin Internet Security *On-access scanning enabled* (Outdated)
FW: Trend Micro PC-cillin Internet Security (Firewall) *enabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kimberly\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\404Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.

2008-12-31 00:47 . 2008-12-31 00:47 d——– c:\windows\ERUNT
2008-12-31 00:45 . 2008-12-31 01:12 d——– C:\SDFix
2008-12-30 00:23 . 2008-12-31 14:36 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-30 00:23 . 2008-12-30 00:23 1,409 –a—— c:\windows\QTFont.for
2008-12-29 23:09 . 2008-12-29 23:09 d——– c:\documents and settings\Kimberly\Application Data\Malwarebytes
2008-12-29 23:08 . 2008-12-29 23:09 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-29 23:08 . 2008-12-29 23:08 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-29 23:08 . 2008-12-03 19:59 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 23:08 . 2008-12-03 19:59 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-29 21:56 . 2008-12-29 21:56 d——– c:\program files\CCleaner
2008-12-29 21:53 . 2008-12-29 21:53 d——– c:\program files\RogueRemover FREE
2008-12-29 21:39 . 2008-12-12 00:57 78,336 –a—— c:\windows\system32\Agent.OMZ.Fix.exe
2008-12-25 00:12 . 2008-12-28 23:28 d——– c:\program files\MediaCoder
2008-12-25 00:05 . 2004-03-03 18:05 1,839,104 –a—— c:\windows\system32\NCTAudioFile2.dll
2008-12-25 00:05 . 2003-02-11 14:36 1,703,936 –a—— c:\windows\system32\NCTAudioFile.dll
2008-12-25 00:05 . 2003-02-11 14:38 892,928 –a—— c:\windows\system32\NCTAudioInformation.dll
2008-12-25 00:05 . 2003-02-11 14:39 647,168 –a—— c:\windows\system32\NCTAudioLibrary.dll
2008-12-25 00:05 . 2004-05-20 13:07 335,872 –a—— c:\windows\system32\NCTAudioVisualization2.dll
2008-12-25 00:05 . 2003-02-11 14:37 327,680 –a—— c:\windows\system32\NCTAudioGrabber.dll
2008-12-25 00:05 . 2004-03-02 19:07 315,392 –a—— c:\windows\system32\NCTAudioPlayer2.dll
2008-12-25 00:05 . 2001-05-16 17:54 309,616 –a—— c:\windows\system32\wmv8dmod.dll
2008-12-25 00:05 . 2004-03-02 19:14 307,200 –a—— c:\windows\system32\NCTAudioRecord2.dll
2008-12-25 00:05 . 2001-03-26 04:41 245,760 –a—— c:\windows\system32\mp4sds32.ax
2008-12-25 00:05 . 2004-05-20 14:24 196,608 –a—— c:\windows\system32\NCTWMAFile2.dll
2008-12-25 00:04 . 2000-05-22 06:00 647,872 –a—— c:\windows\system32\MSCOMCT2.OCX
2008-12-25 00:04 . 2002-07-23 11:05 413,760 –a—— c:\windows\system32\mpg4c32.dll
2008-12-25 00:04 . 1999-05-06 23:00 140,288 –a—— c:\windows\system32\comdlg32.ocx
2008-12-25 00:04 . 2000-07-15 06:00 101,888 –a—— c:\windows\system32\VB6STKIT.DLL
2008-12-24 23:57 . 2008-12-28 23:29 d——– c:\program files\Common Files\AVSMedia
2008-12-24 23:57 . 2008-12-24 23:57 d——– c:\documents and settings\Kimberly\Application Data\AVS4YOU
2008-12-24 23:57 . 2008-12-24 23:57 d——– c:\documents and settings\All Users\Application Data\AVS4YOU
2008-12-24 23:57 . 2006-03-03 10:02 658,432 –a—— c:\windows\system32\cc3270mt.dll
2008-12-24 23:56 . 2008-12-28 23:29 d——– c:\program files\AVS4YOU
2008-12-24 23:56 . 2003-05-21 13:50 24,576 –a—— c:\windows\system32\msxml3a.dll
2008-12-23 20:37 . 2008-12-23 20:37 d——– c:\documents and settings\Kimberly\Application Data\Amazon
2008-12-23 20:36 . 2008-12-23 20:36 d——– c:\program files\Amazon
2008-11-20 11:00 . 2008-11-20 11:00 d——– c:\documents and settings\Victoria\.realobjects
2008-11-20 08:11 . 2008-12-04 11:46 d——– c:\documents and settings\Victoria\Application Data\U3
2008-11-09 11:13 . 2008-11-09 11:13 d——– c:\program files\Walmart MP3 Music Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 02:47 ——— d—–w c:\program files\Google
2008-12-29 23:18 ——— d—–w c:\program files\Rhapsody
2008-12-26 22:13 ——— d—–w c:\documents and settings\Victoria\Application Data\Skype
2008-12-26 22:12 ——— d—–w c:\documents and settings\Victoria\Application Data\skypePM
2008-12-13 06:40 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
2008-11-19 00:32 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-27 01:33 125,160 —-a-w c:\documents and settings\Kimberly\Application Data\GDIPFONTCACHEV1.DAT
2008-10-24 11:10 453,632 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 13:01 283,648 ——w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 13:11 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:57 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:15 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-03 10:15 247,326 ——w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ——w c:\windows\system32\dllcache\msxml3.dll
2008-01-27 00:56 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-12-11 23:42 104,048 -c–a-w c:\documents and settings\Guest\Application Data\GDIPFONTCACHEV1.DAT
2007-01-27 02:10 722,176 -c–a-w c:\documents and settings\Kimberly\gotomypc_428.exe
2006-02-11 18:39 56 -csh–r c:\windows\system32\A1067E525C.sys
2007-01-25 00:40 6,998 -csha-w c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 176201]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Creative WebCam Tray"="c:\program files\Creative\Shared Files\CamTray.exe" [2005-03-29 258048]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-20 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-02-02 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 823362]
"Lexmark X6100 Series"="c:\program files\Lexmark X6100 Series\lxbfbmgr.exe" [2003-09-23 57344]
"HostManager"="c:\program files\Common Files\AOL\1139541727\ee\AOLSoftware.exe" [2006-05-09 50760]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-09 270648]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"PD0620 STISvc"="P0620Pin.dll" [2005-05-10 c:\windows\system32\P0620Pin.dll]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2006-09-17 1454143]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-12-13 630915]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2003-06-08 16432]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2007-08-09 54512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lqvkhx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139541727\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139541727\\ee\\aim6.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

R2 Tmfilter;Tmfilter;c:\windows\system32\drivers\TmXPFlt.sys [2005-08-30 205328]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2005-08-30 290889]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2005-08-30 585792]
R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys [2005-08-30 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2005-08-30 262215]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-02-12 24652]
S2 mrtRate;mrtRate; []

*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-12-31 c:\windows\Tasks\dpvfoiob.job
- c:\windows\system32\rundll32.exe [2004-08-04 06:00]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe


.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = localhost
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll

c:\windows\Downloaded Program Files\FileOpenInstall.dll - O16 -: {CE8267C2-D41A-4A50-A69D-F32B5C289F14}
hxxp://taxwebwlbs2.trendmls.com/Resources/webpublisher/installer/fileopen.cab
c:\windows\Downloaded Program Files\FileOpenInstall.OSD
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-31 15:23:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-12-31 15:25:21
ComboFix-quarantined-files.txt 2008-12-31 20:24:54

Pre-Run: 129,183,383,552 bytes free
Post-Run: 130,511,286,272 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

215 — E O F — 2008-12-19 04:05:00



I'm hoping that someone can tell me if there is anything more I can do to be sure the computer is clean.
Thank you!
I had some trouble with viruses just after Christmas but while reading other posts on this site I found some suggestions that seemed to have helped. However, there is still some slowness and a couple of days ago the computer froze. There has also been two or three popups in the past week that are easy to get rid of, but I'm not sure why they keep happening. I usually pay bills and check on other financial matters while I'm using this computer but I don't want to do that until I know the computer is clean. I've read about the possibility of remote hackers and I want to be sure this can't happen before I go back to paying bills. Please help. I'm posting my latest hijackthis log below:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:19:31, on 1/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Common Files\AOL\1139541727\ee\AOLSoftware.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Creative\Shared Files\CamTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmoAgent.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139541727\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://primis.ebrary.com/support/plugins/ebraryRdr.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolor.com/ClarkActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://taxwebwlbs2.trendmls.com/Resources/…er/fileopen.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O20 - AppInit_DLLs: lqvkhx.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 11542 bytes
Hello Caysee

Welcome to the Whatthetech Malware Removal Forum,

All advice given by anyone volunteering here, is taken at your own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.


Sorry about the delay, but the amount of people posting with infected computers is through the roof and sometimes we can't get to logs as fast as we would like to. If you have not resolved your issue and still need assistance, post a new HJT log please as your system may have changed since your original post.

Ken
Thank you very much, Ken! Here is my latest HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:14:01, on 1/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Common Files\AOL\1139541727\ee\AOLSoftware.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\Creative\Shared Files\CamTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139541727\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://primis.ebrary.com/support/plugins/ebraryRdr.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolor.com/ClarkActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://taxwebwlbs2.trendmls.com/Resources/…er/fileopen.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O20 - AppInit_DLLs: lqvkhx.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 11641 bytes
Hi Caysee,

I know getting infected with this garbage is frustrating to say the least but keep in mind that all infections and systems are different , what Combofix can clean on one system it may damage another so do not run Combofix unless instructed to do so.

Your Trendmicro Anti Virus is out of date, you need to update it, if you don't want this program let me know and I can link you to some free ones that are more than adequate.


Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O20 - AppInit_DLLs: lqvkhx.dll

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe




Go to your Add Remove Programs in the Control Panel and uninstall Viewpoint, it installs without your knowledge or consent, is considered Adware, uses system resources and is not needed for anything.

C:\Program Files\Viewpoint <–Delete this folder if its still present






Please download ATF Cleaner by Atribune to your desktop.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.






Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.
Ok, here is the mbam log:

Malwarebytes' Anti-Malware 1.33
Database version: 1665
Windows 5.1.2600 Service Pack 3

1/18/2009 01:53:35 PM
mbam-log-2009-01-18 (13-53-35).txt

Scan type: Quick Scan
Objects scanned: 65618
Time elapsed: 3 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




and the lates hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:56:13, on 1/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Common Files\AOL\1139541727\ee\AOLSoftware.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Creative\Shared Files\CamTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139541727\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://primis.ebrary.com/support/plugins/ebraryRdr.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolor.com/ClarkActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://taxwebwlbs2.trendmls.com/Resources/…er/fileopen.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 11428 bytes
Hi,

Before you install any other AV, you need to uninstall Trendmicro first, you should never run more than one AV. You can uninstall Trendmicro via the Add Remove Programs in the Control Panel.

Just install One AV and One Firewall.


Free Anti Virus Programs




Free Firewalls





Lets check this file.


Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see.

c:\windows\system32\cc3270mt.dll
It said the file had already been analyzed so I clicked the button to have it analyzed again. Hope that was the right thing to do: File cc3270mt.dll received on 01.18.2009 22:52:42 (CET) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/38 (0%) Loading server information… Your file is queued in position: 1. Estimated start time is between 42 and 60 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.0.0.73 2009.01.18 - AhnLab-V3 2009.1.15.0 2009.01.17 - AntiVir 7.9.0.57 2009.01.18 - Authentium 5.1.0.4 2009.01.18 - Avast 4.8.1281.0 2009.01.16 - AVG 8.0.0.229 2009.01.18 - BitDefender 7.2 2009.01.18 - CAT-QuickHeal 10.00 2009.01.17 - ClamAV 0.94.1 2009.01.18 - Comodo 935 2009.01.18 - DrWeb 4.44.0.09170 2009.01.18 - eSafe 7.0.17.0 2009.01.18 - eTrust-Vet 31.6.6312 2009.01.17 - F-Prot 4.4.4.56 2009.01.18 - F-Secure 8.0.14470.0 2009.01.18 - Fortinet 3.117.0.0 2009.01.15 - GData 19 2009.01.18 - Ikarus T3.1.1.45.0 2009.01.18 - K7AntiVirus 7.10.594 2009.01.17 - Kaspersky 7.0.0.125 2009.01.18 - McAfee 5499 2009.01.18 - McAfee+Artemis 5499 2009.01.18 - Microsoft None 2009.01.18 - NOD32 3775 2009.01.18 - Norman 5.93.01 2009.01.16 - nProtect 2009.1.8.0 2009.01.16 - Panda 9.5.1.2 2009.01.18 - PCTools 4.4.2.0 2009.01.18 - Prevx1 V2 2009.01.18 - Rising 21.12.62.00 2009.01.18 - SecureWeb-Gateway 6.7.6 2009.01.18 - Sophos 4.37.0 2009.01.18 - Sunbelt 3.2.1835.2 2009.01.16 - Symantec 10 2009.01.18 - TheHacker [removed].223 2009.01.18 - TrendMicro 8.700.0.1004 2009.01.16 - ViRobot 2009.1.17.1563 2009.01.17 - VirusBuster 4.5.11.0 2009.01.18 - Additional information File size: 658432 bytes MD5…: 155779c88df4e35695efb19e0d7a2366 SHA1..: 0bbebf5d2bb8196241ea84e5cdba0f5574bd7838 SHA256: 9ca024184070e1cab75e242e4ce037e1bc7953a0b4e0bc3f861edce9b805619c SHA512: 59fae880d8ad3b6f9101ecac33e8014e50a059eee3889008c157d3b45dbf0dc6 0ad00f21df13ddc0f7e20b1b8a315d13b97b2ea0b77b79a1a1aaa57534cbe239 ssdeep: 12288:tC62nvgBNoPlamOZrI+9kmekrJF77sEa8Nf1rb4WWGSyuapZrrk+kQzf:g 624BNoPE9I++meCJF7Q8Nf1X4mSyuY8 PEiD..: - TrID..: File type identification DOS Executable Borland C++ (39.2%) Win32 Executable Generic (25.7%) Win32 Dynamic Link Library (generic) (22.8%) Generic Win/DOS Executable (6.0%) DOS Executable Generic (6.0%) PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x3270121c timedatestamp…..: 0x4418859e (Wed Mar 15 21:22:38 2006) machinetype…….: 0x14c (I386) ( 7 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x7f000 0x7f000 6.57 4a3ce655178883c036b1649b7a354de9 .data 0x80000 0x14000 0xec00 4.78 d1fc99f306bae1b310637d44d0598aea .tls 0x94000 0x3000 0x2400 0.00 13a95890b5f0947d6f058ca9c30a3e01 .idata 0x97000 0x2000 0x1400 5.08 44623cb20847af295a1a3cc0b1a332b0 .edata 0x99000 0xa000 0x9400 5.95 11def70770fddd8950d6c62413684355 .rsrc 0xa3000 0x1000 0x1000 3.31 fb9d72f082e1b37db1c2eef430a999b7 .reloc 0xa4000 0x5000 0x4e00 6.66 346b429ce1d3844691c3273b7cd823de ( 4 imports ) > ADVAPI32.DLL: RegCloseKey, RegOpenKeyExA, RegQueryValueExA > KERNEL32.DLL: Beep, CloseHandle, CompareStringA, CompareStringW, CreateDirectoryA, CreateDirectoryW, CreateFileA, CreateFileW, CreatePipe, CreateProcessA, CreateProcessW, CreateThread, DeleteCriticalSection, DeleteFileA, DeleteFileW, DosDateTimeToFileTime, DuplicateHandle, EnterCriticalSection, EnumCalendarInfoA, ExitProcess, ExitThread, FileTimeToDosDateTime, FileTimeToLocalFileTime, FileTimeToSystemTime, FillConsoleOutputAttribute, FillConsoleOutputCharacterA, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW, FlushConsoleInputBuffer, FlushFileBuffers, FreeLibrary, GetACP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetConsoleMode, GetConsoleScreenBufferInfo, GetCurrentDirectoryA, GetCurrentDirectoryW, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetDateFormatA, GetDiskFreeSpaceA, GetDriveTypeA, GetDriveTypeW, GetEnvironmentStrings, GetEnvironmentStringsW, GetEnvironmentVariableA, GetExitCodeProcess, GetFileAttributesA, GetFileAttributesW, GetFileSize, GetFileTime, GetFileType, GetFullPathNameA, GetFullPathNameW, GetLargestConsoleWindowSize, GetLastError, GetLocalTime, GetLocaleInfoA, GetLogicalDrives, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleA, GetModuleHandleW, GetNumberOfConsoleInputEvents, GetOEMCP, GetProcAddress, GetProcessHeap, GetShortPathNameA, GetShortPathNameW, GetStartupInfoA, GetStartupInfoW, GetStdHandle, GetStringTypeA, GetStringTypeExA, GetStringTypeW, GetSystemDefaultLangID, GetSystemDirectoryA, GetSystemTimeAsFileTime, GetThreadLocale, GetTickCount, GetTimeZoneInformation, GetUserDefaultLCID, GetVersion, GetVersionExA, GetVolumeInformationA, GetVolumeInformationW, GlobalAlloc, GlobalFree, GlobalLock, GlobalMemoryStatus, GlobalReAlloc, GlobalSize, GlobalUnlock, HeapAlloc, HeapFree, HeapReAlloc, InitializeCriticalSection, InterlockedDecrement, InterlockedExchange, InterlockedIncrement, IsBadReadPtr, IsValidLocale, LCMapStringA, LCMapStringW, LeaveCriticalSection, LoadLibraryA, LoadLibraryExA, LoadLibraryW, LocalAlloc, LocalFileTimeToFileTime, LocalFree, LockFile, MoveFileA, MoveFileW, MultiByteToWideChar, PeekConsoleInputA, RaiseException, ReadConsoleInputA, ReadConsoleOutputA, ReadFile, RemoveDirectoryA, RemoveDirectoryW, RtlUnwind, ScrollConsoleScreenBufferA, SetConsoleCtrlHandler, SetConsoleCursorInfo, SetConsoleCursorPosition, SetConsoleMode, SetConsoleScreenBufferSize, SetConsoleWindowInfo, SetCurrentDirectoryA, SetCurrentDirectoryW, SetEndOfFile, SetEnvironmentVariableA, SetEnvironmentVariableW, SetErrorMode, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime, SetHandleCount, SetLastError, SetLocalTime, SetStdHandle, SetThreadLocale, Sleep, SystemTimeToFileTime, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, UnhandledExceptionFilter, UnlockFile, VirtualAlloc, VirtualFree, VirtualQuery, WaitForMultipleObjects, WaitForSingleObject, WideCharToMultiByte, WriteConsoleInputA, WriteConsoleOutputA, WriteFile, lstrcmpiA, lstrcpynA, lstrlenA > USER32.DLL: CharLowerW, CharNextA, CharUpperW, EnumThreadWindows, GetKeyboardType, LoadStringA, MessageBoxA, wsprintfA, wsprintfW, GetSystemMetrics > OLEAUT32.DLL: - ( 1433 exports ) @$bdele$qpv, @$bdele$qpvrx13std@nothrow_t, @$bdele$qpvt1, @$bdla$qpv, @$bdla$qpvrx13std@nothrow_t, @$bdla$qpvt1, @$blsh$qr42std@_basic_ostream$c19std@_char_traits$c__rx3bcd, @$bnew$qui, @$bnew$quirx13std@nothrow_t, @$bnwa$qui, @$bnwa$quirx13std@nothrow_t, @$brsh$qr42std@_basic_istream$c19std@_char_traits$c__r3bcd, @_time_put$b48std@_ostreambuf_iterator$b19std@_char_traits$b___@$bctr$qrx12std@_Locinfoui, @_time_put$b48std@_ostreambuf_iterator$b19std@_char_traits$b___@$bctr$qui, @_time_put$b48std@_ostreambuf_iterator$b19std@_char_traits$b___@$bdtr$qv, @_time_put$b48std@_ostreambuf_iterator$b19std@_char_traits$b___@_Getcat$qppx16std@locale@facet, @_time_put$b48std@_ostreambuf_iterator$b19std@_char_traits$b___@do_put$xq48std@_ostreambuf_iterator$b19std@_char_traits$b__r12std@ios_basebpx6std@tmcc, @_time_put$b48std@_ostreambuf_iterator$b19std@_char_traits$b___@id, @TRegexp@$bctr$qpxc, @TRegexp@$bctr$qrx7TRegexp, @TRegexp@$bdtr$qv, @TRegexp@copy_pattern$qrx7TRegexp, @TRegexp@find$xqpxcpuiui, @TRegexp@gen_pattern$qpxc, @TRegexp@maxpat, @_CatchCleanup$qv, @_InitTermAndUnexPtrs$qv, @_ReThrowException$quipuc, @_ThrowExceptionLDTC$qpvt1t1t1uiuiuipuct1, @__DynamicCast$qpvt1t1t1i, @__DynamicCastVCLptr$qqrpvt1, @__DynamicCastVCLref$qqrpvt1, @__GetTypeInfo$qpvt1t1, @__GetTypeInfo$qpvt1t1t1, @__ThrowExceptionName$qv, @__ThrowFileName$qv, @__ThrowLineNumber$qv, @__lockDebuggerData$qv, @__unlockDebuggerData$qv, @_cast_memptr$qpvt1uiuiui, @_vcl_GetHeapStatus$qv, @_vector_apply_$qpvt1uiuiuit1, @_vector_vapply_$qpvt1uiuiuit1, @bcd@$bctr$qgi, @std@_basic_string$c19std@_char_traits$c_17std@_allocator$c__@npos, @std@_codecvt$bci_@$bctr$qrx12std@_Locinfoui, @std@_codecvt$bci_@$bctr$qui, @std@_codecvt$bci_@$bdtr$qv, @std@_codecvt$bci_@_Getcat$qppx16std@locale@facet, @std@_codecvt$bci_@do_always_noconv$xqv, @std@_codecvt$bci_@do_encoding$xqv, @std@_codecvt$bci_@do_in$xqripxct2rpxcpbt5rpb, @std@_codecvt$bci_@do_length$xqrxipxct2ui, @std@_codecvt$bci_@do_max_length$xqv, @std@_codecvt$bci_@do_out$xqripxbt2rpxbpct5rpc, @std@_codecvt$bci_@do_unshift$xqripct2rpc, @std@_codecvt$bci_@id, @std@_codecvt$cci_@id, @std@_collate$b_@id, @std@_collate$c_@id, @std@_ctype$b_@$bctr$qrx12std@_Locinfoui, @std@_ctype$b_@$bctr$qui, @std@_ctype$b_@$bdtr$qv, @std@_ctype$b_@_Getcat$qppx16std@locale@facet, @std@_ctype$b_@do_is$xqpxbt1ps, @std@_ctype$b_@do_is$xqsb, @std@_ctype$b_@do_narrow$xqbc, @std@_ctype$b_@do_narrow$xqpxbt1cpc, @std@_ctype$b_@do_scan_is$xqspxbt2, @std@_ctype$b_@do_scan_not$xqspxbt2, @std@_ctype$b_@do_tolower$xqb, @std@_ctype$b_@do_tolower$xqpbpxb, @std@_ctype$b_@do_toupper$xqb, @std@_ctype$b_@do_toupper$xqpbpxb, @std@_ctype$b_@do_widen$xqc, @std@_ctype$b_@do_widen$xqpxct1pb, @std@_ctype$b_@id, @std@_ctype$c_@$bctr$qpxsoui, @std@_ctype$c_@$bctr$qrx12std@_Locinfoui, @std@_ctype$c_@$bdtr$qv, @std@_ctype$c_@_Getcat$qppx16std@locale@facet, @std@_ctype$c_@do_narrow$xqcc, @std@_ctype$c_@do_narrow$xqpxct1cpc, @std@_ctype$c_@do_tolower$xqc, @std@_ctype$c_@do_tolower$xqpcpxc, @std@_ctype$c_@do_toupper$xqc, @std@_ctype$c_@do_toupper$xqpcpxc, @std@_ctype$c_@do_widen$xqc, @std@_ctype$c_@do_widen$xqpxct1pc, @std@_ctype$c_@id, @std@_ctype$c_@table_size, @std@_messages$b_@id, @std@_messages$c_@id, @std@_money_get$b48std@_istreambuf_iterator$b19std@_char_traits$b___@id, @std@_money_get$c48std@_istreambuf_iterator$c19std@_char_traits$c___@id, @std@_money_put$b48std@_ostreambuf_iterator$b19std@_char_traits$b___@id, @std@_money_put$c48std@_ostreambuf_iterator$c19std@_char_traits$c___@id, @std@_moneypunct$bo$i0$_@$bctr$qrx12std@_Locinfoui, @std@_moneypunct$bo$i0$_@$bctr$qui, @std@_moneypunct$bo$i0$_@$bdtr$qv, @std@_moneypunct$bo$i0$_@_Getcat$qppx16std@locale@facet, @std@_moneypunct$bo$i0$_@id, @std@_moneypunct$bo$i0$_@intl, @std@_moneypunct$bo$i1$_@$bctr$qrx12std@_Locinfoui, @std@_moneypunct$bo$i1$_@$bctr$qui, @std@_moneypunct$bo$i1$_@$bdtr$qv, @std@_moneypunct$bo$i1$_@_Getcat$qppx16std@locale@facet, @std@_moneypunct$bo$i1$_@id, @std@_moneypunct$bo$i1$_@intl, @std@_moneypunct$co$i0$_@$bctr$qrx12std@_Locinfoui, @std@_moneypunct$co$i0$_@$bctr$qui, @std@_moneypunct$co$i0$_@$bdtr$qv, @std@_moneypunct$co$i0$_@_Getcat$qppx16std@locale@facet, @std@_moneypunct$co$i0$_@id, @std@_moneypunct$co$i0$_@intl, @std@_moneypunct$co$i1$_@$bctr$qrx12std@_Locinfoui, @std@_moneypunct$co$i1$_@$bctr$qui, @std@_moneypunct$co$i1$_@$bdtr$qv, @std@_moneypunct$co$i1$_@_Getcat$qppx16std@locale@facet, @std@_moneypunct$co$i1$_@id, @std@_moneypunct$co$i1$_@intl, @std@_num_get$b48std@_istreambuf_iterator$b19std@_char_traits$b___@id, @std@_num_get$c48std@_istreambuf_iterator$c19std@_char_traits$c___@id, @std@_num_put$b48std@_ostreambuf_iterator$b19std@_char_traits$b___@id, @std@_num_put$c48std@_ostreambuf_iterator$c19std@_char_traits$c___@id, @std@_numeric_limits$b_@digits, @std@_numeric_limits$b_@digits10, @std@_numeric_limits$b_@is_signed, @std@_numeric_limits$c_@digits, @std@_numeric_limits$c_@digits10, @std@_numeric_limits$c_@is_signed, @std@_numeric_limits$d_@digits, @std@_numeric_limits$d_@digits10, @std@_numeric_limits$d_@max_exponent, @std@_numeric_limits$d_@max_exponent10, @std@_numeric_limits$d_@min_exponent, @std@_numeric_limits$d_@min_exponent10, @std@_numeric_limits$f_@digits, @std@_numeric_limits$f_@digits10, @std@_numeric_limits$f_@max_exponent, @std@_numeric_limits$f_@max_exponent10, @std@_numeric_limits$f_@min_exponent, @std@_numeric_limits$f_@min_exponent10, @std@_numeric_limits$g_@digits, @std@_numeric_limits$g_@digits10, @std@_numeric_limits$g_@max_exponent, @std@_numeric_limits$g_@max_exponent10, @std@_numeric_limits$g_@min_exponent, @std@_numeric_limits$g_@min_exponent10, @std@_numeric_limits$i_@digits, @std@_numeric_limits$i_@digits10, @std@_numeric_limits$i_@is_signed, @std@_numeric_limits$j_@digits, @std@_numeric_limits$j_@digits10, @std@_numeric_limits$j_@is_signed, @std@_numeric_limits$l_@digits, @std@_numeric_limits$l_@digits10, @std@_numeric_limits$l_@is_signed, @std@_numeric_limits$o_@digits, @std@_numeric_limits$o_@digits10, @std@_numeric_limits$o_@is_modulo, @std@_numeric_limits$o_@is_signed, @std@_numeric_limits$s_@digits, @std@_numeric_limits$s_@digits10, @std@_numeric_limits$s_@is_signed, @std@_numeric_limits$uc_@digits, @std@_numeric_limits$uc_@digits10, @std@_numeric_limits$uc_@is_signed, @std@_numeric_limits$ui_@digits, @std@_numeric_limits$ui_@digits10, @std@_numeric_limits$ui_@is_signed, @std@_numeric_limits$uj_@digits, @std@_numeric_limits$uj_@digits10, @std@_numeric_limits$uj_@is_signed, @std@_numeric_limits$ul_@digits, @std@_numeric_limits$ul_@digits10, @std@_numeric_limits$ul_@is_signed, @std@_numeric_limits$us_@digits, @std@_numeric_limits$us_@digits10, @std@_numeric_limits$us_@is_signed, @std@_numeric_limits$zc_@digits, @std@_numeric_limits$zc_@digits10, @std@_numeric_limits$zc_@is_signed, @std@_numpunct$b_@id, @std@_numpunct$c_@id, @std@_time_get$b48std@_istreambuf_iterator$b19std@_char_traits$b___@id, @std@_time_get$c48std@_istreambuf_iterator$c19std@_char_traits$c___@id, @std@_time_put$c48std@_ostreambuf_iterator$c19std@_char_traits$c___@id, @std@_BADOFF, @std@_Debug_message$qpxct1, @std@_Fiopen$qpxb23std@__Iosb$i_@_Openmodei, @std@_Fiopen$qpxc23std@__Iosb$i_@_Openmodei, @std@_Fpz, @std@_Ios_init, @std@_Locinfo@$bctr$qipxc, @std@_Locinfo@$bctr$qpxc, @std@_Locinfo@$bdtr$qv, @std@_Locinfo@_Addcats$qipxc, @std@_Locinfo@_Getcoll$xqv, @std@_Locinfo@_Getctype$xqv, @std@_Locinfo@_Getcvt$xqv, @std@_Locinfo@_Getname$xqv, @std@_Locinfo@_Gettnames$xqv, @std@_Lockit@$bctr$qi, @std@_Lockit@$bdtr$qv, @std@_New_hand, @std@_Nomemory$qv, @std@_Num_base@digits, @std@_Num_base@digits10, @std@_Num_base@has_denorm, @std@_Num_base@has_denorm_loss, @std@_Num_base@has_infinity, @std@_Num_base@has_quiet_NaN, @std@_Num_base@has_signaling_NaN, @std@_Num_base@is_bounded, @std@_Num_base@is_exact, @std@_Num_base@is_iec559, @std@_Num_base@is_integer, @std@_Num_base@is_modulo, @std@_Num_base@is_signed, @std@_Num_base@is_specialized, @std@_Num_base@max_exponent, @std@_Num_base@max_exponent10, @std@_Num_base@min_exponent, @std@_Num_base@min_exponent10, @std@_Num_base@radix, @std@_Num_base@round_style, @std@_Num_base@tinyness_before, @std@_Num_base@traps, @std@_Num_float_base@has_denorm, @std@_Num_float_base@has_denorm_loss, @std@_Num_float_base@has_infinity, @std@_Num_float_base@has_quiet_NaN, @std@_Num_float_base@has_signaling_NaN, @std@_Num_float_base@is_bounded, @std@_Num_float_base@is_exact, @std@_Num_float_base@is_iec559, @std@_Num_float_base@is_integer, @std@_Num_float_base@is_modulo, @std@_Num_float_base@is_signed, @std@_Num_float_base@is_specialized, @std@_Num_float_base@radix, @std@_Num_float_base@round_style, @std@_Num_float_base@tinyness_before, @std@_Num_float_base@traps, @std@_Num_int_base@is_bounded, @std@_Num_int_base@is_exact, @std@_Num_int_base@is_integer, @std@_Num_int_base@is_modulo, @std@_Num_int_base@is_specialized, @std@_Num_int_base@radix, @std@_Raise_handler, @std@_String_base@_Xlen$xqv, @std@_String_base@_Xran$xqv, @std@_Throw$qrx13std@exception, @std@_Winit@$bctr$qv, @std@_Winit@$bdtr$qv, @std@_Winit@_Init_cnt, @std@_Wios_init, @std@cerr, @std@cin, @std@clog, @std@codecvt_base@$bctr$qui, @std@codecvt_base@$bdtr$qv, @std@codecvt_base@always_noconv$xqv, @std@codecvt_base@do_always_noconv$xqv, @std@codecvt_base@do_encoding$xqv, @std@codecvt_base@do_max_length$xqv, @std@cout, @std@ctype_base@$bctr$qui, @std@ctype_base@$bdtr$qv, @std@exception@$bctr$qv, @std@exception@$bdtr$qv, @std@exception@_Set_raise_handler$qpqrx13std@exception$v, @std@exception@what$xqv, @std@ios_base@$bctr$qv, @std@ios_base@$bdtr$qv, @std@ios_base@Init@$bctr$qv, @std@ios_base@Init@$bdtr$qv, @std@ios_base@Init@_Init_cnt, @std@ios_base@_Addstd$qv, @std@ios_base@_Callfns$q18std@ios_base@event, @std@ios_base@_Findarr$qi, @std@ios_base@_Index, @std@ios_base@_Init$qv, @std@ios_base@_Sync, @std@ios_base@_Tidy$qv, @std@ios_base@clear$q22std@__Iosb$i_@_Iostateo, @std@ios_base@copyfmt$qrx12std@ios_base, @std@ios_base@getloc$xqv, @std@ios_base@imbue$qrx10std@locale, @std@ios_base@register_callback$qpq18std@ios_base@eventr12std@ios_basei$vi, @std@istrstream@$bdtr$qv, @std@locale@$basg$qrx10std@locale, @std@locale@$bctr$q18std@_Uninitialized, @std@locale@$bctr$qp18std@locale@_Locimp, @std@locale@$bctr$qpxci, @std@locale@$bctr$qrx10std@locale, @std@locale@$bctr$qrx10std@localepxci, @std@locale@$bctr$qrx10std@localet1i, @std@locale@$bctr$qv, @std@locale@$bdtr$qv, @std@locale@$beql$xqrx10std@locale, @std@locale@_Addfac$qp16std@locale@facetuiui, @std@locale@_Getfacet$xqui, @std@locale@_Init$qv, @std@locale@_Locimp@$bctr$qo, @std@locale@_Locimp@$bctr$qrx18std@locale@_Locimp, @std@locale@_Locimp@$bdtr$qv, @std@locale@_Locimp@_Addfac$qp16std@locale@facetui, @std@locale@classic$qv, @std@locale@empty$qv, @std@locale@facet@$bctr$qui, @std@locale@facet@$bdtr$qv, @std@locale@facet@_Decref$qv, @std@locale@facet@_Incref$qv, @std@locale@facet@_Register$qv, @std@locale@global$qrx10std@locale, @std@locale@id@$bctr$qui, @std@locale@id@$oui$qv, @std@locale@id@_Id_cnt, @std@locale@name$xqv, @std@messages_base@$bctr$qui, @std@money_base@$bctr$qui, @std@nothrow, @std@ostrstream@$bctr$qpci23std@__Iosb$i_@_Openmode, @std@ostrstream@$bdtr$qv, @std@resetiosflags$q23std@__Iosb$i_@_Fmtflags, @std@set_new_handler$qpqv$v, @std@set_terminate$qpqv$v, @std@set_unexpected$qpqv$v, @std@setbase$qi, @std@setiosflags$q23std@__Iosb$i_@_Fmtflags, @std@setprecision$qi, @std@setw$qi, @std@strstream@$bctr$qpci23std@__Iosb$i_@_Openmode, @std@strstream@$bdtr$qv, @std@strstreambuf@$bdtr$qv, @std@strstreambuf@_Init$qipct2i, @std@strstreambuf@_Tidy$qv, @std@strstreambuf@freeze$qo, @std@strstreambuf@overflow$qi, @std@strstreambuf@pbackfail$qi, @std@strstreambuf@seekoff$ql22std@__Iosb$i_@_Seekdir23std@__Iosb$i_@_Openmode, @std@strstreambuf@seekpos$q12std@_fpos$i_23std@__Iosb$i_@_Openmode, @std@strstreambuf@underflow$qv, @std@terminate$qv, @std@time_base@$bctr$qui, @std@type_info@$basg$qrx13std@type_info, @std@type_info@$bctr$qrx13std@type_info, @std@type_info@$bdtr$qv, @std@type_info@$beql$xqrx13std@type_info, @std@type_info@$bneq$xqrx13std@type_info, @std@type_info@_first_base$xqr24std@type_info@_base_info, @std@type_info@_first_vbase$xqr25std@type_info@_vbase_info, @std@type_info@_guid$xqv, @std@type_info@_internal_rtti_cast$xqpvpx13std@type_info, @std@type_info@_next_base$xqr24std@type_info@_base_info, @std@type_info@before$xqrx13std@type_info, @std@type_info@name$xqv, @std@uncaught_exception$qv, @std@unexpected$qv, @std@wcerr, @std@wcin, @std@wclog, @std@wcout, @xmsg@$basg$qrx4xmsg, @xmsg@$bctr$qrx4xmsg, @xmsg@$bctr$qrx60std@_basic_string$c19std@_char_traits$c_17std@_allocator$c__, @xmsg@$bdtr$qv, @xmsg@raise$qv, @xmsg@what$xqv, __8087, __Atan, __Atexit, __Cosh, __CurrExcContext, __Denorm, __Dint, __Dnorm, __Dscale, __Dtest, __Dunscale, __Eps, __ErrorExit, __ErrorMessage, __Exp, __FAtan, __FCosh, __FDenorm, __FDint, __FDnorm, __FDscale, __FDtest, __FDunscale, __FEps, __FExp, __FInf, __FLog, __FNan, __FRteps, __FSin, __FSinh, __FSnan, __FUnloadDelayLoadedDLL, __FXbig, __FZero, __Feraise, __Getctyptab, __Global_unwind, __Hugeval, __Inf, __LCosh, __LDenorm, __LDnorm, __LDscale, __LDtest, __LDunscale, __LEps, __LExp, __LInf, __LNan, __LPoly, __LRteps, __LSin, __LSinh, __LSnan, __LXbig, __LZero, __Local_unwind, __Locksyslock, __Mtxdst, __Mtxinit, __Mtxlock, __Mtxunlock, __Nan, __Once, __Return_unwind, __Rteps, __SetUserHandler, __Sin, __Sinh, __Snan, __Stod, __Stodx, __Stof, __Stoflt, __Stofx, __Stold, __Stoldx, __Stoll, __Stollx, __Stolx, __Stopfx, __Stoull, __Stoullx, __Stoulx, __Stoxflt, __Unlocksyslock, __Xbig, __Zero, ___CPPdebugHook, ___CRTL_MEM_GetBorMemPtrs, ___CRTL_MEM_UseBorMM, ___CRTL_TLS_Alloc, ___CRTL_TLS_ExitThread, ___CRTL_TLS_Free, ___CRTL_TLS_GetInfo, ___CRTL_TLS_GetValue, ___CRTL_TLS_InitThread, ___CRTL_TLS_SetValue, ___CRTL_VCL_Thread_Hook, ___CRTL_VCL_Thread_Unhook, ___ErrorMessage, ____ExceptionHandler, ____wopen, ___access, ___alloca_helper, ___assertfail, ___bcd_log10, ___bcd_pow10, ___bcd_tobinary, ___bcd_todecimal, ___close, ___cputn, ___debuggerDisableTerminateCallback, ___doserrno, ___eof, ___errno, ___flush_win95_keyup_events, ___ftruncate, ___getStream, ___getline, ___ieee_64_n_inf, ___ieee_64_n_nanq, ___ieee_64_n_nans, ___ieee_64_n_zero, ___ieee_64_p_inf, ___ieee_64_p_nanq, ___ieee_64_p_nans, ___ieee_64_p_zero, ___isatty, ___isatty_osfhandle, ___isctype, ___iswctype, ___locale, ___lseek, ___matherr, ___matherrl, ___mb_cur_max, ___movecursor, ___moveline, ___open, ___pfnDliFailureHook, ___pfnDliNotifyHook, ___putline, ___raiseDebuggerException, ___read, ___scroll, ___terminatePTR, ___threadid, ___unexpectdPTR, ___validatexy, ___wcreat, ___wcserror, ___wfindfirst, ___wfindnext, ___wopen, ___write, __adopt_thread, __alloca, __argc, __argv, __argv_default_expand, __assert, __atoi64, __atold, __beginthread, __beginthreadNT, __beginthreadex, __c_exit, __cexit, __chartype, __chdrive, __chgsign, __chgsignl, __chmod, __clear87, __close, __cmdline_escapes, __commit, __control87, __copysign, __copysignl, __creat, __crotl, __crotr, __crtinit, __cwait, __daylight, __default87, __delayLoadHelper, __directvideo, __dos_close, __dos_creat, __dos_creatnew, __dos_findfirst, __dos_findnext, __dos_getdate, __dos_getdiskfree, __dos_getdrive, __dos_getfileattr, __dos_getftime, __dos_gettime, __dos_open, __dos_read, __dos_setdate, __dos_setdrive, __dos_setfileattr, __dos_setftime, __dos_settime, __dos_write, __ecvt, __endthread, __endthreadex, __environ, __envsize, __exit, __exitargv, __exitargv_ptr, __expand, __expand_wild, __fcloseall, __fcvt, __fdopen, __fgetc, __fgetchar, __fgetwc, __fgetwchar, __fileno, __findclose, __findfirst, __findfirsti64, __findnext, __findnexti64, __finite, __finitel, __flushall, __flushout, __fnsplit, __fpclass, __fpclassl, __fpreset, __fputc, __fputchar, __fputwc, __fputwchar, __free_heaps, __fsopen, __ftol, __ftoul, __ftruncate, __fullpath, __futime, __gcvt, __get_heap_redirector_info, __get_osfhandle, __getdcwd, __getdrive, __getdrives, __getmbcp, __getsystime, __getw, __getws, __handle_exitargv, __handle_setargv, __handle_wexitargv, __handle_wsetargv, __heapchk, __heapmin, __heapset, __heapwalk, __huge_dble, __huge_flt, __huge_ldble, __i64toa, __i64tow, __indefinite, __init_handles, __ismbbalnum, __ismbbalpha, __ismbbgraph, __ismbbkalpha, __ismbbkana, __ismbbkpunct, __ismbblead, __ismbbprint, __ismbbpunct, __ismbbtrail, __ismbcalnum, __ismbcalpha, __ismbcdigit, __ismbcgraph, __ismbchira, __ismbckata, __ismbcl0, __ismbcl1, __ismbcl2, __ismbclegal, __ismbclower, __ismbcprint, __ismbcpunct, __ismbcspace, __ismbcsymbol, __ismbcupper, __ismbslead, __ismbstrail, __isnan, __isnanl, __itow, __llocaleconv, __logb, __logbl, __lower, __lrand, __lrotl, __lrotr, __lsetlocale, __lstrcoll, __lstricoll, __lstrlwr, __lstrncoll, __lstrnicoll, __lstrupr, __lstrxfrm, __ltoa, __ltolower, __ltoupper, __ltow, __ltowlower, __ltowupper, __lwcscoll, __lwcsicoll, __lwcslwr, __lwcsncoll, __lwcsnicoll, __lwcsupr, __lwcsxfrm, __lwsetlocale, __makepath, __matherr, __matherrl, __max_dble, __max_flt, __max_ldble, __mbbtombc, __mbbtype, __mbccmp, __mbccpy, __mbcjistojms, __mbcjmstojis, __mbclen, __mbctohira, __mbctokata, __mbctolower, __mbctombb, __mbctoupper, __mbctype, __mbsbtype, __mbscat, __mbschr, __mbscmp, __mbscoll, __mbscpy, __mbscspn, __mbsdec, __mbsdup, __mbsicmp, __mbsicoll, __mbsinc, __mbslen, __mbslwr, __mbsnbcat, __mbsnbcmp, __mbsnbcnt, __mbsnbcoll, __mbsnbcpy, __mbsnbicmp, __mbsnbicoll, __mbsnbset, __mbsncat, __mbsnccnt, __mbsncmp, __mbsncoll, __mbsncpy, __mbsnextc, __mbsnicmp, __mbsnicoll, __mbsninc, __mbsnset, __mbspbrk, __mbsrchr, __mbsrev, __mbsset, __mbsspn, __mbsspnp, __mbsstr, __mbstok, __mbsupr, __messagefile, __messagefunc, __mkdir, __mktemp, __msize, __nextafter, __nextafterl, __nfile, __open, __open_osfhandle, __oscmd, __osenv, __osmajor, __osminor, __osmode, __ostype, __osversion, __pclose, __pcre_compile, __pcre_exec, __pcre_maketables, __pcre_regcomp, __pcre_regerror, __pcre_regexec, __pcre_regfree, __pcre_study, __pcre_version, __pipe, __popen, __putw, __putws, __read, __rmdir, __rmtmp, __rotl, __rotr, __rtl_chmod, __rtl_close, __rtl_creat, __rtl_heapwalk, __rtl_memset, __rtl_memset_, __rtl_mstick, __rtl_open, __rtl_read, __rtl_setUnmangleMode, __rtl_strcmp, __rtl_strcpy, __rtl_unmangle, __rtl_ustick, __rtl_write, __scalb, __scalbl, __searchenv, __searchstr, __set_matherr_handler, __set_matherrl_handler, __setargv, __setargv_ptr, __setcursortype, __seterrormode, __setmbcp, __setsystime, __sleep, __snprintf, __snwprintf, __sopen, __splitpath, __startup, __startupd, __stat, __stati64, __status87, __stkbase, __stkchk, __stpcpy, __strdate, __streams, __strerror, __stricoll, __strncoll, __strnicoll, __strtime, __strtold, __sys_errlist, __sys_nerr, __tccmp, __tccpy, __tclen, __tcschr, __tcsclen, __tcscmp, __tcscoll, __tcscspn, __tcsdec, __tcsicmp, __tcsicoll, __tcsinc, __tcslwr, __tcsnbcnt, __tcsncat, __tcsnccat, __tcsnccmp, __tcsnccnt, __tcsnccoll, __tcsnccpy, __tcsncicmp, __tcsncicoll, __tcsncmp, __tcsncoll, __tcsncpy, __tcsncset, __tcsnextc, __tcsnicmp, __tcsnicoll, __tcsninc, __tcsnset, __tcspbrk, __tcsrchr, __tcsrev, __tcsset, __tcsspn, __tcsspnp, __tcsstr, __tcstok, __tcsupr, __tempnam, __timezone, __tiny_ldble, __tzname, __tzset, __ui64toa, __ui64tow, __ultow, __unadopt_thread, __unlink, __unsetuserhandler, __upper, __utime, __version, __vsnprintf, __vsnwprintf, __waccess, __wargv, __wargv_default_expand, __wasctime, __wchdir, __wchmod, __wcreat, __wcsdup, __wcserror, __wcsicmp, __wcsicoll, __wcslwr, __wcsncoll, __wcsnicmp, __wcsnicoll, __wcsnset, __wcspcpy, __wcsrev, __wcsset, __wcstold, __wcsupr, __wctime, __wenviron, __wenvsize, __wexecl, __wexecle, __wexeclp, __wexeclpe, __wexecv, __wexecve, __wexecvp, __wexecvpe, __wexitargv, __wexitargv_ptr, __wexpand_wild, __wfdopen, __wfindclose, __wfindfirst, __wfindfirsti64, __wfindnext, __wfindnexti64, __wfnmerge, __wfnsplit, __wfopen, __wfreopen, __wfsopen, __wfullpath, __wgetcurdir, __wgetcwd, __wgetdcwd, __wgetenv, __wherex, __wherey, __wmakepath, __wmemchr, __wmemcpy, __wmemset, __wmkdir, __wmktemp, __wopen, __woscmd, __wosenv, __wperror, __wpopen, __wputenv, __wremove, __wrename, __write, __wrmdir, __wrtl_chmod, __wrtl_creat, __wrtl_open, __wscroll, __wsearchenv, __wsearchstr, __wsetargv, __wsetargv_ptr, __wsetlocale, __wsopen, __wspawnl, __wspawnle, __wspawnlp, __wspawnlpe, __wspawnv, __wspawnve, __wspawnvp, __wspawnvpe, __wsplitpath, __wstartup, __wstartupd, __wstat, __wstati64, __wstrdate, __wstrtime, __wsystem, __wtempnam, __wtmpnam, __wtof, __wtoi, __wtoi64, __wtol, __wtold, __wtzname, __wtzset, __wunlink, __wutime, _abort, _abs, _access, _acos, _acosl, _alloca, _asctime, _asin, _asinl, _atan, _atan2, _atan2f, _atan2l, _atanl, _atexit, _atof, _atoi, _atol, _basename, _bsearch, _btowc, _calloc, _ceil, _ceill, _cgets, _chdir, _chmod, _chsize, _clearerr, _clock, _close, _closedir, _clreol, _clrscr, _cos, _cosf, _cosh, _coshl, _cosl, _cprintf, _cputs, _creat, _creatnew, _creattemp, _cscanf, _ctime, _cvprintf, _cvscanf, _cwait, _delline, _difftime, _div, _dostounix, _dup, _dup2, _ecvt, _eof, _execl, _execle, _execlp, _execlpe, _execv, _execve, _execvp, _execvpe, _exit, _exp, _expf, _expl, _fabs, _fabsl, _fclose, _fcloseall, _fcvt, _fdopen, _feof, _ferror, _fflush, _fgetc, _fgetchar, _fgetpos, _fgets, _fgetwc, _fgetws, _filelength, _fileno, _findclose, _findfirst, _findnext, _floor, _floorl, _flushall, _fmod, _fmodl, _fnmerge, _fnsplit, _fopen, _fprintf, _fputc, _fputchar, _fputs, _fputwc, _fputws, _fread, _free, _freopen, _frexp, _frexpl, _fscanf, _fseek, _fsetpos, _fstat, _ftell, _ftime, _fwprintf, _fwrite, _fwscanf, _gcvt, _getc, _getch, _getchar, _getche, _getcurdir, _getcwd, _getdate, _getdfree, _getdisk, _getenv, _getftime, _getpass, _getpid, _gets, _gettext, _gettextinfo, _gettime, _getw, _getwc, _getwchar, _gmtime, _gotoxy, _heapcheck, _heapcheckfree, _heapchecknode, _heapfillfree, _heapwalk, _highvideo, _hypot, _hypotl, _insline, _isalnum, _isalpha, _isascii, _isatty, _iscntrl, _isdigit, _isgraph, _islower, _isprint, _ispunct, _isspace, _isupper, _iswalnum, _iswalpha, _iswascii, _iswcntrl, _iswdigit, _iswgraph, _iswlower, _iswprint, _iswpunct, _iswspace, _iswupper, _iswxdigit, _isxdigit, _itoa, _kbhit, _labs, _ldexp, _ldexpf, _ldexpl, _ldiv, _lfind, _localeconv, _localtime, _lock, _locking, _log, _log10, _log10l, _logf, _logl, _longjmp, _lowvideo, _lsearch, _lseek, _ltoa, _malloc, _mblen, _mbrtowc, _mbstowcs, _mbtowc, _memccpy, _memchr, _memcmp, _memcpy, _memicmp, _memmove, _memset, _mkdir, _mktemp, _mktime, _modf, _modfl, _movetext, _normvideo, _open, _opendir, _pcre_compile, _pcre_exec, _pcre_free, _pcre_info, _pcre_maketables, _pcre_malloc, _pcre_study, _pcre_version, _perror, _poly, _polyl, _pow, _pow10, _pow10l, _powf, _powl, _printf, _putc, _putch, _putchar, _putenv, _puts, _puttext, _putw, _putwc, _putwchar, _qsort, _raise, _rand, _read, _readdir, _realloc, _regcomp, _regerror, _regexec, _regfree, _remove, _rename, _rewind, _rewinddir, _rmdir, _rmtmp, _scanf, _searchpath, _setbuf, _setdate, _setdisk, _setftime, _setjmp, _setlocale, _setmode, _settime, _setvbuf, _signal, _sin, _sinf, _sinh, _sinhl, _sinl, _sleep, _snprintf, _snwprintf, _sopen, _spawnl, _spawnle, _spawnlp, _spawnlpe, _spawnv, _spawnve, _spawnvp, _spawnvpe, _sprintf, _sqrt, _sqrtf, _sqrtl, _srand, _sscanf, _stackavail, _stat, _stime, _stpcpy, _strcat, _strchr, _strcmp, _strcoll, _strcpy, _strcspn, _strdup, _strerror, _strftime, _stricmp, _strirshr, _strishr, _strlen, _strlwr, _strncat, _strncmp, _strncpy, _strnicmp, _strnset, _strpbrk, _strptime, _strrchr, _strrev, _strrshr, _strset, _strshr, _strspn, _strstr, _strtod, _strtok, _strtol, _strtoul, _strupr, _strxfrm, _swab, _swprintf, _swscanf, _system, _tan, _tanf, _tanh, _tanhl, _tanl, _tell, _tempnam, _textattr, _textbackground, _textcolor, _textmode, _time, _tmpfile, _tmpnam, _tolower, _toupper, _towlower, _towupper, _tzset, _ultoa, _umask, _ungetc, _ungetch, _ungetwc, _unixtodos, _unlink, _unlock, _utime, _vfprintf, _vfscanf, _vfwprintf, _vfwscanf, _vprintf, _vscanf, _vsnprintf, _vsnwprintf, _vsprintf, _vsscanf, _vswprintf, _vswscanf, _vwprintf, _vwscanf, _wait, _wclosedir, _wcrtomb, _wcscat, _wcschr, _wcscmp, _wcscoll, _wcscpy, _wcscspn, _wcsftime, _wcslen, _wcsncat, _wcsncmp, _wcsncpy, _wcspbrk, _wcsrchr, _wcsspn, _wcsstr, _wcstod, _wcstok, _wcstol, _wcstombs, _wcstoul, _wcsxfrm, _wctob, _wctomb, _wherex, _wherey, _window, _wmemcmp, _wmemmove, _wopendir, _wprintf, _wreaddir, _wrewinddir, _write, _wscanf, _wsearchpath CWSandbox info: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=155779c88df4e35695efb19e0d7a2366
The computer has been running good this weekend. It hasn't been slow and I haven't had any pop-ups. It actually scares me to say these things because I'm worried I'll jinx something! Also, it's a little like the kid is sick when the doctor is not around, but now that the doctor is here, the kid is fine. :)
Caysee,

Just go about using your computer as normal. Don't forget to update Trendmicro or uninstall it and install another one, don't go without one. My choice would be AVG Free, then do a full scan, I am sure it will find some leftovers, not to worry if it does, the main infection is gone.

I Will leave this thread open for you for a week or so in case you need to post back( hopefully you will not ) .



ATF Cleaner <– Yours to keep, run it now and then to clean out the clutter.

Malwarebytes <– Yours to keep also, check for updates and run a scan now and then.

Hijackthis <—Your call, hopefully you won't need it again, if you do you can redownload it

Combofix <—Is not a general cleaning tool, just run it with supervision or you can bork your system

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


    • [external image: Posted Image]

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


  • How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports


Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster, you can still install Spybot Search and Destroy but do not enable the TeaTimer in Spybot.


Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.6
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Safe Surfn
Ken
Ken, I've done everything you had listed. All is running well. The only thing that didn't work was the combofix /u. I've looked and can't find it anywhere so I'm not sure what happened to it, but I guess it's a good thing that its gone, right? I really appreciate all of the help I've gotten from this site. I'm so happy to see that there are still people willing to volunteer time to help others like this. I'll be back on payday to make a donation, but I don't think anyone could donate the amount of money that you all deserve! Thank you so much!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI