This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Here are my logs

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

IE will not open on my PC (I am using FF now); IE won't do anything. Even with a fresh IE download, I click on it, or try to RUN it, and I get a window that says, "Windows cannot find iexplore.exe". I can see it in my programs file, but cannot do anything with it. I have and use; Zonealarm, Ad-Aware, AVG8, CCleaner, Glary Utilities, Spyblaster, and Spybot Search and Destroy. I took my PC to the local repair shop, and I believe they ran a paid-for version of AVG, then told me that they couldn't get all the infections out within budget (they say my PC isn't worth the few hundred dollars to "clean" it).

First, I want to keep this machine, and second, I want to know how to do this in the future.

Thank you very much,

Bosan

P.S. In following your instructions, I did not see the "ADDREPLY" button mentioned. I hope I am doing this properly.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:29:46 PM, on 1/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\wfxsnt40.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Pwrchute\ups.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mybluelight.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\BLSearch\SearchEnh1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {0ADAD48A-BA3B-3D15-B4CC-964446AAC2FD} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar4.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar4.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u…pdate_1-0-0.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsr.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/02d8c718121dc0264318/…ip/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCD5A227-8720-497B-AF5F-4403E94342E3} (CDDM Object) - https://netservices.verizon.net/portal/veri…/DSLControl.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: UPS - APC PowerChute plus (UPS) - APC - C:\Program Files\Pwrchute\ups.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 10347 bytes


Malwarebytes' Anti-Malware 1.32
Database version: 1653
Windows 5.1.2600 Service Pack 3

1/14/2009 6:05:29 PM
mbam-log-2009-01-14 (18-05-29).txt

Scan type: Quick Scan
Objects scanned: 52965
Time elapsed: 6 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7545d8c8-f53c-4e2f-8fa0-d248ef4a6e61} (Rogue.Installer) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSfpmp.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems. HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that it happens.

Please do not run any other tool untill instructed to do so!
Please reply to this thread, do not start another!
Please tell me about any problems that have occurred during the fix.
Please tell me of any other symptoms you may be having as these can help also.
Please try as much as possible not to run anything while executing a fix.

If you follow these instructions, everything should go smoothly.

I am currently looking at your log now and will be back as soon as possible with your instructions.
while you are waiting one other thing that can be of good use is an uninstall list so please do the following

Make an uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in your next reply.

download and run RSIT

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt<- (will be maximized) and info.txt<- (will be minimized)

:information and logs:

In your next post I need the following

1.uninstall list from hijackthis
2.the two logs from RSIT

Gringo
Gringo, Thank you for your help. Following is my "uninstall" list. I tried five times to get RSIT.exe to run, with a computer restart in the middle, and each time got to the part that says,"Performing registry dump" (about 35 to 40 seconds) and a window pops up titled "Autolt Error, and says, "Line-1: Error: error parsing function call." Weather I click on OK or just cancel it, RSIT dissappears from the screen. Also, last night I tried to run Windows Update, and nothing happened; just like the problem with IE. Acrobat.com Acrobat.com Ad-Aware Adobe Acrobat 4.0, 5.0 Adobe AIR Adobe AIR Adobe Flash Player ActiveX Adobe PageMaker 7.0 Adobe Photoshop 6.0 Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 9 Arachnophilia 5.3 ArcSoft Software Suite Ask Toolbar AutoCAD R14.0 AVG Free 8.0 BlueLight Search Enhancements Brother HL-5140 CCleaner (remove only) Concord WinFax Plugin v3.0 CutePDF Writer 2.3 DiscWizard 2003 ERUNT 1.1j FileZilla Client 3.1.3 getPlus® for Adobe Glary Utilities 2.8.0.366 Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer HighMAT Extension to Microsoft Windows XP CD Writing Wizard HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows XP (KB952287) HP PrecisionScan Pro and Utilities Icon Restore 1.0 Icon Suite 2.1.12 Internet Explorer Q903235 IrfanView (remove only) Java™ 6 Update 4 Java™ 6 Update 6 Java™ 6 Update 7 LiveReg (Symantec Corporation) Macromedia Dreamweaver 4 Macromedia Extension Manager Macromedia Fireworks 4 Magnifier Powertoy for Windows XP Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft Data Access Components KB870669 Microsoft FrontPage 2002 Microsoft Image Composer 1.5 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money 2000 Standard Edition Microsoft National Language Support Downlevel APIs Microsoft Office XP Professional Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.0.5) MSN MSN Messenger 6.2 Nero - Burning Rom Nikon Message Center Norton SystemWorks 2002 NVIDIA Drivers Nvu 1.0 OpenOffice.org 2.4 Picasa 2 PictureProject PowerChute plus 5.2.1 PowerDVD QuickTime RealPlayer Sam Spade version 1.14 Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 8 (KB960714) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 8 (KB911565) Security Update for Windows Media Player 8 (KB917734) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Sierra Utilities SolidWorks 98 SolidWorks 98Plus SolidWorks 98Plus Client SolidWorks 98Plus Viewer Spybot - Search & Destroy Spybot - Search & Destroy 1.5.2.20 SpywareBlaster 4.1 Symantec WinFax PRO Tweak UI Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Verizon Online Help and Support VIA Rhine-Family Fast-Ethernet Adapter Windows Backup Utility Windows Internet Explorer 8 Beta 2 Windows Registry Guide Windows XP Service Pack 3 WinZip Yahoo! Toolbar ZoneAlarm
Hello


ok try this one

Download DDS

  • Download to your desktop DDS from one of the links below:

    Link1
    Link2
    Link3

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finish it will open 2 reports.
  • Copy/paste both reports back here and remove DDS from your desktop.

let me have the two logs it produces



gringo
Gringo, While DDS was running, a line appeared on the "Black Screen" saying, "FINDSTR: Cannot read…..(then something about a string. I couldn't finish typing it fast enough to get the whole thing.) Also, the ATTACH.txt file told me to zip it before posting it. I don't know how to do that. I hope I haven't done any damge. Thank you, Bosan UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-01-07.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 11/5/2001 3:28:59 AM System Uptime: 1/17/2009 10:02:56 AM (1 hours ago) Motherboard: ECS | | P4VXASD2 Processor: Intel® Pentium® 4 CPU 1.80GHz | FC-478 | 1800/100mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 75 GiB total, 61.278 GiB free. D: is CDROM () E: is FIXED (NTFS) - 38 GiB total, 26.774 GiB free. ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1318: 1/16/2009 12:46:18 PM - System Checkpoint ==== Installed Programs ====================== Acrobat.com Ad-Aware Adobe Acrobat 4.0, 5.0 Adobe AIR Adobe Flash Player ActiveX Adobe PageMaker 7.0 Adobe Photoshop 6.0 Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 9 Arachnophilia 5.3 ArcSoft Software Suite Ask Toolbar AutoCAD R14.0 AVG Free 8.0 BlueLight Search Enhancements Brother HL-5140 CCleaner (remove only) Concord WinFax Plugin v3.0 CutePDF Writer 2.3 DiscWizard 2003 ERUNT 1.1j FileZilla Client 3.1.3 getPlus® for Adobe Glary Utilities 2.8.0.366 Google Toolbar for Internet Explorer HighMAT Extension to Microsoft Windows XP CD Writing Wizard HijackThis 2.0.2 HomeSite 3.0 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows XP (KB952287) HP PrecisionScan Pro and Utilities Icon Restore 1.0 Icon Suite 2.1.12 Internet Explorer Q903235 IrfanView (remove only) Java™ 6 Update 4 Java™ 6 Update 6 Java™ 6 Update 7 LiveReg (Symantec Corporation) Macromedia Dreamweaver 4 Macromedia Extension Manager Macromedia Fireworks 4 Magnifier Powertoy for Windows XP Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft Data Access Components KB870669 Microsoft FrontPage 2002 Microsoft Image Composer 1.5 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money 2000 Standard Edition Microsoft National Language Support Downlevel APIs Microsoft Office XP Professional Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.0.5) MSN MSN Messenger 6.2 Nero - Burning Rom Nikon Message Center Norton CleanSweep Norton Speed Disk 6.0 for Windows NT Norton SystemWorks 2002 Norton Utilities 2002 for Windows NVIDIA Drivers Nvu 1.0 OpenOffice.org 2.4 Picasa 2 PictureProject PowerChute plus 5.2.1 PowerDVD QuickTime RealPlayer Sam Spade version 1.14 Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 8 (KB960714) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 8 (KB911565) Security Update for Windows Media Player 8 (KB917734) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Sierra Utilities SolidWorks 98 SolidWorks 98Plus SolidWorks 98Plus Client SolidWorks 98Plus Viewer Spybot - Search & Destroy Spybot - Search & Destroy 1.5.2.20 SpywareBlaster 4.1 Symantec Network Drivers Update Symantec WinFax PRO Tweak UI Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Verizon Online Help and Support VIA Rhine-Family Fast-Ethernet Adapter WebFldrs XP Windows Backup Utility Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Beta 2 Windows Registry Guide Windows XP Service Pack 3 WinZip Yahoo! Toolbar ZoneAlarm ==== Event Viewer Messages From Past Week ======== 1/14/2009 11:48:01 AM, error: Service Control Manager [7000] - The Automatic LiveUpdate Scheduler service failed to start due to the following error: The system cannot find the path specified. 1/14/2009 1:37:08 PM, error: DCOM [10000] - Unable to start a DCOM Server: {0002DF01-0000-0000-C000-000000000046}. The error: "%2" Happened while starting this command: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -Embedding 1/15/2009 6:49:14 PM, error: Service Control Manager [7023] - The TrueVector Internet Monitor service terminated with the following error: An instance of the service is already running. 1/17/2009 11:23:18 AM, error: Service Control Manager [7016] - The BrSplService service has reported an invalid current state 0. ==== End Of File ==================== DDS (Ver_09-01-07.01) - NTFSx86 Run by [removed] at 11:23:11.24 on Sat 01/17/2009 Internet Explorer: 8.0.6001.18241 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.121 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\brsvc01a.exe C:\WINDOWS\System32\brss01a.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE C:\WINDOWS\system32\wfxsnt40.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Pwrchute\ups.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\fxssvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\bodillinc.THEBIGONE\Desktop\dds.com ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = 127.0.0.1 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.mybluelight.com/s/search?r=minisearch uURLSearchHooks: URLSearchHook Class: {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} - c:\program files\blsearch\SearchEnh1.dll uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll mWinlogon: System=c:\windows\system32\svch?st.exe, BHO: AutorunsDisabled - No File BHO: {BDF3E430-B101-42AD-A544-FADC6B084872} - No File BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: {0ADAD48A-BA3B-3D15-B4CC-964446AAC2FD} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar5.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar5.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {F5735C15-1FB2-41FE-BA12-242757E69DDE} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [WinFaxAppPortStarter] wfxsnt40.exe mRun: [nwiz] nwiz.exe /install mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\zoneal~1.lnk - c:\program files\zone labs\zonealarm\zonealarm.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll IE: {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - {1FBA04EE-3024-11D2-8F1F-0000F87ABD16} c:\program files\irfanview\ebay\ebay.htm - c:\program files\irfanview\ebay\ebay.htm\inprocserver32 does not exist! Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll AppInit_DLLs: avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\bodill~1.the\applic~1\mozilla\firefox\profiles\8q90me4v.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157 FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg8\toolbarff\components\vmAVGConnector.dll FF - plugin: c:\program files\real\realone player\netscape6\nppl3260.dll FF - plugin: c:\program files\real\realone player\netscape6\nprjplug.dll FF - plugin: c:\program files\real\realone player\netscape6\nprpjplug.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-6 97928] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-1-6 26824] R4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664] R4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-1-6 875288] R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-6 231704] R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-6 76040] R4 NProtectService;Norton Unerase Protection;c:\program files\norton systemworks\norton utilities\NPROTECT.EXE [2002-10-17 135168] R4 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2004-3-13 177496] S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter;c:\windows\system32\drivers\NSDriver.sys [2008-4-29 15648] S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-12-6 33752] S4 NAVAP;NAVAP;c:\windows\system32\drivers\NAVAP.SYS [2004-1-17 184416] S4 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] =============== Created Last 30 ================ ==================== Find3M ==================== 2009-01-09 14:25 637,984 a——- c:\windows\system32\dllcache\iexplore.exe 2008-12-14 08:59 5,699,584 a——- c:\windows\system32\dllcache\mshtml.dll 2008-12-11 05:57 333,952 a——- c:\windows\system32\drivers\srv.sys 2008-12-11 05:57 333,952 ——– c:\windows\system32\dllcache\srv.sys 2008-11-07 16:45 2,174,976 ——– c:\windows\system32\dllcache\WMVCore.dll 2008-10-24 06:21 455,296 ——– c:\windows\system32\dllcache\mrxsmb.sys 2008-10-23 07:36 286,720 a——- c:\windows\system32\gdi32.dll 2008-10-23 07:36 286,720 ——– c:\windows\system32\dllcache\gdi32.dll 2008-10-10 09:51 74,992 a——- c:\docume~1\bodill~1.the\applic~1\GDIPFONTCACHEV1.DAT 2008-07-21 11:03 449,043 a——- c:\program files\RegSeeker.zip 2008-07-21 10:23 788,434 a——- c:\program files\RegpairSetup.exe 2008-06-27 19:42 2,223,444 a——- c:\program files\FreeWebshop.org2.2.9_R2.zip 2008-06-27 08:28 133,227,519 a——- c:\program files\OOo_2.4.1_Win32Intel_install_wJRE_en-US.exe 2008-06-24 12:08 1,786,594 a——- c:\program files\Arachnophilia.exe 2008-06-11 16:34 6,890,528 a——- c:\program files\nvu-1.0-win32-installer-full.exe 2008-05-29 15:56 37,375 a——- c:\program files\openoffice.org-xsltfilter.cab 2008-05-29 15:56 2,490,452 a——- c:\program files\openoffice.org-writer.cab 2008-05-29 15:56 207,388 a——- c:\program files\openoffice.org-testtool.cab 2008-05-29 15:55 2,504,975 a——- c:\program files\openoffice.org-pyuno.cab 2008-05-29 15:55 51,973 a——- c:\program files\openoffice.org-onlineupdate.cab 2008-05-29 15:55 1,090,334 a——- c:\program files\openoffice.org-math.cab 2008-05-29 15:55 118,910 a——- c:\program files\openoffice.org-javafilter.cab 2008-05-29 15:55 1,254,017 a——- c:\program files\openoffice.org-impress.cab 2008-05-29 15:55 86,870 a——- c:\program files\openoffice.org-graphicfilter.cab 2008-05-29 15:55 919,329 a——- c:\program files\openoffice.org-draw.cab 2008-05-29 15:55 2,769 a——- c:\program files\openoffice.org-emailmerge.cab 2008-05-29 15:55 2,031,954 a——- c:\program files\openoffice.org-core09.cab 2008-05-29 15:55 293,078 a——- c:\program files\openoffice.org-core08.cab 2008-05-29 15:55 3,842,531 a——- c:\program files\openoffice.org-core07.cab 2008-05-29 15:54 28,847,705 a——- c:\program files\openoffice.org-core06.cab 2008-05-29 15:50 18,634,513 a——- c:\program files\openoffice.org-core05.cab 2008-05-29 15:49 16,503,595 a——- c:\program files\openoffice.org-core04.cab 2008-05-29 15:48 9,117,929 a——- c:\program files\openoffice.org-core03.cab 2008-05-29 15:48 3,860,980 a——- c:\program files\openoffice.org-core02.cab 2008-05-29 15:47 15,104,219 a——- c:\program files\openoffice.org-core01.cab 2008-05-29 15:47 4,694,039 a——- c:\program files\openoffice.org-calc.cab 2008-05-29 15:47 1,803,630 a——- c:\program files\openoffice.org-base.cab 2008-05-29 15:46 43,005 a——- c:\program files\openoffice.org-activex.cab 2008-05-29 15:46 4,372,992 a——- c:\program files\openofficeorg24.msi 2008-05-29 15:46 217 a——- c:\program files\setup.ini 2006-02-03 13:30 188,406 a——- c:\program files\updatecdr4_53_71.exe 2004-07-13 08:26 169,744 a——- c:\docume~1\bodill~1.the\applic~1\shb.dat 2004-03-01 17:05 58,472 a——- c:\program files\floorplan.dwg 2004-03-01 16:46 98,490 a——- c:\program files\BDlogo.dwg 2004-02-29 01:10 52,611 a——- c:\program files\superD.dwg 2004-02-24 03:00 10,003 a——- c:\program files\acad14.cfg 2004-02-24 02:58 78,538 a——- c:\program files\DeIsL2.isu 2004-02-24 02:58 7,471,616 a——- c:\program files\acad.exe 2004-02-18 19:23 116,953 a——- c:\program files\BDwings.dwg 2003-05-31 03:33 536 a——- c:\program files\acad.err 2003-04-03 19:28 32,849 a——- c:\program files\Scaffold Disk.dwg 2003-03-29 13:47 80,755 a——- c:\program files\DeIsL1.isu 2002-03-11 04:06 1,822,520 a——- c:\program files\instmsiw.exe 2002-03-11 03:45 1,708,856 a——- c:\program files\instmsia.exe 1997-05-06 05:27 90,358 a——- c:\program files\render.xmx 1997-05-06 05:27 1,333,248 a——- c:\program files\render.arx 1997-05-06 05:27 28,672 a——- c:\program files\lsobj.arx 1997-05-06 05:25 587,776 a——- c:\program files\asicfg.exe 1997-05-06 05:25 2,803 a——- c:\program files\asilisp.xmx 1997-05-06 05:25 524,800 a——- c:\program files\asilisp.arx 1997-05-06 05:25 2,625 a——- c:\program files\asiora7.xmx 1997-05-06 05:25 925,696 a——- c:\program files\asiora7.exe 1997-05-06 05:25 2,145 a——- c:\program files\asiodbc.xmx 1997-05-06 05:25 934,400 a——- c:\program files\asiodbc.exe 1997-05-06 05:25 5,121 a——- c:\program files\asidb3.xmx 1997-05-06 05:25 971,776 a——- c:\program files\asidb3.exe 1997-05-06 05:25 52,609 a——- c:\program files\asiloc.xmx 1997-05-06 05:25 38,705 a——- c:\program files\aseloc.xmx 1997-05-06 05:23 49,152 a——- c:\program files\dwf3.hdi 1997-05-06 05:23 13,312 a——- c:\program files\slide3.hdi 1997-05-06 05:23 17,408 a——- c:\program files\rblast3.hdi 1997-05-06 05:23 52,736 a——- c:\program files\gdi3.hdi 1997-05-06 05:23 48,640 a——- c:\program files\lfb3.hdi 1997-05-06 05:23 418,816 a——- c:\program files\dswhip.dll 1997-05-06 05:23 125,952 a——- c:\program files\dlint3.dll 1997-05-06 05:23 968 a——- c:\program files\acshell.pif 1997-05-06 05:18 1,828 a——- c:\program files\mtextmap.ini 1997-05-06 05:16 207,872 a——- c:\program files\whiptk.dll 1997-05-06 05:16 115,712 a——- c:\program files\dwfout.arx 1997-05-06 05:16 39,936 a——- c:\program files\dwfiu.arx 1997-05-06 05:16 100,352 a——- c:\program files\internet.arx 1997-05-06 05:16 3,392 a——- c:\program files\internet.avi 1997-05-06 05:16 47,104 a——- c:\program files\ddelib.dll 1997-05-05 23:15 44,544 a——- c:\program files\UNACAD.DLL 2008-09-27 10:31 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092720080928\index.dat ============= FINISH: 11:24:56.02 ==============
Hello Bosan

:run combofix:

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode.
This allows us to more easily help you should your computer have a problem after an attempted removal of malware.
It is a simple procedure that will only take a few moments of your time.


Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.
Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the report in your next post:

C:\ComboFix.txt

:information and logs:

In your next post I need the following

1.let me have the log from combofix
2.let me have a new hijackthis log

Gringo
Gringo,

Here are the results of the ComboFix and HJT, as you asked.

I am going to turn my anti-virus stuff back on; I hope that's oK.

Thank you again,
Bosan

ComboFix 09-01-18.06 - bodillinc 2009-01-19 11:14:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.205 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\TDSSosvd.dat
c:\windows\winhelp.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys


((((((((((((((((((((((((( Files Created from 2008-12-19 to 2009-01-19 )))))))))))))))))))))))))))))))
.

2009-01-16 14:10 . 2009-01-16 14:10 d——– C:\rsit
2009-01-14 18:28 . 2009-01-14 18:28 d——– c:\program files\Trend Micro
2009-01-14 18:24 . 2009-01-14 18:24 d——– c:\program files\ERUNT
2009-01-14 17:55 . 2009-01-14 17:55 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-14 17:55 . 2009-01-14 17:55 d——– c:\documents and settings\bodillinc.THEBIGONE\Application Data\Malwarebytes
2009-01-14 17:55 . 2009-01-14 17:55 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-14 17:55 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 17:55 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-09 11:48 . 2002-10-12 20:51 529,151 –a—— c:\windows\_detmp.1
2009-01-09 11:48 . 2001-09-10 15:03 128,000 –a—— c:\windows\_detmp.2
2009-01-07 18:04 . 2009-01-07 18:04 d——– c:\windows\ie8updates
2009-01-07 10:54 . 2009-01-07 10:56 d–h-c— c:\windows\ie8
2009-01-06 13:03 . 2009-01-19 10:02 d——– c:\windows\system32\drivers\Avg
2009-01-06 13:03 . 2009-01-06 13:03 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2009-01-06 13:03 . 2009-01-06 13:03 76,040 –a—— c:\windows\system32\drivers\avgtdix.sys
2009-01-06 13:03 . 2009-01-06 13:03 10,520 –a—— c:\windows\system32\avgrsstx.dll
2009-01-06 13:02 . 2009-01-06 13:02 d——– c:\documents and settings\bodillinc.THEBIGONE\Application Data\AVGTOOLBAR
2009-01-02 08:43 . 2009-01-02 11:09 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-01-02 08:42 . 2009-01-02 08:42 d——– c:\program files\Common Files\iS3
2009-01-02 08:42 . 2009-01-02 11:13 d——– c:\documents and settings\All Users\Application Data\STOPzilla!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-19 16:06 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-15 23:47 ——— d—–w c:\program files\Glary Utilities
2009-01-15 23:45 ——— d—–w c:\program files\AskBarDis
2009-01-09 19:19 ——— d—–w c:\program files\WinFax
2009-01-09 19:19 ——— d—–w c:\program files\PhoTags Express
2009-01-09 19:19 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-09 16:47 ——— d—–w c:\program files\Sierra On-Line
2009-01-09 15:41 689,664 —-a-w c:\windows\Internet Logs\xDB4.tmp
2009-01-09 15:41 2,925,568 —-a-w c:\windows\Internet Logs\xDB3.tmp
2009-01-07 18:36 ——— d—–w c:\documents and settings\bodillinc.THEBIGONE\Application Data\OpenOffice.org2
2009-01-06 18:21 ——— d—–w c:\program files\Free Window Registry Repair
2009-01-06 18:02 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-12-30 02:43 ——— d—–w c:\program files\AutoCAD R14
2008-12-27 20:30 ——— d—–w c:\program files\SpywareBlaster
2008-12-27 00:49 ——— d—–w c:\program files\CCleaner
2008-12-16 14:37 ——— d—–w c:\program files\Pwrchute
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-06 20:26 ——— d—–w c:\program files\Common Files\Adobe AIR
2008-12-06 20:25 ——— d—–w c:\program files\Common Files\Adobe
2008-12-06 20:15 ——— d—–w c:\documents and settings\All Users\Application Data\NOS
2008-12-06 20:05 ——— d—–w c:\program files\NOS
2008-12-03 15:20 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-10-10 14:51 74,992 —-a-w c:\documents and settings\bodillinc.THEBIGONE\Application Data\GDIPFONTCACHEV1.DAT
2008-07-21 16:03 449,043 —-a-w c:\program files\RegSeeker.zip
2008-07-21 15:23 788,434 —-a-w c:\program files\RegpairSetup.exe
2008-06-28 00:42 2,223,444 —-a-w c:\program files\FreeWebshop.org2.2.9_R2.zip
2008-06-27 13:28 133,227,519 —-a-w c:\program files\OOo_2.4.1_Win32Intel_install_wJRE_en-US.exe
2008-06-24 17:08 1,786,594 —-a-w c:\program files\Arachnophilia.exe
2008-06-11 21:34 6,890,528 —-a-w c:\program files\nvu-1.0-win32-installer-full.exe
2008-05-29 20:56 37,375 —-a-w c:\program files\openoffice.org-xsltfilter.cab
2008-05-29 20:56 207,388 —-a-w c:\program files\openoffice.org-testtool.cab
2008-05-29 20:56 2,490,452 —-a-w c:\program files\openoffice.org-writer.cab
2008-05-29 20:55 919,329 —-a-w c:\program files\openoffice.org-draw.cab
2008-05-29 20:55 86,870 —-a-w c:\program files\openoffice.org-graphicfilter.cab
2008-05-29 20:55 51,973 —-a-w c:\program files\openoffice.org-onlineupdate.cab
2008-05-29 20:55 3,842,531 —-a-w c:\program files\openoffice.org-core07.cab
2008-05-29 20:55 293,078 —-a-w c:\program files\openoffice.org-core08.cab
2008-05-29 20:55 2,769 —-a-w c:\program files\openoffice.org-emailmerge.cab
2008-05-29 20:55 2,504,975 —-a-w c:\program files\openoffice.org-pyuno.cab
2008-05-29 20:55 2,031,954 —-a-w c:\program files\openoffice.org-core09.cab
2008-05-29 20:55 118,910 —-a-w c:\program files\openoffice.org-javafilter.cab
2008-05-29 20:55 1,254,017 —-a-w c:\program files\openoffice.org-impress.cab
2008-05-29 20:55 1,090,334 —-a-w c:\program files\openoffice.org-math.cab
2008-05-29 20:54 28,847,705 —-a-w c:\program files\openoffice.org-core06.cab
2008-05-29 20:50 18,634,513 —-a-w c:\program files\openoffice.org-core05.cab
2008-05-29 20:49 16,503,595 —-a-w c:\program files\openoffice.org-core04.cab
2008-05-29 20:48 9,117,929 —-a-w c:\program files\openoffice.org-core03.cab
2008-05-29 20:48 3,860,980 —-a-w c:\program files\openoffice.org-core02.cab
2008-05-29 20:47 4,694,039 —-a-w c:\program files\openoffice.org-calc.cab
2008-05-29 20:47 15,104,219 —-a-w c:\program files\openoffice.org-core01.cab
2008-05-29 20:47 1,803,630 —-a-w c:\program files\openoffice.org-base.cab
2008-05-29 20:46 43,005 —-a-w c:\program files\openoffice.org-activex.cab
2008-05-29 20:46 4,372,992 —-a-w c:\program files\openofficeorg24.msi
2008-05-29 20:46 217 —-a-w c:\program files\setup.ini
2006-02-03 18:30 188,406 —-a-w c:\program files\updatecdr4_53_71.exe
2004-07-13 13:26 169,744 —-a-w c:\documents and settings\bodillinc.THEBIGONE\Application Data\shb.dat
2004-03-01 22:05 58,472 —-a-w c:\program files\floorplan.dwg
2004-03-01 21:46 98,490 —-a-w c:\program files\BDlogo.dwg
2004-02-29 06:10 52,611 —-a-w c:\program files\superD.dwg
2004-02-24 08:00 10,003 —-a-w c:\program files\acad14.cfg
2004-02-24 07:58 78,538 —-a-w c:\program files\DeIsL2.isu
2004-02-24 07:58 7,471,616 —-a-w c:\program files\acad.exe
2004-02-19 00:23 116,953 —-a-w c:\program files\BDwings.dwg
2003-05-31 08:33 536 —-a-w c:\program files\acad.err
2003-04-04 00:28 32,849 —-a-w c:\program files\Scaffold Disk.dwg
2003-03-29 18:47 80,755 —-a-w c:\program files\DeIsL1.isu
2002-03-11 09:06 1,822,520 —-a-w c:\program files\instmsiw.exe
2002-03-11 08:45 1,708,856 —-a-w c:\program files\instmsia.exe
1997-05-06 10:27 90,358 —-a-w c:\program files\render.xmx
1997-05-06 10:27 28,672 —-a-w c:\program files\lsobj.arx
1997-05-06 10:27 1,333,248 —-a-w c:\program files\render.arx
1997-05-06 10:25 971,776 —-a-w c:\program files\asidb3.exe
1997-05-06 10:25 934,400 —-a-w c:\program files\asiodbc.exe
1997-05-06 10:25 925,696 —-a-w c:\program files\asiora7.exe
1997-05-06 10:25 587,776 —-a-w c:\program files\asicfg.exe
1997-05-06 10:25 524,800 —-a-w c:\program files\asilisp.arx
1997-05-06 10:25 52,609 —-a-w c:\program files\asiloc.xmx
1997-05-06 10:25 5,121 —-a-w c:\program files\asidb3.xmx
1997-05-06 10:25 38,705 —-a-w c:\program files\aseloc.xmx
1997-05-06 10:25 2,803 —-a-w c:\program files\asilisp.xmx
1997-05-06 10:25 2,625 —-a-w c:\program files\asiora7.xmx
1997-05-06 10:25 2,145 —-a-w c:\program files\asiodbc.xmx
1997-05-06 10:23 968 —-a-w c:\program files\acshell.pif
1997-05-06 10:23 52,736 —-a-w c:\program files\gdi3.hdi
1997-05-06 10:23 49,152 —-a-w c:\program files\dwf3.hdi
1997-05-06 10:23 48,640 —-a-w c:\program files\lfb3.hdi
1997-05-06 10:23 418,816 —-a-w c:\program files\dswhip.dll
1997-05-06 10:23 17,408 —-a-w c:\program files\rblast3.hdi
1997-05-06 10:23 13,312 —-a-w c:\program files\slide3.hdi
1997-05-06 10:23 125,952 —-a-w c:\program files\dlint3.dll
1997-05-06 10:18 1,828 —-a-w c:\program files\mtextmap.ini
1997-05-06 10:16 47,104 —-a-w c:\program files\ddelib.dll
1997-05-06 10:16 39,936 —-a-w c:\program files\dwfiu.arx
1997-05-06 10:16 3,392 —-a-w c:\program files\internet.avi
1997-05-06 10:16 207,872 —-a-w c:\program files\whiptk.dll
1997-05-06 10:16 115,712 —-a-w c:\program files\dwfout.arx
1997-05-06 10:16 100,352 —-a-w c:\program files\internet.arx
1997-05-06 04:15 44,544 —-a-w c:\program files\UNACAD.DLL
2008-09-27 15:31 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092720080928\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 17:20 279944 –a—— c:\program files\AskBarDis\bar\bin\askBar5.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar5.dll" [2008-07-17 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NeroCheck"="c:\windows\System32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-06 1261336]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-09-10 c:\windows\system32\WFXSNT40.EXE]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
ZoneAlarm.lnk - c:\program files\Zone Labs\ZoneAlarm\zonealarm.exe [2002-10-13 623936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iexplore.exe]
"Debugger"=c:\windows\system32\ropfnqz.exe

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2004-05-28 14:22 4882432 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV Agent]
–a—— 2002-02-27 11:27 75384 c:\progra~1\NORTON~1\NORTON~1\NAVAPW32.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QD FastAndSafe]
–a—— 2002-02-27 11:27 75384 c:\progra~1\NORTON~1\NORTON~1\NAVAPW32.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
——— 2008-09-16 11:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymWSC"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SAVScan"=3 (0x3)
"NPFMntor"=2 (0x2)
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"SBService"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"PrinTray"=c:\windows\System32\spool\DRIVERS\W32X86\2\printray.exe
"LXSUPMON"=c:\windows\System32\LXSUPMON.EXE RUN
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Verizon_McciTrayApp"=c:\program files\Verizon\McciTrayApp.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-06 97928]
R4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-06 875288]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-06 231704]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-06 76040]
R4 NProtectService;Norton Unerase Protection;c:\program files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE [2002-10-17 135168]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-06 33752]
.
Contents of the 'Scheduled Tasks' folder

2009-01-19 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-10-29 17:58]

2006-10-12 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Common Files\Symantec Shared\NMAIN.EXE [2004-08-13 20:17]
.
- - - - ORPHANS REMOVED - - - -

BHO-{0ADAD48A-BA3B-3D15-B4CC-964446AAC2FD} - (no file)
HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe


.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - hxxp://download.verizon.net/sfp/Cabs/max_update/VOLUpdate_1-0-0.cab
DPF: {BCD5A227-8720-497B-AF5F-4403E94342E3} - hxxps://netservices.verizon.net/portal/verizon/passwdchg/activex/DSLControl.cab
DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} - hxxp://www2.verizon.net/update/msnwebinstall/includes/vzWebIns.CAB
FF - ProfilePath - c:\documents and settings\bodillinc.THEBIGONE\Application Data\Mozilla\Firefox\Profiles\8q90me4v.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-19 11:20:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\KasperskyLab\AVP32]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\KasperskyLab\Components]
@DACL=(02 0000)
@SACL=
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\BRSS01A.EXE
c:\windows\system32\LexBceS.exe
c:\windows\system32\Lexpps.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\progra~1\NORTON~1\SPEEDD~1\NOPDB.EXE
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\fxssvc.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-19 11:23:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-19 16:23:27

Pre-Run: 65,642,688,512 bytes free
Post-Run: 65,532,858,368 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=2 Sets=1,2,3,4
284 — E O F — 2009-01-14 16:56:09



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:26:01 AM, on 1/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\BLSearch\SearchEnh1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar5.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar5.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u…pdate_1-0-0.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCD5A227-8720-497B-AF5F-4403E94342E3} (CDDM Object) - https://netservices.verizon.net/portal/veri…/DSLControl.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 9822 bytes
hello

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

KILLALL::

File::
c:\windows\_detmp.1
c:\windows\_detmp.2
c:\windows\Internet Logs\xDB4.tmp
c:\windows\Internet Logs\xDB3.tmp
c:\documents and settings\bodillinc.THEBIGONE\Application Data\GDIPFONTCACHEV1.DAT
c:\windows\system32\ropfnqz.exe

Folder::
c:\program files\AskBarDis

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-

[-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

[-HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iexplore.exe]
"Debugger"=-


Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
[external image: Posted Image]
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

:Clean temp files:

Download and Run ATF Cleaner
Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.Double-click ATF Cleaner.exe to open it.

Under Main choose: Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.
if you use Firefox: Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
if you use Opera: Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program

: Malwarebytes' Anti-Malware :

  • Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Update Java

Please download JavaRa and unzip it to your desktop.

  • Double-click on JavaRa.exe to start the program.
  • Click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a log file has been produced. Click OK.
  • A log file will pop up. Please save it to a convenient location.

Download the latest version of Java Runtime Environment (JRE) 6 Update 11.

  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on the download to install the newest version.

:information and logs:

In your next post I need the following

1.log from combofix
2.log from MBAM
3.new log from hijackthis

Gringo
Gringo,
Attached are the logs you requested.

A couple of things have happened; 1) "The J2SE Runtime Environment (JRE)… seems to have been updated, as this selection is not on the screen. I could not get the part to work where I save the link to "Windows Offline Installation" to my desktop. I ended up with two icons on my Desktop. Clicking on one got a a window saying, "jre-6u11-windows-i586-p.exe is not a valid Win32 application"; and the other got a window saying, "Windows cannot open this file, jre-6u11-windows-i586-p.exe.part.

Also, when my PC restarted after the ComboFix, IE seemed to try to start. it looked like it might work (I got s window that said, "Welcome to Explorer 8"), but i shut it down, and clicked on another window that made FF my default browser.

I can't think of anything else significant.

Thanks again,

Bosan



ComboFix 09-01-18.06 - bodillinc 2009-01-20 9:46:07.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.221 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\bodillinc.THEBIGONE\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\documents and settings\bodillinc.THEBIGONE\Application Data\GDIPFONTCACHEV1.DAT
c:\windows\_detmp.1
c:\windows\_detmp.2
c:\windows\Internet Logs\xDB3.tmp
c:\windows\Internet Logs\xDB4.tmp
c:\windows\system32\ropfnqz.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\bodillinc.THEBIGONE\Application Data\GDIPFONTCACHEV1.DAT
c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askBar1.dll
c:\program files\AskBarDis\bar\bin\askBar2.dll
c:\program files\AskBarDis\bar\bin\askBar3.dll
c:\program files\AskBarDis\bar\bin\askBar4.dll
c:\program files\AskBarDis\bar\bin\askBar5.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\askPopStp1.dll
c:\program files\AskBarDis\bar\bin\askPopStp2.dll
c:\program files\AskBarDis\bar\bin\askPopStp3.dll
c:\program files\AskBarDis\bar\bin\askPopStp4.dll
c:\program files\AskBarDis\bar\bin\askPopStp5.dll
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Cache\002BE373
c:\program files\AskBarDis\bar\Cache\002BE9FC.bin
c:\program files\AskBarDis\bar\Cache\002BF14C.bin
c:\program files\AskBarDis\bar\Cache\002BF4AA.bin
c:\program files\AskBarDis\bar\Cache\002BF7C1.bin
c:\program files\AskBarDis\bar\Cache\002BF998.bin
c:\program files\AskBarDis\bar\Cache\files.ini
c:\program files\AskBarDis\bar\History\search
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\bar\Settings\prevcfg.htm
c:\program files\AskBarDis\PopSwatter\History\notallow
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\windows\_detmp.1
c:\windows\_detmp.2
c:\windows\Internet Logs\xDB3.tmp
c:\windows\Internet Logs\xDB4.tmp

.
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.

2009-01-16 14:10 . 2009-01-16 14:10 d——– C:\rsit
2009-01-14 18:28 . 2009-01-14 18:28 d——– c:\program files\Trend Micro
2009-01-14 18:24 . 2009-01-14 18:24 d——– c:\program files\ERUNT
2009-01-14 17:55 . 2009-01-14 17:55 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-14 17:55 . 2009-01-14 17:55 d——– c:\documents and settings\bodillinc.THEBIGONE\Application Data\Malwarebytes
2009-01-14 17:55 . 2009-01-14 17:55 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-14 17:55 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 17:55 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-07 18:04 . 2009-01-07 18:04 d——– c:\windows\ie8updates
2009-01-07 10:54 . 2009-01-07 10:56 d–h-c— c:\windows\ie8
2009-01-06 13:03 . 2009-01-20 08:46 d——– c:\windows\system32\drivers\Avg
2009-01-06 13:03 . 2009-01-06 13:03 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2009-01-06 13:03 . 2009-01-06 13:03 76,040 –a—— c:\windows\system32\drivers\avgtdix.sys
2009-01-06 13:03 . 2009-01-06 13:03 10,520 –a—— c:\windows\system32\avgrsstx.dll
2009-01-06 13:02 . 2009-01-06 13:02 d——– c:\documents and settings\bodillinc.THEBIGONE\Application Data\AVGTOOLBAR
2009-01-02 08:43 . 2009-01-02 11:09 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-01-02 08:42 . 2009-01-02 08:42 d——– c:\program files\Common Files\iS3
2009-01-02 08:42 . 2009-01-02 11:13 d——– c:\documents and settings\All Users\Application Data\STOPzilla!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-19 16:39 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-19 16:38 ——— d—–w c:\program files\SpywareBlaster
2009-01-15 23:47 ——— d—–w c:\program files\Glary Utilities
2009-01-09 19:19 ——— d—–w c:\program files\WinFax
2009-01-09 19:19 ——— d—–w c:\program files\PhoTags Express
2009-01-09 19:19 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-09 16:47 ——— d—–w c:\program files\Sierra On-Line
2009-01-07 18:36 ——— d—–w c:\documents and settings\bodillinc.THEBIGONE\Application Data\OpenOffice.org2
2009-01-06 18:21 ——— d—–w c:\program files\Free Window Registry Repair
2009-01-06 18:02 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-12-30 02:43 ——— d—–w c:\program files\AutoCAD R14
2008-12-27 00:49 ——— d—–w c:\program files\CCleaner
2008-12-16 14:37 ——— d—–w c:\program files\Pwrchute
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-06 20:26 ——— d—–w c:\program files\Common Files\Adobe AIR
2008-12-06 20:25 ——— d—–w c:\program files\Common Files\Adobe
2008-12-06 20:15 ——— d—–w c:\documents and settings\All Users\Application Data\NOS
2008-12-06 20:05 ——— d—–w c:\program files\NOS
2008-12-03 15:20 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-07-21 16:03 449,043 —-a-w c:\program files\RegSeeker.zip
2008-07-21 15:23 788,434 —-a-w c:\program files\RegpairSetup.exe
2008-06-28 00:42 2,223,444 —-a-w c:\program files\FreeWebshop.org2.2.9_R2.zip
2008-06-27 13:28 133,227,519 —-a-w c:\program files\OOo_2.4.1_Win32Intel_install_wJRE_en-US.exe
2008-06-24 17:08 1,786,594 —-a-w c:\program files\Arachnophilia.exe
2008-06-11 21:34 6,890,528 —-a-w c:\program files\nvu-1.0-win32-installer-full.exe
2008-05-29 20:56 37,375 —-a-w c:\program files\openoffice.org-xsltfilter.cab
2008-05-29 20:56 207,388 —-a-w c:\program files\openoffice.org-testtool.cab
2008-05-29 20:56 2,490,452 —-a-w c:\program files\openoffice.org-writer.cab
2008-05-29 20:55 919,329 —-a-w c:\program files\openoffice.org-draw.cab
2008-05-29 20:55 86,870 —-a-w c:\program files\openoffice.org-graphicfilter.cab
2008-05-29 20:55 51,973 —-a-w c:\program files\openoffice.org-onlineupdate.cab
2008-05-29 20:55 3,842,531 —-a-w c:\program files\openoffice.org-core07.cab
2008-05-29 20:55 293,078 —-a-w c:\program files\openoffice.org-core08.cab
2008-05-29 20:55 2,769 —-a-w c:\program files\openoffice.org-emailmerge.cab
2008-05-29 20:55 2,504,975 —-a-w c:\program files\openoffice.org-pyuno.cab
2008-05-29 20:55 2,031,954 —-a-w c:\program files\openoffice.org-core09.cab
2008-05-29 20:55 118,910 —-a-w c:\program files\openoffice.org-javafilter.cab
2008-05-29 20:55 1,254,017 —-a-w c:\program files\openoffice.org-impress.cab
2008-05-29 20:55 1,090,334 —-a-w c:\program files\openoffice.org-math.cab
2008-05-29 20:54 28,847,705 —-a-w c:\program files\openoffice.org-core06.cab
2008-05-29 20:50 18,634,513 —-a-w c:\program files\openoffice.org-core05.cab
2008-05-29 20:49 16,503,595 —-a-w c:\program files\openoffice.org-core04.cab
2008-05-29 20:48 9,117,929 —-a-w c:\program files\openoffice.org-core03.cab
2008-05-29 20:48 3,860,980 —-a-w c:\program files\openoffice.org-core02.cab
2008-05-29 20:47 4,694,039 —-a-w c:\program files\openoffice.org-calc.cab
2008-05-29 20:47 15,104,219 —-a-w c:\program files\openoffice.org-core01.cab
2008-05-29 20:47 1,803,630 —-a-w c:\program files\openoffice.org-base.cab
2008-05-29 20:46 43,005 —-a-w c:\program files\openoffice.org-activex.cab
2008-05-29 20:46 4,372,992 —-a-w c:\program files\openofficeorg24.msi
2008-05-29 20:46 217 —-a-w c:\program files\setup.ini
2006-02-03 18:30 188,406 —-a-w c:\program files\updatecdr4_53_71.exe
2004-07-13 13:26 169,744 —-a-w c:\documents and settings\bodillinc.THEBIGONE\Application Data\shb.dat
2004-03-01 22:05 58,472 —-a-w c:\program files\floorplan.dwg
2004-03-01 21:46 98,490 —-a-w c:\program files\BDlogo.dwg
2004-02-29 06:10 52,611 —-a-w c:\program files\superD.dwg
2004-02-24 08:00 10,003 —-a-w c:\program files\acad14.cfg
2004-02-24 07:58 78,538 —-a-w c:\program files\DeIsL2.isu
2004-02-24 07:58 7,471,616 —-a-w c:\program files\acad.exe
2004-02-19 00:23 116,953 —-a-w c:\program files\BDwings.dwg
2003-05-31 08:33 536 —-a-w c:\program files\acad.err
2003-04-04 00:28 32,849 —-a-w c:\program files\Scaffold Disk.dwg
2003-03-29 18:47 80,755 —-a-w c:\program files\DeIsL1.isu
2002-03-11 09:06 1,822,520 —-a-w c:\program files\instmsiw.exe
2002-03-11 08:45 1,708,856 —-a-w c:\program files\instmsia.exe
1997-05-06 10:27 90,358 —-a-w c:\program files\render.xmx
1997-05-06 10:27 28,672 —-a-w c:\program files\lsobj.arx
1997-05-06 10:27 1,333,248 —-a-w c:\program files\render.arx
1997-05-06 10:25 971,776 —-a-w c:\program files\asidb3.exe
1997-05-06 10:25 934,400 —-a-w c:\program files\asiodbc.exe
1997-05-06 10:25 925,696 —-a-w c:\program files\asiora7.exe
1997-05-06 10:25 587,776 —-a-w c:\program files\asicfg.exe
1997-05-06 10:25 524,800 —-a-w c:\program files\asilisp.arx
1997-05-06 10:25 52,609 —-a-w c:\program files\asiloc.xmx
1997-05-06 10:25 5,121 —-a-w c:\program files\asidb3.xmx
1997-05-06 10:25 38,705 —-a-w c:\program files\aseloc.xmx
1997-05-06 10:25 2,803 —-a-w c:\program files\asilisp.xmx
1997-05-06 10:25 2,625 —-a-w c:\program files\asiora7.xmx
1997-05-06 10:25 2,145 —-a-w c:\program files\asiodbc.xmx
1997-05-06 10:23 968 —-a-w c:\program files\acshell.pif
1997-05-06 10:23 52,736 —-a-w c:\program files\gdi3.hdi
1997-05-06 10:23 49,152 —-a-w c:\program files\dwf3.hdi
1997-05-06 10:23 48,640 —-a-w c:\program files\lfb3.hdi
1997-05-06 10:23 418,816 —-a-w c:\program files\dswhip.dll
1997-05-06 10:23 17,408 —-a-w c:\program files\rblast3.hdi
1997-05-06 10:23 13,312 —-a-w c:\program files\slide3.hdi
1997-05-06 10:23 125,952 —-a-w c:\program files\dlint3.dll
1997-05-06 10:18 1,828 —-a-w c:\program files\mtextmap.ini
1997-05-06 10:16 47,104 —-a-w c:\program files\ddelib.dll
1997-05-06 10:16 39,936 —-a-w c:\program files\dwfiu.arx
1997-05-06 10:16 3,392 —-a-w c:\program files\internet.avi
1997-05-06 10:16 207,872 —-a-w c:\program files\whiptk.dll
1997-05-06 10:16 115,712 —-a-w c:\program files\dwfout.arx
1997-05-06 10:16 100,352 —-a-w c:\program files\internet.arx
1997-05-06 04:15 44,544 —-a-w c:\program files\UNACAD.DLL
2008-09-27 15:31 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092720080928\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NeroCheck"="c:\windows\System32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-06 1261336]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-09-10 c:\windows\system32\WFXSNT40.EXE]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
ZoneAlarm.lnk - c:\program files\Zone Labs\ZoneAlarm\zonealarm.exe [2002-10-13 623936]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2004-05-28 14:22 4882432 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV Agent]
–a—— 2002-02-27 11:27 75384 c:\progra~1\NORTON~1\NORTON~1\NAVAPW32.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QD FastAndSafe]
–a—— 2002-02-27 11:27 75384 c:\progra~1\NORTON~1\NORTON~1\NAVAPW32.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
——— 2008-09-16 11:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymWSC"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SAVScan"=3 (0x3)
"NPFMntor"=2 (0x2)
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"SBService"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"PrinTray"=c:\windows\System32\spool\DRIVERS\W32X86\2\printray.exe
"LXSUPMON"=c:\windows\System32\LXSUPMON.EXE RUN
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Verizon_McciTrayApp"=c:\program files\Verizon\McciTrayApp.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-06 97928]
R4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-06 875288]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-06 231704]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-06 76040]
R4 NProtectService;Norton Unerase Protection;c:\program files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE [2002-10-17 135168]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-06 33752]
.
Contents of the 'Scheduled Tasks' folder

2009-01-20 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-10-29 17:58]

2006-10-12 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Common Files\Symantec Shared\NMAIN.EXE [2004-08-13 20:17]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - hxxp://download.verizon.net/sfp/Cabs/max_update/VOLUpdate_1-0-0.cab
DPF: {BCD5A227-8720-497B-AF5F-4403E94342E3} - hxxps://netservices.verizon.net/portal/verizon/passwdchg/activex/DSLControl.cab
DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} - hxxp://www2.verizon.net/update/msnwebinstall/includes/vzWebIns.CAB
FF - ProfilePath - c:\documents and settings\bodillinc.THEBIGONE\Application Data\Mozilla\Firefox\Profiles\8q90me4v.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 09:51:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\KasperskyLab\AVP32]
@DACL=(02 0000)
@SACL=

[HKEY_LOCAL_MACHINE\software\KasperskyLab\Components]
@DACL=(02 0000)
@SACL=
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\BRSS01A.EXE
c:\windows\system32\LexBceS.exe
c:\windows\system32\Lexpps.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\progra~1\NORTON~1\SPEEDD~1\NOPDB.EXE
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\fxssvc.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-20 9:55:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-20 14:55:14
ComboFix2.txt 2009-01-19 16:23:59

Pre-Run: 65,597,407,232 bytes free
Post-Run: 65,571,377,152 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=2 Sets=1,2,3,4
301 — E O F — 2009-01-14 16:56:09


Malwarebytes' Anti-Malware 1.32
Database version: 1653
Windows 5.1.2600 Service Pack 3

1/20/2009 10:05:51 AM
mbam-log-2009-01-20 (10-05-51).txt

Scan type: Quick Scan
Objects scanned: 53230
Time elapsed: 3 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:33:43 AM, on 1/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\BLSearch\SearchEnh1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u…pdate_1-0-0.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCD5A227-8720-497B-AF5F-4403E94342E3} (CDDM Object) - https://netservices.verizon.net/portal/veri…/DSLControl.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 9682 bytes


Again, thanks.
Hello

things are looking alot better now.

lets retry updating java one more time, Delete everything you have so far for the java - jre-6u11-windows-i586-p.exe

Update Java

Please download JavaRa and unzip it to your desktop.

  • Double-click on JavaRa.exe to start the program.
  • Click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a log file has been produced. Click OK.
  • A log file will pop up. Please save it to a convenient location.

Download the latest version of Java Runtime Environment (JRE) 6 Update 11.

  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on the download to install the newest version.

:Kaspersky scan:

  • Please go to Kaspersky website and perform an online antivirus scan.

    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

:information and logs:

In your next post I need the following

1.log from kaspersky
2.new hijackthis log

Gringo
Gringo,

Again, the requested files are attached. The "J2SE Runtime Environment' still did not work as you described. First, it is not listed in the downloads as "J2SE" but as something else (I think JSE version 6, or something like that). However, I ended up with an icon on my desktop, and one in my System Tray. Yesterday, the icon on my desktop would open a window saying that (….. is not a valid Win32 application), same as before. As of this morning, if I click on it, I get a "ZoneAlarm' window asking if i want it to connect to the internet. When I clicked on "No" it started to load anyway, but I hit "Cancel" immediately. The icon in my System Tray opens a window that says, "About Java", and simply states, "Java Platform Standard Edition 6", and has a "Sun" logo, and a "Close" button (I closed it). Should I do some sort of uninstall on this stuff? Your directions said, "Do not use the Sun download manager.."

KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, January 21, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, January 20, 2009 15:58:15
Records in database: 1654946
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Files scanned: 159292
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 08:05:30


File name / Threat name / Threats count
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\67AC4FF0.htm Infected: Exploit.HTML.Mht 1

The selected area was scanned.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:57:10 AM, on 1/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\bodillinc.THEBIGONE\Local Settings\temp\jkos-bodillinc\binaries\ScanningProcess.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\BLSearch\SearchEnh1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u…pdate_1-0-0.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCD5A227-8720-497B-AF5F-4403E94342E3} (CDDM Object) - https://netservices.verizon.net/portal/veri…/DSLControl.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 9694 bytes

Gringo, thanks again. By the way, when this is over, can you recommend a program that is the most effective against this sort of infection?
Hello Bosan

I would like you to go here and check to see if java is working ok,
http://www.javatester.org/
Now click on Test the version of Java your browser is using
then let me know what it says inside the pink rectangle

Let me have another uninstall list please

uninstall list

Make an uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.

:information and logs:

In your next post I need the following

1.let me have the info from the pink rectangle
2.the uninstall list from hijackthis

Gringo
Gringo, The "Pink Rectangle" showed, "Java Version 1.6.0_11 from Sun Microsystems Inc.". Below is the HJT uninstall log. A few questions; 1) Since the maleware found by the Kaspersky scan had the name "Norton" in it, should I try to delete (or uninstall) everything on my computer with the name Norton in it? 2) When I open My Yahoo, among the things that flash by in the lower left hand corner of my screen is something that has J2 or JS2 in it (it goes by very fast), is this where I get my Java? 3) again, when this is over, can you recommend a preventative for such infections? Thanks again, Bosan Acrobat.com Acrobat.com Ad-Aware Adobe Acrobat 4.0, 5.0 Adobe AIR Adobe AIR Adobe Flash Player ActiveX Adobe PageMaker 7.0 Adobe Photoshop 6.0 Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 9 Arachnophilia 5.3 ArcSoft Software Suite Ask Toolbar AutoCAD R14.0 AVG Free 8.0 BlueLight Search Enhancements Brother HL-5140 CCleaner (remove only) Concord WinFax Plugin v3.0 CutePDF Writer 2.3 DiscWizard 2003 ERUNT 1.1j FileZilla Client 3.1.3 getPlus® for Adobe Glary Utilities 2.8.0.366 Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer HighMAT Extension to Microsoft Windows XP CD Writing Wizard HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows XP (KB952287) HP PrecisionScan Pro and Utilities Icon Restore 1.0 Icon Suite 2.1.12 Internet Explorer Q903235 IrfanView (remove only) Java™ 6 Update 11 Java™ 6 Update 7 LiveReg (Symantec Corporation) Macromedia Dreamweaver 4 Macromedia Extension Manager Macromedia Fireworks 4 Magnifier Powertoy for Windows XP Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft Data Access Components KB870669 Microsoft FrontPage 2002 Microsoft Image Composer 1.5 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money 2000 Standard Edition Microsoft National Language Support Downlevel APIs Microsoft Office XP Professional Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.0.5) MSN MSN Messenger 6.2 Nero - Burning Rom Nikon Message Center Norton SystemWorks 2002 NVIDIA Drivers Nvu 1.0 OpenOffice.org 2.4 Picasa 2 PictureProject PowerChute plus 5.2.1 PowerDVD QuickTime RealPlayer Sam Spade version 1.14 Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 8 (KB960714) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 8 (KB911565) Security Update for Windows Media Player 8 (KB917734) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Sierra Utilities SolidWorks 98 SolidWorks 98Plus SolidWorks 98Plus Client SolidWorks 98Plus Viewer Spybot - Search & Destroy Spybot - Search & Destroy 1.5.2.20 SpywareBlaster 4.1 Symantec WinFax PRO Tweak UI Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Verizon Online Help and Support VIA Rhine-Family Fast-Ethernet Adapter Windows Backup Utility Windows Internet Explorer 8 Beta 2 Windows Registry Guide Windows XP Service Pack 3 WinZip Yahoo! Toolbar ZoneAlarm
Hello Bosan

1) Since the maleware found by the Kaspersky scan had the name "Norton" in it, should I try to delete (or uninstall) everything on my computer with the name Norton in it?

No don't do that if you look C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine you can see it is in the Quarantine folder and that is the best place for it. ( if you know how to empty the Quarantine folder then go ahead and do that )

2) When I open My Yahoo, among the things that flash by in the lower left hand corner of my screen is something that has J2 or JS2 in it (it goes by very fast), is this where I get my Java?

acualy I don't know when i tried to go to yahoo now I didn't get anything like that I can tell you though that you don't have any maleware on your computer now- also looking at your logs a see you are using IE8 and as this is still in Beta I don't know anything about it or what it shows

3) again, when this is over, can you recommend a preventative for such infections?

Of course, below you will find my allclean speech and in it you will find alot of good info on staying clean

There is no one program or antivirus that will keep you completly safe and everyone if they spend time on the net will get infected with something sooner or later

uninstall some programs

1. click on start
2. then go to settings
3. after that you need control panel
4. look for the icon add/remove programs
click on the following programs

Ask Toolbar
Java™ 6 Update 7


and click on remove

This is my general post for when your logs show no more signs of malware ;)- Please let me know if you still are having problems with your computer and what these problems are

:Time for some housekeeping:
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • [external image: Posted Image]

:remove tools:
  • Let's clear out the programmes we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately.


    Please download OTCleanIt and save it to desktop. This tool will remove all the tools we used to clean your pc.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

:Set correct settings for files:
  • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
  • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
  • If unchecked please check Hide protected operating system files (Recommended)
  • If necessary check "Display content of system folders"
  • If necessary Uncheck Hide file extensions for known file types.
  • Click OK

:clear system restore points:
  • This is a good time to clear your existing system restore points and establish a new clean restore point:
  • Go to Start > All Programs > Accessories > System Tools > System Restore
  • Select Create a restore point, and Ok it.
  • Next, go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created.

:Make your Internet Explorer more secure:

please visit this page that gives instructions to do this
http://surfthenetsafely.com/ieseczone8.htm

:Turn On Automatic Updates:

Turn On Automatic Updates
1. Click Start, click Run, type sysdm.cpl, and then press ENTER.
2. Click the Automatic Updates tab, and then click to select one of the following options. We recommend that you select the Automatic (recommended) Automatically download recommended updates for my computer and install them

If you click this setting, click to select the day and time for scheduled updates to occur. You can schedule Automatic Updates for any time of day. Remember, your computer must be on at the scheduled time for updates to be installed. After you set this option, Windows recognizes when you are online and uses your Internet connection to find updates on the Windows Update Web site or on the Microsoft Update Web site that apply to your computer. Updates are downloaded automatically in the background, and you are not notified or interrupted during this process. An icon appears in the notification area of your taskbar when the updates are being downloaded. You can point to the icon to view the download status. To pause or to resume the download, right-click the icon, and then click Pause or Resume. When the download is completed, another message appears in the notification area so that you can review the updates that are scheduled for installation. If you choose not to install at that time, Windows starts the installation on your set schedule.

or visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

:antispyware programs:
  • you have a couple of good antispyware programs on this computer but you still can try some of these others to see if you like them also

    I would reccomend the download and installation of some or all of the following programs (all free), and the updating of them regularly:
  • WinPatrol As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.
  • Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
    totally free but for real-time protection you will have to pay a small one-time fee.
  • Spyware Blaster - By altering your registry, this program stops harmful sites from installing things like ActiveX Controls on your machines.
  • IE_Spyad - Works by placing known "bad" sites into your Internet Explorer "Restricted Zones" prohibiting them from doing potentially problematic things to your computer.

Consider a custom hosts file
Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

please read this great article by miekiemoes How to prevent Malware:
and
this great article by Tony Klein So How Did I Get Infected In First Place


Now you have followed my advice - it's time to lodge a complaint against what you have suffered………

Malware Complaints
If you were infected …. Stand Up and be Counted.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can then be closed.

Gringo
Gringo, Thank you very much for everything. I want to contribute to the financial support of WhattheTech, but do not like to put any such info on the internet. Is there a way to do this by check? Also, one of the other sites you asked me to use (Maybe Combofix?) had a donation icon. Can you tell me which one so that I can contact them about sending a check? Next, after following your instructions, I still have ATFcleaner, ERUNT and NTREGOPT on my desktop (along with malwarebytes, but you told me to keep that one); should I delete ATF, ERUNT and NTREGOPT manually? Also, I have uninstalled IE8, as the only reason it was on my computer is that I went to the first "IE download" site I could find when IE quit working. Even after all your work with me, the IE8 wouldn't work. I downloaded IE7, and it works just fine. Thanks again, and don't forget to send me that check information! Bosan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI