1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active Task manager not working but no error message.

Discussion in 'Malware and Virus Removal Archive' started by Vicki, 2009/07/08.

  1. 2009/07/08
    Vicki

    Vicki Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    413
    Likes Received:
    8
    [Active] Task manager not working but no error message.

    It was suggested in the WindowsXP forum that I post my logs here to be reviewed. I am having trouble using my task manager program, but do not receive any error messages when trying to access the program.

    It just flashes for a second, but appears as a "DOS" type window that opens? It opens/closes so quickly that I can't even read what it says in the heading/border.

    Here is the requested logs:

    DDS (Ver_09-06-26.01) - NTFSx86
    Run by amd at 13:43:56.45 on Tue 07/07/2009
    Internet Explorer: 6.0.2900.2180
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.991.573 [GMT -5:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    C:\WINDOWS\system32\svchost -k rpcss
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\WINDOWS\Explorer.EXE
    svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\MSN\MSNCoreFiles\msn.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Documents and Settings\amd\Desktop\dds.pif

    ============== Pseudo HJT Report ===============

    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    mDefault_Search_URL = hxxp://www.google.com/ie
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: ST: {9394ede7-c8b5-483e-8773-474bf36af6e4} - c:\program files\msn apps\st\01.03.0000.1005\en-xu\stmain.dll
    BHO: MSNToolBandBHO: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: MSN: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll
    TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    mRun: [VTTimer] VTTimer.exe
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
    DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://www.ipix.com/viewers/ipixx.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
    DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
    DPF: {56393399-041A-4650-94C7-13DFCB1F4665} - hxxp://www.pcpitstop.com/pestscan/pestscan.cab
    DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
    DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1134266582209
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198800691232
    DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxp://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37680.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
    DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
    DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
    DPF: {E001C731-5E37-4538-A5CB-8168736A2360} - hxxp://91.199.104.31/cab/ActiveQscan.cab
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Notify: avgrsstarter - avgrsstx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-28 335752]
    R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-11-12 27784]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-28 108552]
    R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-3 907032]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 298776]
    S2 gupdate1c9cb63f58a137c;Google Update Service (gupdate1c9cb63f58a137c);c:\program files\google\update\GoogleUpdate.exe [2009-5-2 133104]
    S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2008-2-4 44928]

    =============== Created Last 30 ================

    2009-07-07 12:37 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
    2009-07-06 14:00 <DIR> --d----- c:\windows\system32\wbem\Repository
    2009-07-06 13:55 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
    2009-06-18 15:34 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}

    ==================== Find3M ====================

    2009-07-06 14:10 335,752 a------- c:\windows\system32\drivers\avgldx86.sys
    2009-07-06 14:10 11,952 a------- c:\windows\system32\avgrsstx.dll
    2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll
    2009-05-07 10:44 344,064 a------- c:\windows\system32\localspl.dll
    2009-04-28 23:52 659,456 a------- c:\windows\system32\wininet.dll
    2009-04-28 23:52 81,920 -------- c:\windows\system32\ieencode.dll
    2009-04-17 04:58 1,846,656 a------- c:\windows\system32\win32k.sys
    2009-04-15 10:11 584,192 a------- c:\windows\system32\rpcrt4.dll
    2008-07-10 08:16 758 a------- c:\docume~1\amd\applic~1\wklnhst.dat
    2005-11-08 11:00 32 a--sh--- c:\windows\{6BCB0AE8-3381-4311-905A-CD5910AB9D21}.dat
    2005-11-08 11:00 32 a--sh--- c:\windows\system32\{D6845DBB-B1E7-42A2-B5F9-30E7D7A05BEF}.dat

    ============= FINISH: 13:44:51.26 ===============


    and the 2nd part:

    DDS (Ver_09-06-26.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 11/7/2005 4:19:05 PM
    System Uptime: 7/7/2009 1:27:55 PM (0 hours ago)

    Motherboard: PCCHIPS | | M861G
    Processor: AMD Sempron(tm) Processor 3000+ | CPU 1 | 1799/200mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 76 GiB total, 52.009 GiB free.
    D: is CDROM ()
    E: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1250: 4/8/2009 11:52:52 PM - System Checkpoint
    RP1251: 4/10/2009 12:37:45 AM - System Checkpoint
    RP1252: 4/11/2009 1:37:44 AM - System Checkpoint
    RP1253: 4/11/2009 8:39:42 AM - Avg8 Update
    RP1254: 4/12/2009 9:39:44 AM - System Checkpoint
    RP1255: 4/13/2009 11:40:33 AM - System Checkpoint
    RP1256: 4/14/2009 12:50:08 PM - System Checkpoint
    RP1257: 4/15/2009 7:26:23 AM - Software Distribution Service 3.0
    RP1258: 4/16/2009 8:20:41 AM - System Checkpoint
    RP1259: 4/16/2009 8:53:50 AM - Avg8 Update
    RP1260: 4/17/2009 9:12:25 AM - System Checkpoint
    RP1261: 4/18/2009 9:35:37 AM - System Checkpoint
    RP1262: 4/19/2009 10:04:05 AM - System Checkpoint
    RP1263: 4/20/2009 11:04:05 AM - System Checkpoint
    RP1264: 4/21/2009 11:19:35 AM - System Checkpoint
    RP1265: 4/22/2009 12:33:53 PM - System Checkpoint
    RP1266: 4/23/2009 1:25:33 PM - System Checkpoint
    RP1267: 4/24/2009 1:38:02 PM - System Checkpoint
    RP1268: 4/25/2009 1:39:02 PM - System Checkpoint
    RP1269: 4/26/2009 2:16:55 PM - System Checkpoint
    RP1270: 4/27/2009 4:39:59 PM - System Checkpoint
    RP1271: 4/28/2009 6:07:35 PM - System Checkpoint
    RP1272: 4/29/2009 8:40:16 PM - System Checkpoint
    RP1273: 4/30/2009 8:54:34 PM - System Checkpoint
    RP1274: 5/1/2009 9:36:12 PM - System Checkpoint
    RP1275: 5/3/2009 12:56:29 AM - System Checkpoint
    RP1276: 5/3/2009 8:42:29 AM - Avg8 Update
    RP1277: 5/3/2009 8:44:33 AM - Avg8 Update
    RP1278: 5/4/2009 9:04:21 AM - System Checkpoint
    RP1279: 5/5/2009 9:14:49 AM - System Checkpoint
    RP1280: 5/6/2009 10:27:33 AM - System Checkpoint
    RP1281: 5/7/2009 11:03:11 AM - System Checkpoint
    RP1282: 5/8/2009 12:03:09 PM - System Checkpoint
    RP1283: 5/9/2009 1:58:00 PM - System Checkpoint
    RP1284: 5/10/2009 2:03:09 PM - System Checkpoint
    RP1285: 5/11/2009 2:20:32 PM - System Checkpoint
    RP1286: 5/12/2009 3:02:07 PM - System Checkpoint
    RP1287: 5/13/2009 7:18:44 AM - Software Distribution Service 3.0
    RP1288: 5/14/2009 10:01:23 AM - System Checkpoint
    RP1289: 5/15/2009 10:33:04 AM - System Checkpoint
    RP1290: 5/16/2009 11:33:04 AM - System Checkpoint
    RP1291: 5/17/2009 9:34:35 AM - Avg8 Update
    RP1292: 5/18/2009 10:03:50 AM - System Checkpoint
    RP1293: 5/19/2009 9:34:30 AM - Avg8 Update
    RP1294: 5/19/2009 9:36:29 AM - Avg8 Update
    RP1295: 5/20/2009 9:53:45 AM - System Checkpoint
    RP1296: 5/21/2009 10:35:07 AM - System Checkpoint
    RP1297: 5/22/2009 11:35:08 AM - System Checkpoint
    RP1298: 5/25/2009 1:31:42 AM - System Checkpoint
    RP1299: 5/26/2009 1:39:06 AM - System Checkpoint
    RP1300: 5/27/2009 5:51:01 AM - System Checkpoint
    RP1301: 5/28/2009 6:39:00 AM - System Checkpoint
    RP1302: 5/29/2009 9:08:13 AM - System Checkpoint
    RP1303: 5/30/2009 9:39:00 AM - System Checkpoint
    RP1304: 5/31/2009 10:07:02 AM - System Checkpoint
    RP1305: 6/1/2009 10:18:46 AM - System Checkpoint
    RP1306: 6/2/2009 10:39:42 AM - System Checkpoint
    RP1307: 6/3/2009 11:36:51 AM - System Checkpoint
    RP1308: 6/4/2009 12:36:50 PM - System Checkpoint
    RP1309: 6/5/2009 1:36:52 PM - System Checkpoint
    RP1310: 6/6/2009 1:37:56 PM - System Checkpoint
    RP1311: 6/7/2009 2:36:51 PM - System Checkpoint
    RP1312: 6/8/2009 3:36:54 PM - System Checkpoint
    RP1313: 6/9/2009 4:33:09 PM - System Checkpoint
    RP1314: 6/10/2009 7:34:01 AM - Software Distribution Service 3.0
    RP1315: 6/10/2009 8:03:27 AM - Installed Java(TM) 6 Update 14
    RP1316: 6/11/2009 8:20:42 AM - System Checkpoint
    RP1317: 6/12/2009 8:26:43 AM - System Checkpoint
    RP1318: 6/13/2009 11:02:52 AM - System Checkpoint
    RP1319: 6/14/2009 11:40:52 AM - System Checkpoint
    RP1320: 6/15/2009 12:17:39 PM - System Checkpoint
    RP1321: 6/16/2009 1:31:42 PM - System Checkpoint
    RP1322: 6/17/2009 2:17:35 PM - System Checkpoint
    RP1323: 6/18/2009 2:36:29 PM - System Checkpoint
    RP1324: 6/18/2009 3:31:25 PM - Removed Ad-Aware
    RP1325: 6/19/2009 3:49:51 PM - System Checkpoint
    RP1326: 6/21/2009 7:39:38 PM - System Checkpoint
    RP1327: 6/22/2009 7:53:39 PM - System Checkpoint
    RP1328: 6/23/2009 8:27:01 PM - System Checkpoint
    RP1329: 6/24/2009 8:28:09 PM - System Checkpoint
    RP1330: 6/25/2009 9:12:48 PM - System Checkpoint
    RP1331: 6/26/2009 10:06:50 PM - System Checkpoint
    RP1332: 6/27/2009 10:09:34 PM - System Checkpoint
    RP1333: 6/29/2009 12:00:17 AM - System Checkpoint
    RP1334: 6/30/2009 12:58:08 AM - System Checkpoint
    RP1335: 7/1/2009 1:58:07 AM - System Checkpoint
    RP1336: 7/2/2009 7:22:59 AM - System Checkpoint
    RP1337: 7/2/2009 8:29:35 AM - Avg8 Update
    RP1338: 7/2/2009 8:32:59 AM - Avg8 Update
    RP1339: 7/3/2009 9:09:16 AM - System Checkpoint
    RP1340: 7/4/2009 9:41:35 AM - Avg8 Update
    RP1341: 7/4/2009 9:43:56 AM - Avg8 Update
    RP1342: 7/5/2009 10:09:17 AM - System Checkpoint
    RP1343: 7/6/2009 10:26:56 AM - System Checkpoint
    RP1344: 7/6/2009 1:52:49 PM - Restore Operation
    RP1345: 7/6/2009 2:07:35 PM - Avg8 Update
    RP1346: 7/6/2009 2:11:49 PM - Avg8 Update
    RP1347: 7/6/2009 8:10:29 PM - Software Distribution Service 3.0
    RP1348: 7/7/2009 10:13:32 AM - Installed Java(TM) 6 Update 14

    ==== Installed Programs ======================

    123 Free Solitaire
    1300
    1300_Help
    1300Tour
    1300Trb
    Ad-Aware
    Adobe Flash Player 10 ActiveX
    Adobe Reader 7.0.5 Language Support
    Adobe Reader 7.1.0
    Adobe Shockwave Player
    Advanced Tools
    AiO_Scan
    AIOMinimal
    AiOSoftware
    AVG 8.5
    Belarc Advisor 7.2
    Compatibility Pack for the 2007 Office system
    Copy
    CreataCard Plus 3
    CreativeProjects
    DIGOpt
    DIGReqEx
    Director
    DocProc
    Fax
    Foxit Reader
    GdiplusUpgrade
    Google Earth
    Google Update Helper
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows XP (KB926239)
    Hotfix for Windows XP (KB952287)
    HP Photo & Imaging 3.1
    HP PSC & OfficeJet 3.0
    hpmdtab
    HPSystemDiagnostics
    InstantShare
    IrfanView (remove only)
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 14
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    K-Lite Codec Pack 4.3.1 (Standard)
    Malwarebytes' Anti-Malware
    MathPlayer
    Memories Disc Creator 2.0
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Money 2005
    Microsoft Office 2000 Standard
    Microsoft Picture It! Express 9
    Microsoft Picture It! Library 9
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Web Publishing Wizard 1.52
    Microsoft Works
    Move Networks Media Player for Internet Explorer
    MSN
    MSN Encarta Plus Support Files
    MSN Toolbar
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    Nero Suite
    On-line Help Console
    Overland
    PhotoGallery
    PhotoSuite 4 (Remove Only)
    PrintMaster® Gold 8.0
    PrintScreen
    QFolder
    QuickProjects
    QuickTime
    Readme
    Realtek AC'97 Audio
    S3 S3Config3D
    S3 S3Display
    Scan
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893066)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899589)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB905915)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911567)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912812)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913446)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB918899)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920214)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921398)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB921883)
    Security Update for Windows XP (KB922616)
    Security Update for Windows XP (KB922760)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923694)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924191)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925454)
    Security Update for Windows XP (KB925486)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928090)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB929969)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931768)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933566)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB937143)
    Security Update for Windows XP (KB937894)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB939653)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB941568)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB941644)
    Security Update for Windows XP (KB941693)
    Security Update for Windows XP (KB942615)
    Security Update for Windows XP (KB943055)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944338)
    Security Update for Windows XP (KB944533)
    Security Update for Windows XP (KB944653)
    Security Update for Windows XP (KB945553)
    Security Update for Windows XP (KB946026)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB947864)
    Security Update for Windows XP (KB948590)
    Security Update for Windows XP (KB948881)
    Security Update for Windows XP (KB950749)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB963027)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969897)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Serif DrawPlus 3.0
    SkinsHP1
    SkinsHP2
    Spybot - Search & Destroy
    Spybot - Search & Destroy 1.5.2.20
    SpywareBlaster 4.2
    TrayApp
    UniChrome Pro IGP Display Driver and Utilities
    Unload
    Update for Windows XP (KB894391)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB929338)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB931836)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB942840)
    Update for Windows XP (KB946627)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    VIA Audio Driver Setup Program
    VIA Rhine-Family Fast-Ethernet Adapter
    WebFldrs XP
    WebReg
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Installer 3.1 (KB893803)
    Windows Live installer
    Windows Live Messenger
    Windows Live OneCare safety scanner
    Windows Live Sign-in Assistant
    Windows Media Format 11 runtime
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    Windows XP Service Pack 2

    ==== Event Viewer Messages From Past Week ========

    7/1/2009 7:05:29 AM, error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    7/1/2009 2:47:45 AM, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period.

    ==== End Of File ===========================

    My goodness, but that's alot of mumbo jumbo! Hope someone can assist me in finding/correcting any issues that I might have that is causing my task manager to be unresponsive or any other problems that I could have (and am completely unaware of!)

    Regards,
    ~Vicki
     
  2. 2009/07/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.
     

  3. to hide this advert.

  4. 2009/07/10
    Vicki

    Vicki Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    413
    Likes Received:
    8
    Logs

    Hello broni!

    I've done the scan with combofix (and hopefully I did it correctly!) Here is the log from that:

    ComboFix 09-07-09.08 - amd 07/10/2009 10:39.1.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.991.651 [GMT -5:00]
    Running from: c:\documents and settings\amd\Desktop\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\DBI.EXE
    c:\windows\Downloaded Program Files\Quarantine
    c:\windows\Installer\120690.msp
    c:\windows\Installer\2d832e2.msp
    c:\windows\Installer\2d99a71.msp
    c:\windows\Installer\3b7fcf.msp
    c:\windows\Installer\5736d7.msp
    c:\windows\Installer\878110e.msp
    c:\windows\Installer\8781117.msp
    c:\windows\Installer\9b0415.msp
    c:\windows\Installer\9f51a5.msp
    c:\windows\Installer\9f51e2.msp
    c:\windows\Installer\d159.msp
    c:\windows\Installer\d196.msp
    c:\windows\system32\Drivers\fmhpjirlawnb.sys
    c:\windows\system32\Drivers\gmkbixffxrmi.sys

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_fmhpjirlawnb
    -------\Legacy_gmkbixffxrmi
    -------\Service_fmhpjirlawnb
    -------\Service_gmkbixffxrmi


    ((((((((((((((((((((((((( Files Created from 2009-06-10 to 2009-07-10 )))))))))))))))))))))))))))))))
    .

    2009-07-07 17:37 . 2007-12-24 16:48 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
    2009-07-07 15:11 . 2009-07-07 15:11 152576 ----a-w- c:\documents and settings\amd\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
    2009-07-06 19:00 . 2009-07-06 19:00 -------- d-----w- c:\windows\system32\wbem\Repository
    2009-06-18 20:34 . 2009-07-06 18:55 -------- dc----w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-07-10 15:35 . 2008-03-04 14:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-07-10 15:17 . 2006-01-20 15:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-07-10 15:17 . 2006-01-20 15:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-07-10 15:02 . 2006-01-20 23:08 -------- d-----w- c:\documents and settings\amd\Application Data\MSN6
    2009-07-07 15:14 . 2005-11-08 15:55 -------- d-----w- c:\program files\Java
    2009-07-06 19:10 . 2008-05-28 13:49 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-07-06 19:10 . 2008-05-28 13:49 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-07-06 19:10 . 2007-11-12 14:25 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-07-06 18:59 . 2009-03-28 17:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-07-06 17:30 . 2009-04-16 22:40 -------- d-----w- c:\program files\SpywareBlaster
    2009-05-21 16:33 . 2009-01-21 13:06 410984 ----a-w- c:\windows\system32\deploytk.dll
    2009-05-19 18:40 . 2006-01-27 06:44 -------- d-----w- c:\program files\Google
    2009-05-16 23:18 . 2007-11-13 22:11 -------- d-----w- c:\documents and settings\amd\Application Data\Move Networks
    2009-05-07 15:44 . 2001-08-23 18:00 344064 ----a-w- c:\windows\system32\localspl.dll
    2009-05-03 13:43 . 2008-05-28 13:49 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-04-29 04:52 . 2004-01-08 21:23 659456 ----a-w- c:\windows\system32\wininet.dll
    2009-04-29 04:52 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll
    2009-04-17 09:58 . 2001-08-23 18:00 1846656 ----a-w- c:\windows\system32\win32k.sys
    2009-04-15 15:11 . 2005-12-11 02:37 584192 ----a-w- c:\windows\system32\rpcrt4.dll
    2009-04-15 01:00 . 2009-03-28 17:20 2967799 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
    2005-11-08 16:00 . 2005-11-08 16:00 32 --sha-w- c:\windows\{6BCB0AE8-3381-4311-905A-CD5910AB9D21}.dat
    2005-11-08 16:00 . 2005-11-08 16:00 32 --sha-w- c:\windows\system32\{D6845DBB-B1E7-42A2-B5F9-30E7D7A05BEF}.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck "= "c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "AVG8_TRAY "= "c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-06 1948440]
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
    "SoundMan "= "SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-01-20 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-07-06 19:10 11952 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk
    backup=c:\windows\pss\Event Reminder.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^amd^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=c:\documents and settings\amd\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=c:\windows\pss\LimeWire On Startup.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "VTTimer "=VTTimer.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\WINDOWS\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    "c:\\WINDOWS\\system32\\mshta.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe "=
    "c:\\Program Files\\MSN\\MSNCoreFiles\\msn.exe "=

    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/28/2008 8:49 AM 335752]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/28/2008 8:49 AM 108552]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2008 2:29 PM 907032]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/3/2008 2:29 PM 298776]
    S2 gupdate1c9cb63f58a137c;Google Update Service (gupdate1c9cb63f58a137c);c:\program files\Google\Update\GoogleUpdate.exe [5/2/2009 3:23 PM 133104]
    S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2/4/2008 9:39 PM 44928]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-02 20:23]

    2009-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-02 20:23]

    2009-07-09 c:\windows\Tasks\WebReg 20070304184719.job
    - c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2003-07-07 07:43]
    .
    .
    ------- Supplementary Scan -------
    .
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxp://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37680.cab
    DPF: {E001C731-5E37-4538-A5CB-8168736A2360} - hxxp://91.199.104.31/cab/ActiveQscan.cab
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-07-10 10:49
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-823518204-1993962763-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(2904)
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\program files\AVG\AVG8\avgtray.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\AVG\AVG8\avgcsrvx.exe
    .
    **************************************************************************
    .
    Completion time: 2009-07-10 10:56 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-07-10 15:55

    Pre-Run: 57,238,224,896 bytes free
    Post-Run: 57,414,979,584 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= "Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

    168 --- E O F --- 2009-07-07 01:18


    I wasn't sure about the "hijackthis" log as I don't recollect ever using that program? (I'm truly sorry if I missed something here). But I did run another "DDS" scan and if this helps here is the reports from that scan:

    DDS (Ver_09-06-26.01) - NTFSx86
    Run by amd at 11:01:16.09 on Fri 07/10/2009
    Internet Explorer: 6.0.2900.2180
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.991.624 [GMT -5:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    C:\WINDOWS\system32\svchost -k rpcss
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\explorer.exe
    C:\Documents and Settings\amd\Desktop\dds.pif

    ============== Pseudo HJT Report ===============

    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: ST: {9394ede7-c8b5-483e-8773-474bf36af6e4} - c:\program files\msn apps\st\01.03.0000.1005\en-xu\stmain.dll
    BHO: MSNToolBandBHO: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: MSN: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll
    TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
    DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://www.ipix.com/viewers/ipixx.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
    DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
    DPF: {56393399-041A-4650-94C7-13DFCB1F4665} - hxxp://www.pcpitstop.com/pestscan/pestscan.cab
    DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
    DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1134266582209
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198800691232
    DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxp://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37680.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
    DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
    DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
    DPF: {E001C731-5E37-4538-A5CB-8168736A2360} - hxxp://91.199.104.31/cab/ActiveQscan.cab
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Notify: avgrsstarter - avgrsstx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-28 335752]
    R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-11-12 27784]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-28 108552]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-3 907032]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 298776]
    S2 gupdate1c9cb63f58a137c;Google Update Service (gupdate1c9cb63f58a137c);c:\program files\google\update\GoogleUpdate.exe [2009-5-2 133104]
    S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2008-2-4 44928]

    =============== Created Last 30 ================

    2009-07-10 10:54 <DIR> -cd----- c:\windows\system32\dllcache\cache
    2009-07-10 10:38 <DIR> a-dshr-- C:\cmdcons
    2009-07-10 10:35 161,792 a------- c:\windows\SWREG.exe
    2009-07-10 10:35 155,136 a------- c:\windows\PEV.exe
    2009-07-10 10:35 98,816 a------- c:\windows\sed.exe
    2009-07-07 12:37 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
    2009-07-06 14:00 <DIR> --d----- c:\windows\system32\wbem\Repository
    2009-06-18 15:34 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}

    ==================== Find3M ====================

    2009-07-06 14:10 335,752 a------- c:\windows\system32\drivers\avgldx86.sys
    2009-07-06 14:10 11,952 a------- c:\windows\system32\avgrsstx.dll
    2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll
    2009-05-07 10:44 344,064 a------- c:\windows\system32\localspl.dll
    2009-04-28 23:52 659,456 a------- c:\windows\system32\wininet.dll
    2009-04-28 23:52 81,920 -------- c:\windows\system32\ieencode.dll
    2009-04-17 04:58 1,846,656 a------- c:\windows\system32\win32k.sys
    2009-04-15 10:11 584,192 a------- c:\windows\system32\rpcrt4.dll
    2008-07-10 08:16 758 a------- c:\docume~1\amd\applic~1\wklnhst.dat
    2005-11-08 11:00 32 a--sh--- c:\windows\{6BCB0AE8-3381-4311-905A-CD5910AB9D21}.dat
    2005-11-08 11:00 32 a--sh--- c:\windows\system32\{D6845DBB-B1E7-42A2-B5F9-30E7D7A05BEF}.dat

    ============= FINISH: 11:01:42.62 ===============


    And the 2nd part of that scan:

    DDS (Ver_09-06-26.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 11/7/2005 4:19:05 PM
    System Uptime: 7/10/2009 10:47:59 AM (1 hours ago)

    Motherboard: PCCHIPS | | M861G
    Processor: AMD Sempron(tm) Processor 3000+ | CPU 1 | 1799/200mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 76 GiB total, 53.49 GiB free.
    D: is CDROM ()
    E: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1253: 4/11/2009 8:39:42 AM - Avg8 Update
    RP1254: 4/12/2009 9:39:44 AM - System Checkpoint
    RP1255: 4/13/2009 11:40:33 AM - System Checkpoint
    RP1256: 4/14/2009 12:50:08 PM - System Checkpoint
    RP1257: 4/15/2009 7:26:23 AM - Software Distribution Service 3.0
    RP1258: 4/16/2009 8:20:41 AM - System Checkpoint
    RP1259: 4/16/2009 8:53:50 AM - Avg8 Update
    RP1260: 4/17/2009 9:12:25 AM - System Checkpoint
    RP1261: 4/18/2009 9:35:37 AM - System Checkpoint
    RP1262: 4/19/2009 10:04:05 AM - System Checkpoint
    RP1263: 4/20/2009 11:04:05 AM - System Checkpoint
    RP1264: 4/21/2009 11:19:35 AM - System Checkpoint
    RP1265: 4/22/2009 12:33:53 PM - System Checkpoint
    RP1266: 4/23/2009 1:25:33 PM - System Checkpoint
    RP1267: 4/24/2009 1:38:02 PM - System Checkpoint
    RP1268: 4/25/2009 1:39:02 PM - System Checkpoint
    RP1269: 4/26/2009 2:16:55 PM - System Checkpoint
    RP1270: 4/27/2009 4:39:59 PM - System Checkpoint
    RP1271: 4/28/2009 6:07:35 PM - System Checkpoint
    RP1272: 4/29/2009 8:40:16 PM - System Checkpoint
    RP1273: 4/30/2009 8:54:34 PM - System Checkpoint
    RP1274: 5/1/2009 9:36:12 PM - System Checkpoint
    RP1275: 5/3/2009 12:56:29 AM - System Checkpoint
    RP1276: 5/3/2009 8:42:29 AM - Avg8 Update
    RP1277: 5/3/2009 8:44:33 AM - Avg8 Update
    RP1278: 5/4/2009 9:04:21 AM - System Checkpoint
    RP1279: 5/5/2009 9:14:49 AM - System Checkpoint
    RP1280: 5/6/2009 10:27:33 AM - System Checkpoint
    RP1281: 5/7/2009 11:03:11 AM - System Checkpoint
    RP1282: 5/8/2009 12:03:09 PM - System Checkpoint
    RP1283: 5/9/2009 1:58:00 PM - System Checkpoint
    RP1284: 5/10/2009 2:03:09 PM - System Checkpoint
    RP1285: 5/11/2009 2:20:32 PM - System Checkpoint
    RP1286: 5/12/2009 3:02:07 PM - System Checkpoint
    RP1287: 5/13/2009 7:18:44 AM - Software Distribution Service 3.0
    RP1288: 5/14/2009 10:01:23 AM - System Checkpoint
    RP1289: 5/15/2009 10:33:04 AM - System Checkpoint
    RP1290: 5/16/2009 11:33:04 AM - System Checkpoint
    RP1291: 5/17/2009 9:34:35 AM - Avg8 Update
    RP1292: 5/18/2009 10:03:50 AM - System Checkpoint
    RP1293: 5/19/2009 9:34:30 AM - Avg8 Update
    RP1294: 5/19/2009 9:36:29 AM - Avg8 Update
    RP1295: 5/20/2009 9:53:45 AM - System Checkpoint
    RP1296: 5/21/2009 10:35:07 AM - System Checkpoint
    RP1297: 5/22/2009 11:35:08 AM - System Checkpoint
    RP1298: 5/25/2009 1:31:42 AM - System Checkpoint
    RP1299: 5/26/2009 1:39:06 AM - System Checkpoint
    RP1300: 5/27/2009 5:51:01 AM - System Checkpoint
    RP1301: 5/28/2009 6:39:00 AM - System Checkpoint
    RP1302: 5/29/2009 9:08:13 AM - System Checkpoint
    RP1303: 5/30/2009 9:39:00 AM - System Checkpoint
    RP1304: 5/31/2009 10:07:02 AM - System Checkpoint
    RP1305: 6/1/2009 10:18:46 AM - System Checkpoint
    RP1306: 6/2/2009 10:39:42 AM - System Checkpoint
    RP1307: 6/3/2009 11:36:51 AM - System Checkpoint
    RP1308: 6/4/2009 12:36:50 PM - System Checkpoint
    RP1309: 6/5/2009 1:36:52 PM - System Checkpoint
    RP1310: 6/6/2009 1:37:56 PM - System Checkpoint
    RP1311: 6/7/2009 2:36:51 PM - System Checkpoint
    RP1312: 6/8/2009 3:36:54 PM - System Checkpoint
    RP1313: 6/9/2009 4:33:09 PM - System Checkpoint
    RP1314: 6/10/2009 7:34:01 AM - Software Distribution Service 3.0
    RP1315: 6/10/2009 8:03:27 AM - Installed Java(TM) 6 Update 14
    RP1316: 6/11/2009 8:20:42 AM - System Checkpoint
    RP1317: 6/12/2009 8:26:43 AM - System Checkpoint
    RP1318: 6/13/2009 11:02:52 AM - System Checkpoint
    RP1319: 6/14/2009 11:40:52 AM - System Checkpoint
    RP1320: 6/15/2009 12:17:39 PM - System Checkpoint
    RP1321: 6/16/2009 1:31:42 PM - System Checkpoint
    RP1322: 6/17/2009 2:17:35 PM - System Checkpoint
    RP1323: 6/18/2009 2:36:29 PM - System Checkpoint
    RP1324: 6/18/2009 3:31:25 PM - Removed Ad-Aware
    RP1325: 6/19/2009 3:49:51 PM - System Checkpoint
    RP1326: 6/21/2009 7:39:38 PM - System Checkpoint
    RP1327: 6/22/2009 7:53:39 PM - System Checkpoint
    RP1328: 6/23/2009 8:27:01 PM - System Checkpoint
    RP1329: 6/24/2009 8:28:09 PM - System Checkpoint
    RP1330: 6/25/2009 9:12:48 PM - System Checkpoint
    RP1331: 6/26/2009 10:06:50 PM - System Checkpoint
    RP1332: 6/27/2009 10:09:34 PM - System Checkpoint
    RP1333: 6/29/2009 12:00:17 AM - System Checkpoint
    RP1334: 6/30/2009 12:58:08 AM - System Checkpoint
    RP1335: 7/1/2009 1:58:07 AM - System Checkpoint
    RP1336: 7/2/2009 7:22:59 AM - System Checkpoint
    RP1337: 7/2/2009 8:29:35 AM - Avg8 Update
    RP1338: 7/2/2009 8:32:59 AM - Avg8 Update
    RP1339: 7/3/2009 9:09:16 AM - System Checkpoint
    RP1340: 7/4/2009 9:41:35 AM - Avg8 Update
    RP1341: 7/4/2009 9:43:56 AM - Avg8 Update
    RP1342: 7/5/2009 10:09:17 AM - System Checkpoint
    RP1343: 7/6/2009 10:26:56 AM - System Checkpoint
    RP1344: 7/6/2009 1:52:49 PM - Restore Operation
    RP1345: 7/6/2009 2:07:35 PM - Avg8 Update
    RP1346: 7/6/2009 2:11:49 PM - Avg8 Update
    RP1347: 7/6/2009 8:10:29 PM - Software Distribution Service 3.0
    RP1348: 7/7/2009 10:13:32 AM - Installed Java(TM) 6 Update 14
    RP1349: 7/8/2009 10:57:05 AM - System Checkpoint
    RP1350: 7/8/2009 5:55:44 PM - Software Distribution Service 3.0
    RP1351: 7/9/2009 6:49:07 PM - System Checkpoint
    RP1352: 7/10/2009 9:11:58 AM - Removed Ad-Aware
    RP1353: 7/10/2009 9:53:13 AM - Removed Ad-Aware

    ==== Installed Programs ======================

    123 Free Solitaire
    1300
    1300_Help
    1300Tour
    1300Trb
    Adobe Flash Player 10 ActiveX
    Adobe Reader 7.0.5 Language Support
    Adobe Reader 7.1.0
    Adobe Shockwave Player
    Advanced Tools
    AiO_Scan
    AIOMinimal
    AiOSoftware
    AVG 8.5
    Belarc Advisor 7.2
    Compatibility Pack for the 2007 Office system
    Copy
    CreataCard Plus 3
    CreativeProjects
    DIGOpt
    DIGReqEx
    Director
    DocProc
    Fax
    Foxit Reader
    GdiplusUpgrade
    Google Earth
    Google Update Helper
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows XP (KB926239)
    Hotfix for Windows XP (KB952287)
    HP Photo & Imaging 3.1
    HP PSC & OfficeJet 3.0
    hpmdtab
    HPSystemDiagnostics
    InstantShare
    IrfanView (remove only)
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 14
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    K-Lite Codec Pack 4.3.1 (Standard)
    Malwarebytes' Anti-Malware
    MathPlayer
    Memories Disc Creator 2.0
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Money 2005
    Microsoft Office 2000 Standard
    Microsoft Picture It! Express 9
    Microsoft Picture It! Library 9
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Web Publishing Wizard 1.52
    Microsoft Works
    Move Networks Media Player for Internet Explorer
    MSN
    MSN Encarta Plus Support Files
    MSN Toolbar
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    Nero Suite
    On-line Help Console
    overland
    PhotoGallery
    PhotoSuite 4 (Remove Only)
    PrintMaster® Gold 8.0
    PrintScreen
    QFolder
    QuickProjects
    QuickTime
    Readme
    Realtek AC'97 Audio
    S3 S3Config3D
    S3 S3Display
    Scan
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893066)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899589)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB905915)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911567)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912812)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913446)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB918899)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920214)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921398)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB921883)
    Security Update for Windows XP (KB922616)
    Security Update for Windows XP (KB922760)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923694)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924191)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925454)
    Security Update for Windows XP (KB925486)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928090)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB929969)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931768)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933566)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB937143)
    Security Update for Windows XP (KB937894)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB939653)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB941568)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB941644)
    Security Update for Windows XP (KB941693)
    Security Update for Windows XP (KB942615)
    Security Update for Windows XP (KB943055)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944338)
    Security Update for Windows XP (KB944533)
    Security Update for Windows XP (KB944653)
    Security Update for Windows XP (KB945553)
    Security Update for Windows XP (KB946026)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB947864)
    Security Update for Windows XP (KB948590)
    Security Update for Windows XP (KB948881)
    Security Update for Windows XP (KB950749)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB963027)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969897)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Serif DrawPlus 3.0
    SkinsHP1
    SkinsHP2
    SpywareBlaster 4.2
    TrayApp
    UniChrome Pro IGP Display Driver and Utilities
    Unload
    Update for Windows XP (KB894391)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB929338)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB931836)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB942840)
    Update for Windows XP (KB946627)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    VIA Audio Driver Setup Program
    VIA Rhine-Family Fast-Ethernet Adapter
    WebFldrs XP
    WebReg
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Installer 3.1 (KB893803)
    Windows Live installer
    Windows Live Messenger
    Windows Live OneCare safety scanner
    Windows Live Sign-in Assistant
    Windows Media Format 11 runtime
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    Windows XP Service Pack 2

    ==== Event Viewer Messages From Past Week ========

    7/6/2009 2:41:35 AM, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period.
    7/6/2009 11:00:16 AM, error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    7/10/2009 9:54:23 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the service.
    7/10/2009 9:53:53 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the aawservice service.
    7/10/2009 10:39:34 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.

    ==== End Of File ===========================



    I hope this is the information you were needing and that you'll be able to assist me in getting this machine "clean "! Thank you for your help!

    Regards,
    ~Vicki
     
  5. 2009/07/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Uninstall Combofix:

    Go Start > Run
    Type in:
    combofix /u
    Note the space between the "combofix" and the "/u "
    Restart computer.


    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***

    STEP 1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes ". If not, update the definitions before scanning by selecting "Check for Updates ". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Click Scan your Computer... button.
    * Click Scanning Preferences/Control Center... button.
    * Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    - Close browsers before scanning.
    - Terminate memory threats before quarantining.

    * Click the Close button to leave the control center screen.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    - Click Preferences, then click the Statistics/Logs tab.
    - Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    - If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    - Please copy and paste the Scan Log results in your next reply.

    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    STEP 2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!


    STEP 3. Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackThis log.
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  6. 2009/07/16
    Vicki

    Vicki Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    413
    Likes Received:
    8
    superantispyware log

    Hello broni!

    Sorry it's taken me so long to reply with the results of the scan, but I know you are a busy person helping many others as well!

    I did get my task manager issue resolved (posted the results in the WindowsXP forum) but I still want to be sure that my system is clean. Here is the log from the superantispyware scan:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 07/15/2009 at 07:50 PM

    Application Version : 4.26.1006

    Core Rules Database Version : 3995
    Trace Rules Database Version: 1935

    Scan type : Complete Scan
    Total Scan Time : 02:20:41

    Memory items scanned : 211
    Memory threats detected : 0
    Registry items scanned : 5727
    Registry threats detected : 0
    File items scanned : 74032
    File threats detected : 1

    Trace.Known Threat Sources
    C:\Documents and Settings\amd\Local Settings\Temporary Internet Files\Content.IE5\OZVFQ0LH\PPU_Twista_v1[1].gif


    I have had the malwarbytes' anti-malware program prior to your suggestion to download and while I haven't done a scan with it for a couple of weeks, it never seems to find anything. Here is the results from the last scan I did:

    Malwarebytes' Anti-Malware 1.38
    Database version: 2381
    Windows 5.1.2600 Service Pack 2

    7/6/2009 1:14:33 PM
    mbam-log-2009-07-06 (13-14-33).txt

    Scan type: Quick Scan
    Objects scanned: 105281
    Time elapsed: 14 minute(s), 29 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    Would you suggest that I do a new scan? Also, because my task manager is now functioning properly, would I still need to download the HijackThis program?

    Thank you so much for taking the time to look through this and offering your assistance!

    Regards,
    Vicki
     
  7. 2009/07/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, I'd like to see HJT log.
     
  8. 2009/07/17
    Vicki

    Vicki Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    413
    Likes Received:
    8
    HJT log

    Hello broni!

    Here is the HJT log as you requested:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:33:15 AM, on 7/17/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\MSN\MSNCoreFiles\msn.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe "
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games "“ Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.pcpitstop.com/pestscan/pestscan.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1134266582209
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1198800691232
    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37680.cab
    O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games "“ Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
    O16 - DPF: {E001C731-5E37-4538-A5CB-8168736A2360} (Confirmation) - http://91.199.104.31/cab/ActiveQscan.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Google Update Service (gupdate1c9cb63f58a137c) (gupdate1c9cb63f58a137c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 6584 bytes


    Hoping to hear that my computer is clean or easily fixed if it isn't! Thanks again for taking the time to analyze all of this for me!

    ~Vicki
     
  9. 2009/07/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)

    Go to Add\Remove, and uninstall these old Java versions:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1


    ================================================================

    Print this post out, since you won't have an access to it, at some point.

    1. Open HijackThis.

    2. Close all windows, except for HijackThis.

    3. Put checkmarks next to the following HijackThis entries:

    - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    4. You should also checkmark following entries (these are unnecessary startups; no actual programs will be removed):

    - O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    - O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    - O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe "
    - O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (leave this one alone, if you use paid version)
    - O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


    5. Click on Fix checked button.

    6. Restart computer.


    Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.


    You should be good to go...
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.