1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Cant Update Mse

Discussion in 'Malware Removal Help' started by BigDan, Apr 19, 2011.

  1. BigDan

    BigDan Registered Members

    Joined:
    Apr 19, 2011
    Messages:
    26
    Location:
    Toronto
    Operating System:
    Windows 7
    ahhh found it. here it is



    ComboFix 11-05-11.04 - user 05/12/2011 16:36:59.11.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1404 [GMT -4:00]
    Running from: c:\documents and settings\user\Desktop\Combo-Fix.exe
    Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files\Internet Explorer\iexplore.exe
    c:\windows\system32\NOTEPAD.EXE
    .
    Infected copy of c:\windows\system32\sfcfiles.dll was found and disinfected
    Restored copy from - c:\windows\ERDNT\cache\sfcfiles.dll
    .
    Infected copy of c:\windows\system32\userinit.exe was found and disinfected
    Restored copy from - c:\windows\ERDNT\cache\userinit.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-04-12 to 2011-05-12 )))))))))))))))))))))))))))))))
    .
    .
    2011-05-09 00:49 . 2011-05-09 00:49 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\ArcSoft
    2011-05-09 00:49 . 2011-05-09 07:58 -------- d--h--w- c:\documents and settings\All Users\Application Data\ArcSoft
    2011-05-09 00:46 . 2011-05-09 00:46 -------- d-----w- c:\program files\ArcSoft
    2011-05-09 00:46 . 2011-05-09 00:46 -------- d-----w- c:\program files\Common Files\ArcSoft
    2011-05-09 00:44 . 2011-05-09 07:54 -------- d-----w- c:\documents and settings\user\Application Data\ArcSoft
    2011-05-07 00:59 . 2011-05-07 00:59 -------- d-----w- c:\documents and settings\user\Application Data\RealHideIP
    2011-05-07 00:59 . 2011-05-07 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\RealHideIP
    2011-05-06 23:02 . 2011-05-06 23:02 -------- d-----w- c:\program files\Hotspot Shield
    2011-05-04 04:59 . 2011-05-04 04:59 -------- d-----w- c:\program files\UWC
    2011-05-04 04:52 . 2011-05-04 04:52 -------- d-----w- c:\program files\Webshots
    2011-05-04 04:52 . 2011-05-04 04:52 -------- d-----w- c:\documents and settings\user\Application Data\Webshots
    2011-05-03 17:31 . 2011-05-03 21:30 -------- d-----w- c:\program files\DesktopEarth
    2011-05-03 09:00 . 2011-05-03 09:00 -------- d-----w- c:\program files\Common Files\SWF Studio
    2011-05-03 09:00 . 2011-05-03 09:00 4580537 ----a-w- c:\windows\X-mas Eve Screensaver.scr
    2011-05-03 09:00 . 2011-05-03 09:00 45056 ----a-w- c:\windows\NCUNINST.EXe
    2011-05-03 09:00 . 2011-05-03 09:00 40960 ----a-w- c:\windows\NCLAUNCH.EXe
    2011-05-03 09:00 . 2011-05-03 09:00 -------- d-----w- c:\program files\X-mas Eve Screensaver
    2011-05-03 05:38 . 2011-04-18 17:17 307288 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2011-05-03 05:38 . 2011-04-18 17:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2011-05-03 05:38 . 2011-04-18 17:13 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2011-05-03 05:38 . 2011-04-18 17:16 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2011-05-03 05:38 . 2011-04-18 17:17 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-05-03 05:38 . 2011-04-18 17:16 102488 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2011-05-03 05:38 . 2011-04-18 17:16 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2011-05-03 05:38 . 2011-04-18 17:13 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2011-05-03 05:37 . 2011-04-18 17:25 40112 ----a-w- c:\windows\avastSS.scr
    2011-05-03 05:37 . 2011-04-18 17:25 199304 ----a-w- c:\windows\system32\aswBoot.exe
    2011-05-03 05:36 . 2011-05-03 05:36 -------- d-----w- c:\program files\AVAST Software
    2011-05-03 05:36 . 2011-05-03 05:36 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
    2011-05-02 10:17 . 2011-05-05 07:01 -------- d--h--w- c:\windows\$hf_mig$
    2011-05-02 09:28 . 2011-05-02 09:28 -------- d-----w- c:\program files\Microsoft Reader
    2011-05-02 09:28 . 2003-06-05 21:15 57436 ----a-w- c:\windows\DASShp.dll
    2011-05-02 09:28 . 2003-05-23 04:15 217174 ----a-w- c:\program files\Common Files\Microsoft Shared\ClearType\ctras.dll
    2011-04-25 23:42 . 2011-04-25 23:42 -------- d-----w- c:\program files\IObit
    2011-04-25 23:42 . 2011-04-25 23:42 -------- d-----w- c:\documents and settings\user\Application Data\IObit
    2011-04-23 02:08 . 2011-04-23 02:09 -------- d-----w- c:\program files\ERUNT
    2011-04-22 22:44 . 2011-04-23 16:54 -------- d-----w- c:\windows\SxsCaPendDel
    2011-04-22 22:35 . 2011-04-22 22:35 -------- d--h--w- c:\windows\system32\GroupPolicy
    2011-04-19 23:43 . 2011-05-03 18:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2011-04-19 00:36 . 2011-05-12 20:36 -------- d-----w- c:\windows\system32\wbem\Logs
    2011-04-19 00:20 . 2011-05-02 06:23 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Temp
    2011-04-17 19:52 . 2011-04-17 19:52 -------- d-----w- c:\program files\Easy-Hide-IP
    2011-04-16 18:10 . 2011-04-16 18:11 -------- d-----w- c:\program files\Common Files\Adobe
    2011-04-14 04:29 . 2011-04-14 04:29 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-05-09 00:52 . 2003-03-19 16:05 106496 ----a-w- c:\windows\system32\ATL71.DLL
    2011-04-10 20:53 . 2010-11-04 23:09 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-04-10 20:53 . 2009-09-07 06:27 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-03-07 05:33 . 2009-09-02 14:42 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-04 06:37 . 2008-04-14 09:42 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:21 . 2008-04-14 05:00 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:06 . 2008-04-14 09:42 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 23:06 . 2008-04-14 09:42 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:06 . 2008-04-14 09:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 11:41 . 2008-04-14 04:07 385024 ----a-w- c:\windows\system32\html.iec
    2011-02-17 13:18 . 2008-04-14 04:47 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-02-17 13:18 . 2008-04-14 04:45 357888 ----a-w- c:\windows\system32\drivers\srv.sys
    2011-02-17 12:32 . 2009-09-04 21:55 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2011-02-15 12:56 . 2008-04-14 09:39 290432 ----a-w- c:\windows\system32\atmfd.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2011-04-18 17:25 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2009-12-09 01:19 94208 ----a-w- c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2009-12-09 01:19 94208 ----a-w- c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2009-12-09 01:19 94208 ----a-w- c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
    @="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
    [HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
    2010-11-18 02:29 319488 ----a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
    @="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
    [HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
    2010-11-18 02:29 319488 ----a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
    @="{A759AFF6-5851-457D-A540-F4ECED148351}"
    [HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
    2010-11-18 02:29 319488 ----a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
    @="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
    [HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
    2010-11-18 02:29 319488 ----a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Bandwidth Monitor Pro"="c:\program files\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe" [2005-02-16 225280]
    "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
    "NCLaunch"="c:\windows\NCLAUNCH.EXe" [2011-05-03 40960]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2011-01-07 126976]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-09-25 202256]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
    "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-04-18 3460784]
    "ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
    "Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
    .
    c:\documents and settings\user\Start Menu\Programs\Startup\
    StickyNotes.exe [2009-5-19 483328]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Bandwidth Monitor Pro.lnk - c:\program files\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe [2005-1-8 225280]
    Evernote Clipper.lnk - c:\windows\Installer\{F761359C-9CED-45AE-9A51-9D6605CD55C4}\Evernote.ico [2010-12-16 293950]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^Secunia PSI.lnk]
    path=c:\documents and settings\user\Start Menu\Programs\Startup\Secunia PSI.lnk
    backup=c:\windows\pss\Secunia PSI.lnkStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2010-11-10 16:49 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2008-04-14 09:42 15360 ----a-w- c:\windows\system32\ctfmon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
    2011-01-07 23:53 126976 ----a-w- c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
    2008-04-14 02:13 208952 -c--a-w- c:\windows\ime\IMJP8_1\imjpmig.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2010-09-24 06:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
    2008-04-14 02:13 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
    2008-04-14 02:13 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QAGENT]
    2001-08-01 17:30 94208 ----a-w- c:\program files\QUICKENW\qagent.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
    2005-01-12 08:01 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
    2007-09-02 18:58 495616 ----a-w- c:\program files\RocketDock\RocketDock.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    2007-04-16 20:28 577536 ----a-w- c:\windows\SOUNDMAN.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    2008-08-01 19:23 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SugarSync]
    2010-11-18 02:29 14790656 ----a-w- c:\program files\SugarSync\SugarSyncManager.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2010-09-25 20:03 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
    "c:\\Program Files\\Shareaza\\Shareaza.exe"=
    "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "c:\\Program Files\\Ares\\Ares.exe"=
    "c:\\Program Files\\Opera\\opera.exe"=
    "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
    "c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
    "c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
    "c:\\Documents and Settings\\user\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
    "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\\Program Files\\wLite\\wLite.exe"=
    "c:\\Program Files\\wLite\\wService.exe"=
    "c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
    "c:\\Program Files\\RNX-N150UBE\\11n USB Wireless LAN Utility\\RtWLan.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\WINDOWS\\system32\\SUPDSvc.exe"=
    "c:\\Documents and Settings\\user\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
    "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
    "c:\\Program Files\\Easy-Hide-IP\\easy-hide-ip.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "85:TCP"= 85:TCP:BroadWave Web Server
    "1542:TCP"= 1542:TCP:Realtek WPS TCP Prot
    "1542:UDP"= 1542:UDP:Realtek WPS UDP Prot
    "53:UDP"= 53:UDP:Realtek AP UDP Prot
    .
    R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [02/05/2010 2:17 PM 691696]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [05/03/2011 1:38 AM 441176]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [05/03/2011 1:38 AM 307288]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [05/03/2011 1:38 AM 19544]
    R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS --> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
    R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [01/11/2010 1:49 AM 34712]
    R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\psia.exe [01/10/2011 10:24 AM 993848]
    R2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [01/10/2011 10:24 AM 399416]
    S1 MpKsl46d3683f;MpKsl46d3683f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A8B6A7AF-9ADF-48EE-B9B7-3EA6C65A6B94}\MpKsl46d3683f.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A8B6A7AF-9ADF-48EE-B9B7-3EA6C65A6B94}\MpKsl46d3683f.sys [?]
    S2 gupdate1ca303f1aa26f2a;Google Update Service (gupdate1ca303f1aa26f2a);c:\program files\Google\Update\GoogleUpdate.exe [09/08/2009 12:44 AM 133104]
    S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [12/23/2010 4:03 PM 44432]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [09/08/2009 12:44 AM 133104]
    S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
    S3 lgmdbus;LG Mobile driver (WDM);c:\windows\system32\drivers\lgmdbus.sys [06/14/2010 10:53 PM 89600]
    S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [12/15/2010 2:35 AM 131888]
    S3 wxpSvc;webcamXP Service;c:\program files\wLite\wService.exe [05/02/2010 5:34 PM 5027328]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-05-12 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-10-15 03:29]
    .
    2011-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-08 04:44]
    .
    2011-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-08 04:44]
    .
    2011-05-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1450960922-1801674531-1003Core.job
    - c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-02-14 23:18]
    .
    2011-05-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1450960922-1801674531-1003UA.job
    - c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-02-14 23:18]
    .
    2011-05-12 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-839522115-1450960922-1801674531-1003.job
    - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 07:02]
    .
    2011-05-12 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-839522115-1450960922-1801674531-1003.job
    - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 07:02]
    .
    2011-02-23 c:\windows\Tasks\switchShakeIcon.job
    - c:\program files\NCH Swift Sound\Switch\switch.exe [2010-06-21 02:57]
    .
    2011-05-12 c:\windows\Tasks\User_Feed_Synchronization-{E9078856-2E39-4A58-995F-39847461201E}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
    .
    2010-10-21 c:\windows\Tasks\wavepadShakeIcon.job
    - c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2010-06-21 02:59]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.ask.com?o=102876&l=dis&gct=hp
    mStart Page = hxxp://www.bigseekpro.com/tempcleaner/{22D7B6DD-AB2A-47B1-858B-1F515E6B2C37}
    IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
    IE: {{A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\Evernote\Evernote\EvernoteIE.dll/204
    FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\1shtgwx9.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://globeandmail.com/
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-05-12 17:10
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\wxpSvc]
    "ImagePath"="c:\program files\wLite\wService.exe /startedbyscm:5053B757-40E35B3B-webcamSRV"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(548)
    c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
    c:\windows\system32\Ati2evxx.dll
    .
    - - - - - - - > 'explorer.exe'(3396)
    c:\windows\system32\WININET.dll
    c:\windows\TEMP\logishrd\LVPrcInj01.dll
    c:\program files\RocketDock\RocketDock.dll
    c:\documents and settings\user\Application Data\Dropbox\bin\DropboxExt.13.dll
    c:\program files\SugarSync\SugarSyncShellExt.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\Ati2evxx.exe
    c:\windows\system32\Ati2evxx.exe
    c:\program files\AVAST Software\Avast\AvastSvc.exe
    c:\program files\Google\Update\1.3.21.53\GoogleCrashHandler.exe
    c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
    c:\program files\Hotspot Shield\bin\hsswd.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
    c:\documents and settings\user\Start Menu\Programs\Startup\StickyNotes.exe
    c:\program files\Foxit Software\Foxit Reader\Foxit Reader.exe
    c:\program files\Microsoft Office\OFFICE11\WINWORD.EXE
    .
    **************************************************************************
    .
    Completion time: 2011-05-12 17:22:06 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-05-12 21:22
    ComboFix2.txt 2011-05-08 19:11
    ComboFix3.txt 2011-05-02 10:22
    .
    Pre-Run: 20,541,530,112 bytes free
    Post-Run: 20,757,069,824 bytes free
    .
    - - End Of File - - 89DD24BB3FFF7F29C858AD0C31FB60E0
     
  2. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi BigDan

    Is Notepad working ok?
    I see that CF removed it again.
    If it's not working, following the instructions again that i posted earlier.
     
  3. BigDan

    BigDan Registered Members

    Joined:
    Apr 19, 2011
    Messages:
    26
    Location:
    Toronto
    Operating System:
    Windows 7
    it was removed but i followed your earlier instructions yesterday and its back to normal.
     
  4. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi BigDan

    The reason that CF has removed Notepad is a mystery.
    I spoke to the developer of CF and he can only put it down to Notepad being infected for some reason.

    How's the system running now?
     
  5. BigDan

    BigDan Registered Members

    Joined:
    Apr 19, 2011
    Messages:
    26
    Location:
    Toronto
    Operating System:
    Windows 7
    there dont seem to be any viruses per se but my computer starts lagging pretty badly at times. if im watching netflix i often find the computer at 100% capacity, while a couple months ago this never happened. back then i didnt really use netflix to be honest, but i never hit anything close to max cap while now i do it every day. i dont think ive installed anything that ram intensive. any idea what gives?
     
  6. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi BigDan

    You said at the beginning:
    Actually it isn't a decent amount.
    To run smoothly a system should always have at least 15% hard drive space spare.
    15% of 149GB ... is 22GB.

    So if you can free up some space you will notice a difference.

    also as it's XP when was the last time the system had a good defrag? ( not the usual windows defrag)

    Try this:

    Download Puran Disc Defragmenter
    Save it to your 'Desktop'.
    Run the program.
    From the main 'Puran Defrag' screen, click on the 'C' drive to highlight it.
    Then click on 'Defrag'.

    This program is faster than the built in Windows Defrag and is more efficient.
    Try not to use the m/c while the defrag is running.

    See if the system runs any faster afterwards.
     
  7. BigDan

    BigDan Registered Members

    Joined:
    Apr 19, 2011
    Messages:
    26
    Location:
    Toronto
    Operating System:
    Windows 7
    i looked at the hard disk again and realized i was down to 10 gigs! i guess that must've been one of the causes. ive moved another 13 over to my E drive, so now have 23/149 = 15% available.

    the program i downloaded from your link above wasnt actually the executable somehow. i did end up getting puran disc defragmenter from somewhere else. the first night i ran it, in the morning it was only 51% done, so i stopped it. ran it again last night. this morning there was no indication of whether it had finished or not (while last time it said how much was done, this time it didnt) however i did have the option of stopping it, indicating not all of it was done.

    unfortunately there's no text file log. however it did export some random stuff to an html link, pasted below.

    while writing the last sentence i've seen the performance go from 100% to 0% now back to 100%. i do have a number of applications open, but not too many. firefox with 3 tabs, 3 ms word windows, foxit reader, and calculator. oh and the virus scanner shields of course.




    2011/05/19 at 04:38:51
    Analysis Report For C:

    Total Files 183911
    Total Directories 21499
    Total Excluded 0
    Total Deleted 0
    Total Deleted Bytes 0 MB

    Total Fragmented Files 966
    Total Fragmented Directories 12
    Total Fragmented Bytes 40184 MB

    MFT Fragments 2
    Registry Fragments 2
    Pagefile Fragments 52

    Fragmentation Percentage By Size 32%
    Fragmentation Percentage By Count 0%


    The following files/directories are fragmented - Top 10

    Path Lcn Size in MB Fragments
    C:\Program Files\Secunia\PSI\psialog.txt2 35791 2.00 513
    C:\Program Files\Secunia\PSI\psialog.txt 11958 0.52 135
    C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\1XIAU6HD\assesscorrectintro[1].wmv 376455 23.96 130
    C:\System Volume Information\_restore{771AD627-E393-463A-8841-12A4937A3BE1}\RP56\snapshot\_REGISTRY_MACHINE_SOFTWARE 28102646 40.64 100
    C:\System Volume Information\_restore{771AD627-E393-463A-8841-12A4937A3BE1}\RP55\A0009928.vpx 15217577 43.64 98
    C:\System Volume Information\_restore{771AD627-E393-463A-8841-12A4937A3BE1}\RP54\A0009578.vpx 8134096 43.45 95
    C:\Documents and Settings\user\Application Data\Thunderbird\Profiles\ikmx17re.default\Mail\pop.gmail.com\Inbox 32289036 1071.37 91
    C:\System Volume Information\_restore{771AD627-E393-463A-8841-12A4937A3BE1}\RP54\A0009579.vpx 1472888 5.07 82
    C:\System Volume Information\_restore{771AD627-E393-463A-8841-12A4937A3BE1}\RP55\A0009929.vpx 16348547 5.07 82
    C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Outlook\outlook.pst 14391099 313.89 45
     
  8. BigDan

    BigDan Registered Members

    Joined:
    Apr 19, 2011
    Messages:
    26
    Location:
    Toronto
    Operating System:
    Windows 7
    Starbuck? any advice?
     
  9. Match

    Match Registered Members

    Joined:
    Apr 23, 2009
    Messages:
    4,175
    Location:
    Wolverhampton, UK.
    Computer Brand or Motherboard:
    Abit AN52
    CPU:
    AMD Athlon dual core 5000+
    Memory:
    4 Gig Corsair
    Hard Drive:
    160 Gb Hitachi 500 Gb Western Digital
    Graphics Card:
    Radion XFX 4650
    Power Supply:
    550W EZcool
    Sorry BigDan, I Apologise on behalf of Starbuck but he has gone away for the weekend I believe, But as soon as he gets back I'm sure he will reply, I also have to say on his behalf that it is unlike him not to have let you know prior or arranged for someone else to reply in his absence.
     
  10. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi BigDan

    That's odd, i just tried it myself and it did download the .exe version ok.

    It doesn't actually produce a text file that you can save.

    We really should try and see if OTL will run, it'll tell us a lot about your system.
    Please try again using this link:

    • Download OTL to your desktop.
      right click on the link and select 'Save Link/Target As'.

      if you have problems, try this download link:
      OTL
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check
    .

    just click the scan button and see if it runs ok.

    If not try this:

    Download OTS to your Desktop

    • Close ALL OTHER PROGRAMS.
    • Double-click on OTS.exe to start the program.
    • Check the box that says Scan All Users
    • Under Additional Scans check the following:

      o Reg - Desktop Components
      o Reg - Disabled MS Config Items
      o Reg - NetSvcs
      o Reg - Shell Spawning
      o Reg - Uninstall List
      o File - Lop Check
      o File - Purity Scan
      o Evnt - EvtViewer (last 10)

    then just click the run scan button.

    See if either will give you a report.
     
  11. BigDan

    BigDan Registered Members

    Joined:
    Apr 19, 2011
    Messages:
    26
    Location:
    Toronto
    Operating System:
    Windows 7
    Damn neither will run.

    OTL gives the same error as before, "OTL has encountered a problem and needs to close"

    same for OldTimer, exact same error.

    I should mention before they opened the avast antivirus caught it and asked whether to open in sandbox mode or normally. I said normally. If they had actually started running I would turn the virus scanner off, but since they're not even starting I assume that's not the issue.
     
  12. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    I've just remembered that Avast has a script blocking feature that is sometimes enabled, this may well prevent OTL from running.
    Remove any OTL icon you have.
    Try turning off all security software and script blocking measures.... then try downloading again.

    If that fails, try this:

    • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
    • Notepad will open with the results.
    • Follow the instructions that pop up for posting the results.
    • Close the program window, and delete the program from your desktop.
    Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

    Information on A/V control HERE
     
  13. BigDan

    BigDan Registered Members

    Joined:
    Apr 19, 2011
    Messages:
    26
    Location:
    Toronto
    Operating System:
    Windows 7
    I assume by script blocking measures you mean to disable avast. I did so. OTL / OTS still didnt work.

    It gave me two files, DDS and Attach, It said to add the Attach file as a zip but not sure if that can be done on a forum. So adding it be

    Here's DDS


    .
    DDS (Ver_11-05-19.01) - NTFSx86
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
    Run by user at 9:02:50 on 2011-05-23
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1260 [GMT -4:00]
    .
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\AVAST Software\Avast\avastUI.exe
    C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
    C:\Program Files\RocketDock\RocketDock.exe
    C:\WINDOWS\NCLAUNCH.EXe
    C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
    C:\Documents and Settings\user\Start Menu\Programs\Startup\StickyNotes.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Google\Update\1.3.21.53\GoogleCrashHandler.exe
    svchost.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
    C:\Program Files\Hotspot Shield\bin\hsswd.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Secunia\PSI\PSIA.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Secunia\PSI\sua.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\uTorrent\uTorrent.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox 4.0 Beta 8\firefox.exe
    C:\Program Files\Mozilla Firefox 4.0 Beta 8\plugin-container.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\user\Desktop\dds.scr
    C:\WINDOWS\system32\WSCRIPT.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.ask.com?o=102876&l=dis&gct=hp
    mStart Page = hxxp://www.bigseekpro.com/tempcleaner/{22D7B6DD-AB2A-47B1-858B-1F515E6B2C37}
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll
    BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1312.0\msneshellx.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: SMTTB2009 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\temp file cleaner db toolbar\tbcore3.dll
    TB: Clipmarks.Toolbar: {1205d44c-ffd2-44e5-aa1d-929dca37eb7a} - c:\program files\clipmarks\clipmarks.dll
    TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1312.0\msneshellx.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
    uRun: [Bandwidth Monitor Pro] "c:\program files\bandwidth monitor pro\Bandwidth Monitor Pro.exe" /minimized
    uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
    uRun: [NCLaunch] c:\windows\NCLAUNCH.EXe
    mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" ogui
    mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
    mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe
    mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    StartupFolder: c:\documents and settings\user\start menu\programs\startup\StickyNotes.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bandwi~1.lnk - c:\program files\bandwidth monitor pro\Bandwidth Monitor Pro.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\everno~1.lnk - c:\windows\installer\{f761359c-9ced-45ae-9a51-9d6605cd55c4}\Evernote.ico
    IE: Add to Evernote 4.0 - c:\program files\evernote\evernote\EvernoteIE.dll/204
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
    IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\evernote\evernote\EvernoteIE.dll/204
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: AtiExtEvent - Ati2evxx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\1shtgwx9.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://globeandmail.com/
    FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
    FF - plugin: c:\documents and settings\user\application data\facebook\npfbplugin_1_0_3.dll
    FF - plugin: c:\documents and settings\user\application data\mozilla\plugins\npgoogletalk.dll
    FF - plugin: c:\documents and settings\user\application data\mozilla\plugins\npgtpo3dautoplugin.dll
    FF - plugin: c:\documents and settings\user\local settings\application data\google\update\1.3.21.53\npGoogleUpdate3.dll
    FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\google updater\2.4.1970.7372\npCIDetect14.dll
    FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\microsoft silverlight\4.0.60129.0\npctrlui.dll
    FF - plugin: c:\program files\mozilla firefox 4.0 beta 8\plugins\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox 4.0 beta 8\plugins\npdjvu.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-5-3 441176]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-5-3 307288]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-5-3 19544]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-5-3 42184]
    R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
    R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2010-1-11 34712]
    R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-1-10 993848]
    R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-1-10 399416]
    S1 MpKsl46d3683f;MpKsl46d3683f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a8b6a7af-9adf-48ee-b9b7-3ea6c65a6b94}\mpksl46d3683f.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a8b6a7af-9adf-48ee-b9b7-3ea6c65a6b94}\MpKsl46d3683f.sys [?]
    S2 gupdate1ca303f1aa26f2a;Google Update Service (gupdate1ca303f1aa26f2a);c:\program files\google\update\GoogleUpdate.exe [2009-9-8 133104]
    S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [2010-12-23 44432]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-9-8 133104]
    S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys --> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?]
    S3 lgmdbus;LG Mobile driver (WDM);c:\windows\system32\drivers\lgmdbus.sys [2010-6-14 89600]
    S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [2010-12-15 131888]
    S3 wxpSvc;webcamXP Service;c:\program files\wlite\wService.exe [2010-5-2 5027328]
    S4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [2011-5-16 229376]
    .
    =============== Created Last 30 ================
    .
    2011-05-16 19:54:33 212992 ----a-w- c:\windows\system32\PuranDefrag.dll
    2011-05-16 19:54:32 221184 ----a-w- c:\windows\system32\PuranDC.exe
    2011-05-16 19:54:32 107008 ----a-w- c:\windows\system32\PuranDefragBT.exe
    2011-05-16 19:54:31 229376 ----a-w- c:\windows\system32\PuranDefragS.exe
    2011-05-16 19:54:31 1110016 ----a-w- c:\windows\system32\PuranFD.exe
    2011-05-16 19:54:31 -------- d-----w- c:\program files\Puran Defrag
    2011-05-12 21:49:53 638816 ----a-w- c:\windows\system32\iexplore.exe
    2011-05-12 21:49:25 69120 ----a-w- c:\windows\system32\notepad.exe
    2011-05-09 01:22:44 -------- d-----w- c:\documents and settings\user\local settings\application data\Nikon
    2011-05-09 01:10:22 49152 ----a-r- c:\documents and settings\user\application data\microsoft\installer\{d2fcc1ae-6311-47c5-8130-c6c66d77dd71}\ARPPRODUCTICON.exe
    2011-05-09 01:08:34 335872 ----a-r- c:\documents and settings\user\application data\microsoft\installer\{237cd223-1b9d-47e8-a76c-e478b83ccea2}\ARPPRODUCTICON.exe
    2011-05-09 01:05:39 57344 ----a-r- c:\documents and settings\user\application data\microsoft\installer\{87441a59-5e64-4096-a170-14efe67200c3}\ARPPRODUCTICON.exe
    2011-05-09 00:57:31 -------- d-----w- c:\documents and settings\all users\application data\Application
    2011-05-09 00:54:47 -------- d-----w- c:\program files\common files\muvee Technologies
    2011-05-09 00:54:20 -------- d-----w- c:\program files\common files\Nikon
    2011-05-09 00:54:10 -------- d-----w- c:\program files\Nikon
    2011-05-09 00:52:32 -------- d-----w- c:\documents and settings\all users\application data\Abstract
    2011-05-09 00:49:58 -------- d-----w- c:\documents and settings\user\local settings\application data\ArcSoft
    2011-05-09 00:49:41 -------- d--h--w- c:\documents and settings\all users\application data\ArcSoft
    2011-05-07 00:59:48 -------- d-----w- c:\documents and settings\user\application data\RealHideIP
    2011-05-07 00:59:48 -------- d-----w- c:\documents and settings\all users\application data\RealHideIP
    2011-05-06 23:02:25 -------- d-----w- c:\program files\Hotspot Shield
    2011-05-04 04:59:29 -------- d-----w- c:\program files\UWC
    2011-05-04 04:52:10 -------- d-----w- c:\program files\Webshots
    2011-05-04 04:52:10 -------- d-----w- c:\documents and settings\user\application data\Webshots
    2011-05-03 17:31:14 -------- d-----w- c:\program files\DesktopEarth
    2011-05-03 09:00:50 -------- d-----w- c:\program files\common files\SWF Studio
    2011-05-03 09:00:46 4580537 ----a-w- c:\windows\X-mas Eve Screensaver.scr
    2011-05-03 09:00:46 45056 ----a-w- c:\windows\NCUNINST.EXe
    2011-05-03 09:00:46 40960 ----a-w- c:\windows\NCLAUNCH.EXe
    2011-05-03 09:00:46 -------- d-----w- c:\program files\X-mas Eve Screensaver
    2011-05-03 05:38:29 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-05-03 05:37:48 40112 ----a-w- c:\windows\avastSS.scr
    2011-05-03 05:36:34 -------- d-----w- c:\program files\AVAST Software
    2011-05-03 05:36:34 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
    2011-05-02 10:17:13 -------- d--h--w- c:\windows\$hf_mig$
    2011-05-02 09:48:40 98816 ----a-w- c:\windows\sed.exe
    2011-05-02 09:48:40 89088 ----a-w- c:\windows\MBR.exe
    2011-05-02 09:48:40 256512 ----a-w- c:\windows\PEV.exe
    2011-05-02 09:48:40 161792 ----a-w- c:\windows\SWREG.exe
    2011-05-02 09:28:07 57436 ----a-w- c:\windows\DASShp.dll
    2011-05-02 09:28:07 217174 ----a-w- c:\program files\common files\microsoft shared\cleartype\ctras.dll
    2011-05-02 09:28:07 -------- d-----w- c:\program files\Microsoft Reader
    2011-04-25 23:42:22 -------- d-----w- c:\program files\IObit
    2011-04-25 23:42:22 -------- d-----w- c:\documents and settings\user\application data\IObit
    .
    ==================== Find3M ====================
    .
    2011-05-09 00:52:13 106496 ----a-w- c:\windows\system32\ATL71.DLL
    2011-04-10 20:53:13 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-04-10 20:53:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:06:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
    .
    ============= FINISH: 9:05:04.29 ===============










    Here's Attach


    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_11-05-19.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 09/02/2009 10:47:12 AM
    System Uptime: 05/22/2011 2:08:28 PM (19 hours ago)
    .
    Motherboard: Foxconn | | 8657MF-series
    Processor: Intel(R) Pentium(R) 4 CPU 2.66GHz | Socket 775 | 2659/133mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 149 GiB total, 22.023 GiB free.
    D: is CDROM (UDF)
    E: is FIXED (NTFS) - 233 GiB total, 19.303 GiB free.
    G: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Hotspot Shield Helper Miniport
    Device ID: ROOT\MS_HSSDRVMP\0000
    Manufacturer: Hotspot Shield
    Name: Realtek RTL8139/810x Family Fast Ethernet NIC - Hotspot Shield Helper Miniport
    PNP Device ID: ROOT\MS_HSSDRVMP\0000
    Service: HssDrv
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Hotspot Shield Helper Miniport
    Device ID: ROOT\MS_HSSDRVMP\0001
    Manufacturer: Hotspot Shield
    Name: WAN Miniport (Network Monitor) - Hotspot Shield Helper Miniport
    PNP Device ID: ROOT\MS_HSSDRVMP\0001
    Service: HssDrv
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Hotspot Shield Helper Miniport
    Device ID: ROOT\MS_HSSDRVMP\0002
    Manufacturer: Hotspot Shield
    Name: WAN Miniport (IP) - Hotspot Shield Helper Miniport
    PNP Device ID: ROOT\MS_HSSDRVMP\0002
    Service: HssDrv
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Hotspot Shield Helper Miniport
    Device ID: ROOT\MS_HSSDRVMP\0003
    Manufacturer: Hotspot Shield
    Name: Anchorfree HSS Adapter - Hotspot Shield Helper Miniport
    PNP Device ID: ROOT\MS_HSSDRVMP\0003
    Service: HssDrv
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Anchorfree HSS Adapter
    Device ID: ROOT\NET\0000
    Manufacturer: Anchorfree HSS Adapter
    Name: Anchorfree HSS Adapter
    PNP Device ID: ROOT\NET\0000
    Service: taphss
    .
    ==== System Restore Points ===================
    .
    RP1: 04/11/2011 9:04:51 AM - System Checkpoint
    RP2: 04/12/2011 12:33:30 AM - Installed Adobe Reader X (10.0.1).
    RP3: 04/13/2011 1:08:50 AM - System Checkpoint
    RP4: 04/14/2011 1:21:11 AM - System Checkpoint
    RP5: 04/14/2011 10:59:35 PM - Removed Adobe Reader X (10.0.1).
    RP6: 04/16/2011 2:06:37 AM - System Checkpoint
    RP7: 04/16/2011 2:10:27 PM - Installed Adobe Reader X (10.0.1).
    RP8: 04/19/2011 1:25:02 AM - System Checkpoint
    RP9: 04/20/2011 4:12:26 AM - System Checkpoint
    RP10: 04/21/2011 4:25:31 AM - System Checkpoint
    RP11: 04/22/2011 5:04:20 AM - System Checkpoint
    RP12: 04/22/2011 6:43:37 PM - Removed TouchCopy 09
    RP13: 04/22/2011 6:46:03 PM - Removed Windows Defender
    RP14: 04/22/2011 6:51:38 PM - Removed Habits
    RP15: 04/24/2011 1:45:12 AM - System Checkpoint
    RP16: 04/25/2011 2:15:16 AM - System Checkpoint
    RP17: 04/25/2011 7:44:00 PM - Advanced SystemCare RestorePoint
    RP18: 04/26/2011 8:16:56 PM - System Checkpoint
    RP19: 04/27/2011 8:46:13 PM - System Checkpoint
    RP20: 04/28/2011 9:49:03 PM - System Checkpoint
    RP21: 04/30/2011 3:35:32 AM - System Checkpoint
    RP22: 05/01/2011 4:56:19 AM - System Checkpoint
    RP23: 05/02/2011 8:10:50 AM - System Checkpoint
    RP24: 05/03/2011 1:36:34 AM - avast! Free Antivirus Setup
    RP25: 05/03/2011 3:03:26 AM - Software Distribution Service 3.0
    RP26: 05/03/2011 6:22:38 AM - Software Distribution Service 3.0
    RP27: 05/03/2011 1:31:03 PM - Installed DesktopEarth
    RP28: 05/03/2011 1:47:44 PM - Software Distribution Service 3.0
    RP29: 05/03/2011 5:31:19 PM - Installed Zune Desktop Theme
    RP30: 05/04/2011 3:00:41 AM - Software Distribution Service 3.0
    RP31: 05/05/2011 3:00:40 AM - Software Distribution Service 3.0
    RP32: 05/05/2011 5:13:50 AM - Software Distribution Service 3.0
    RP33: 05/06/2011 3:00:42 AM - Software Distribution Service 3.0
    RP34: 05/07/2011 3:00:57 AM - Software Distribution Service 3.0
    RP35: 05/08/2011 3:01:21 AM - Software Distribution Service 3.0
    RP36: 05/08/2011 8:46:20 PM - Installed Panorama Maker
    RP37: 05/08/2011 8:54:02 PM - Installed Nikon Transfer
    RP38: 05/08/2011 8:58:47 PM - Installed ViewNX
    RP39: 05/08/2011 9:02:31 PM - Installed Connect Service
    RP40: 05/08/2011 9:05:11 PM - Installed Picture Control Utility
    RP41: 05/08/2011 9:07:58 PM - Installed File Uploader
    RP42: 05/08/2011 9:10:13 PM - Installed Nikon Message Center
    RP43: 05/09/2011 3:00:52 AM - Software Distribution Service 3.0
    RP44: 05/09/2011 3:57:48 AM - Installed Connect Service
    RP45: 05/09/2011 2:46:10 PM - Software Distribution Service 3.0
    RP46: 05/10/2011 3:00:57 AM - Software Distribution Service 3.0
    RP47: 05/11/2011 3:01:54 AM - Software Distribution Service 3.0
    RP48: 05/11/2011 6:41:35 PM - Removed Ask Toolbar.
    RP49: 05/12/2011 3:00:41 AM - Software Distribution Service 3.0
    RP50: 05/13/2011 3:00:38 AM - Software Distribution Service 3.0
    RP51: 05/14/2011 3:00:56 AM - Software Distribution Service 3.0
    RP52: 05/15/2011 3:00:50 AM - Software Distribution Service 3.0
    RP53: 05/16/2011 3:00:52 AM - Software Distribution Service 3.0
    RP54: 05/17/2011 3:00:53 AM - Software Distribution Service 3.0
    RP55: 05/18/2011 3:00:48 AM - Software Distribution Service 3.0
    RP56: 05/19/2011 3:01:03 AM - Software Distribution Service 3.0
    RP57: 05/20/2011 3:00:50 AM - Software Distribution Service 3.0
    RP58: 05/21/2011 3:00:41 AM - Software Distribution Service 3.0
    RP59: 05/22/2011 3:00:45 AM - Software Distribution Service 3.0
    RP60: 05/22/2011 5:30:53 AM - Software Distribution Service 3.0
    RP61: 05/23/2011 3:00:43 AM - Software Distribution Service 3.0
    .
    ==== Installed Programs ======================
    .
    µTorrent
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader X (10.0.1)
    Advanced Renamer
    Apple Application Support
    Apple Software Update
    ArcSoft Panorama Maker 5
    Ares 2.1.4
    Ashampoo Burning Studio 6 FREE v.6.80
    ATI Catalyst Control Center
    ATI Display Driver
    Audacity 1.2.6
    AutoUpdate
    avast! Free Antivirus
    Bandwidth Monitor Pro
    BlazeDVD 6.0
    Britannica Ready Reference
    calibre
    Canon MP Navigator 3.0
    Canon MP160
    Capture NX 2
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    ccc-core-preinstall
    ccc-core-static
    ccc-utility
    CCC Help English
    CCleaner
    Clipmarks
    Command & Conquer Generals
    Command and ConquerTM Generals Zero Hour
    Compatibility Pack for the 2007 Office system
    CompositionTracker 1.1
    ConvertHelper 2.2
    COWON Media Center - jetAudio Basic VX
    DesktopEarth
    DivX Player
    DivX Version Checker
    DjVuLibre+DjView
    Document Express DjVu Plug-in
    Dropbox
    ERUNT 1.1j
    ESET Online Scanner v3
    Evernote v. 4.2.1
    Facebook Plug-In
    File Uploader
    FileASSASSIN
    Find+Run Robot 2.80.02
    FitDay
    Foxit Reader
    Free Burning Studio 1.0.9.9
    GoldWave v5.55
    GOM Player
    Google Chrome
    Google Earth
    Google Gears
    Google Talk (remove only)
    Google Talk Plugin
    Google Toolbar for Internet Explorer
    Google Update Helper
    Google Updater
    GoToMeeting 4.5.0.457
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB932716-v2)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB954708)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    InterActual Player
    iPod2PC 3.9.4
    IrfanView (remove only)
    iTunes
    Java Auto Updater
    Java DB 10.6.2.1
    Java(TM) 6 Update 24
    Java(TM) SE Development Kit 6 Update 24
    LastPass (uninstall only)
    LG MC USB U330 driver
    Logitech Vid
    Logitech Webcam Software
    LookInMyPC
    Magic ISO Maker v5.5 (build 0281)
    MagicDisc 2.7.106
    Malwarebytes' Anti-Malware
    Market Samurai
    Mavis Beacon Teaches Typing Deluxe 15
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
    Microsoft Office Outlook Connector
    Microsoft Office Professional Edition 2003
    Microsoft Reader
    Microsoft Silverlight
    Microsoft Sync Framework 2.0 Core Components (x86) ENU
    Microsoft Sync Framework 2.0 Provider Services (x86) ENU
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Windows Journal Viewer
    Mozilla Firefox 4.0.1 (x86 en-US)
    Mozilla Thunderbird (2.0.0.24)
    MP3 Cutter 1.3
    MP3 Speed 5.1.2
    MSN Toolbar
    MSVCRT
    Nero - Burning Rom
    Nikon Message Center
    Nikon Transfer
    NotesHolder 2.1
    Opera 11.10
    Picture Control Utility
    Pod to PC 4.004
    Power Audio Cutter 3.0
    Power MP3 WMA Converter 2008, (ver 4.20)
    PowerDVD
    Professor Answers
    Professor Teaches Excel 2003
    Puran Defrag Free Edition 7.3
    Quicken 2002 New User Edition
    QuickTime
    Real Alternative 2.0.2
    RealPlayer
    Realtek AC'97 Audio
    REALTEK Wireless LAN Driver and Utility
    RealUpgrade 1.0
    RescueTime 2.1.0
    ResumeMaker
    RocketDock 1.3.5
    Rosetta Stone Version 3
    Safari
    Samsung Universal Print Driver
    Secunia PSI (2.0.0.3001)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB2416400)
    Security Update for Windows Internet Explorer 8 (KB2482017)
    Security Update for Windows Internet Explorer 8 (KB2497640)
    Security Update for Windows Internet Explorer 8 (KB2510531)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB979402)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2160329)
    Security Update for Windows XP (KB2183461)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296199)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2412687)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2436673)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2479628)
    Security Update for Windows XP (KB2479943)
    Security Update for Windows XP (KB2481109)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485376)
    Security Update for Windows XP (KB2485663)
    Security Update for Windows XP (KB2503658)
    Security Update for Windows XP (KB2506212)
    Security Update for Windows XP (KB2506223)
    Security Update for Windows XP (KB2507618)
    Security Update for Windows XP (KB2508272)
    Security Update for Windows XP (KB2508429)
    Security Update for Windows XP (KB2509553)
    Security Update for Windows XP (KB2511455)
    Security Update for Windows XP (KB2524375)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371-v2)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972260)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974455)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB976325)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981349)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982381)
    Security Update for Windows XP (KB982665)
    Security Update for Windows XP (KB982802)
    Segoe UI
    Shareaza 2.4.0.0
    Skins
    Skype web features
    Skype™ 4.1
    Speccy
    SugarSync - WebSync
    SugarSync Manager
    Switch Sound File Converter
    SyncToy 2.1 (x86)
    T3Desk 2010 Build Version 10.01
    Temp File Cleaner
    Temp File Cleaner DB Toolbar
    The KMPlayer (remove only)
    TimeMe Timer Stopwatch CL 1.4.0
    TypingMaster Pro
    TypingMaster TypingTest
    Unlocker 1.9.0
    UnlockMe
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB2362765)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB961503)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971029)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Update for Windows XP (KB976749)
    Update for Windows XP (KB978207)
    Update for Windows XP (KB980182)
    UpdateMyDrivers
    VC80CRTRedist - 8.0.50727.4053
    ViewNX
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    VLC media player 1.0.1
    WavePad Sound Editor
    WebFldrs XP
    Webshots Desktop
    Winamp
    Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
    Windows Genuine Advantage Notifications (KB905474)
    Windows Internet Explorer 8
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Upload Tool
    Windows Media Format 11 runtime
    WinRAR archiver
    WordPerfect Office 2002
    X-mas Eve Screensaver Screen Saver
    Youtube Music Downloader V3.7.1
    Zune Desktop Theme
    .
    ==== Event Viewer Messages From Past Week ========
    .
    05/16/2011 3:03:53 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft Silverlight (KB2526954).
    05/16/2011 3:01:33 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for .NET Framework 2.0 SP2 and 3.5 SP1 on Windows Server 2003 and Windows XP x86 (KB2446704).
    05/16/2011 3:01:22 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB954430).
    05/16/2011 3:01:14 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB973688).
    .
    ==== End Of File ===========================
     
  14. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi BigDan

    Thanks for the reports.

    Whatever problems you're still experiencing is not down to malware.
    Everything looks ok now.

    The only thing that does stand out is the unnecessary startup entries.
    Although they are legit programs, they don't need to run at startup as they can be run manually if required.
    These are the ones:
    uRun: [Bandwidth Monitor Pro] "c:\program files\bandwidth monitor pro\Bandwidth Monitor Pro.exe" /minimized
    uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
    uRun: [NCLaunch] c:\windows\NCLAUNCH.EXe
    mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
    mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe

    But stopping them is down to users choice.


    The other i'll mention is this:
    BHO: SMTTB2009 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\temp file cleaner db toolbar\tbcore3.dll
    This entry is classed as 'Open to Debate', read this and decide:
    http://www.systemlookup.com/search.php?type=clsid&client=malwaresearch-ff&search=fcbccb87-9224-4b8d-b117-f56d924beb18

    it can be removed using the add/remove.
     

Share This Page