Page 1 of 4 1234 LastLast
Results 1 to 10 of 38

Thread: Redirect at facebook.

  1. #1
    Junior Member
    Join Date
    Sep 2006
    Posts
    21

    Default Redirect at facebook.

    I seem to have a virus problem, every time I go to facebook, another window opens up and it gets rediected to a web site;

    This web site is being blocked by Blue-Coat (my "Net Nanny" program) so the web site has not loaded, I do not know what is on that web site.

    Now it is opening 4-5 windows (earlier today it was one). I am running Avast, and SD with Blue-Coat; both updated and did the scans today with no help.

    I pulled down the McAfee scanner for it to look but found nothing.

    This only happens when I am on facebook on my desktop computer, when I shut down the window that was on facebook the other windows do not open up, and the computer seems to be running fine.

    This does NOT happen when I have my laptop (though the same router) going onto facebook.

    I am at the limit of my knowledge here.... here is the DDS file:
    I ran Ennuit for the registery, however I regularly run CCleaner (though not recently)
    Attached the Attache file.

    ********************
    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Mark Fedorov at 17:34:13.95 on Tue 03/29/2011
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.239 [GMT -4:00]
    .
    AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: Norton Internet Worm Protection *Disabled*
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\lxeccoms.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    C:\WINDOWS\stsystra.exe
    C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    svchost.exe
    C:\Program Files\Lexmark Pro800-Pro900 Series\lxecmon.exe
    C:\Program Files\Lexmark Pro800-Pro900 Series\ezprint.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Startup Guard 3\startupguard.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\McAfee Security Scan\3.0.199\SSScheduler.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Mark Fedorov\Local Settings\Temporary Internet Files\Content.IE5\7TUZABQ9\dds[1].scr
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uDefault_Page_URL = http://www.google.com/ig/dell?hl=en&...us&ibd=6070111
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 10\SnagitBHO.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
    TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
    TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
    TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; Creative ZENcast v2.00.14)" -"http://www.cartoonnetwork.com/games/scooby/attackofvampire/index.html"
    mRun: [SigmatelSysTrayApp] stsystra.exe
    mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [lxecmon.exe] "c:\program files\lexmark pro800-pro900 series\lxecmon.exe"
    mRun: [EzPrint] "c:\program files\lexmark pro800-pro900 series\ezprint.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    dRunOnce: [RunNarrator] Narrator.exe
    StartupFolder: c:\docume~1\markfe~1\startm~1\programs\startup\startu~1.lnk - c:\program files\startup guard 3\startupguard.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.199\SSScheduler.exe
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    LSP: c:\progra~1\whalec~1\client~1\31265d~1.0\WhlLSP.dll
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
    DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15031/CTSUEng.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/56.39/uploader2.cab
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178497609035
    DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX27.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} - hxxps://my.airproducts.com:/InternalSite/WhlCompMgr.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15034/CTPID.cab
    TCP: {4DB6DBAA-9257-4BDA-8E68-023D8E034030} = 208.59.247.45,208.59.247.46
    Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
    Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    LSA: Authentication Packages = msv1_0 nwprovau
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-20 371544]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2008-4-6 301528]
    R1 bckd;bckd;c:\windows\system32\drivers\bckd.sys [2009-1-13 72992]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-6 19544]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-27 42184]
    R2 bckwfs;Blue Coat K9 Web Protection;c:\program files\blue coat k9 web protection\k9filter.exe [2007-2-7 1078560]
    R2 lxec_device;lxec_device;c:\windows\system32\lxeccoms.exe -service --> c:\windows\system32\lxeccoms.exe -service [?]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 QuickBooksDB18;QuickBooksDB18;c:\progra~1\intuit\quickb~2\qbdbmgrn.exe -hvquickbooksdb18 --> c:\progra~1\intuit\quickb~2\QBDBMgrN.exe -hvQuickBooksDB18 [?]
    R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-1-11 1174152]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-7-6 133104]
    S2 lxecCATSCustConnectService;lxecCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxecserv.exe [2011-3-17 193192]
    S3 Cobra_GPS;%Cobra_GPS.SvcDesc%;c:\windows\system32\drivers\Cobra_GPS.sys [2010-4-13 15318]
    S3 JL2004A;JL2004A Photo Viewer;c:\windows\system32\drivers\pv_wdm.sys --> c:\windows\system32\drivers\pv_wdm.sys [?]
    S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2010-4-10 266544]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.0.199\McCHSvc.exe [2011-2-23 237008]
    S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
    S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-3-8 8320]
    S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys --> c:\windows\system32\drivers\motodrv.sys [?]
    .
    =============== Created Last 30 ================
    .
    2011-03-29 20:51:55 -------- d-----w- c:\docume~1\alluse~1\applic~1\McAfee Security Scan
    2011-03-29 20:51:38 -------- d-----w- c:\program files\McAfee Security Scan
    2011-03-25 03:09:08 -------- d-----w- c:\docume~1\markfe~1\locals~1\applic~1\assembly
    2011-03-25 03:08:10 -------- d-----w- c:\docume~1\markfe~1\locals~1\applic~1\TechSmith
    2011-03-25 03:06:49 -------- d-----w- c:\program files\common files\Wise Installation Wizard
    2011-03-20 14:03:00 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-03-17 23:13:57 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-03-17 23:07:32 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-03-17 22:43:25 -------- d-----w- c:\documents and settings\all users\Lx_cats
    2011-03-17 22:25:31 40960 ----a-w- c:\windows\system32\lxecvs.dll
    2011-03-17 22:25:30 442368 ----a-w- c:\windows\system32\lxeccoin.dll
    2011-03-17 22:25:30 157696 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\lxecdrpp.dll
    2011-03-17 22:25:26 983121 ----a-w- c:\windows\system32\lxk_gf.dll
    2011-03-17 22:25:25 86016 ----a-w- c:\windows\system32\lxecgcfg.dll
    2011-03-17 22:25:25 294912 ----a-w- c:\windows\system32\lxeccui.dll
    2011-03-17 22:25:25 110592 ----a-w- c:\windows\system32\lxeccuir.dll
    2011-03-17 22:25:17 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
    2011-03-17 22:25:17 87040 ----a-w- c:\windows\system32\dllcache\wiafbdrv.dll
    2011-03-17 22:24:23 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
    2011-03-17 22:24:09 372736 ----a-w- c:\windows\system32\LXECwupd.dll
    2011-03-17 22:24:09 213672 ----a-w- c:\windows\system32\LXECwupd.exe
    2011-03-17 22:22:50 -------- d-----w- c:\program files\Lexmark
    2011-03-17 22:18:33 -------- d-----w- c:\program files\Lexmark Pro800-Pro900 Series
    2011-03-17 22:18:32 299008 ----a-w- c:\windows\system32\LXECsm.dll
    2011-03-17 22:18:32 23552 ----a-w- c:\windows\system32\LXECsmr.dll
    2011-03-12 16:28:40 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
    .
    ==================== Find3M ====================
    .
    2011-02-23 14:04:21 40648 ----a-w- c:\windows\avastSS.scr
    2011-02-04 22:48:32 456192 ----a-w- c:\windows\system32\encdec.dll
    2011-02-04 22:48:30 291840 ----a-w- c:\windows\system32\sbe.dll
    2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
    2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
    2002-07-26 22:02:06 153088 ------w- c:\program files\UNWISE.EXE
    .
    ============= FINISH: 17:36:18.68 ===============

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Download aswMBR to your desktop. Double click the aswMBR.exe to run it
    Click the Scan button to start scan

    On completion of the scan click save log, save it to your desktop and post in your next reply.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Junior Member
    Join Date
    Sep 2006
    Posts
    21

    Default Log

    Here is the log:

    +++++++++++++++++++++++
    aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software
    Run date: 2011-04-02 13:22:58
    -----------------------------
    13:22:58.400 OS Version: Windows 5.1.2600 Service Pack 3
    13:22:58.400 Number of processors: 2 586 0xF06
    13:22:58.400 ComputerName: QUICKCHECKER UserName: Mark Fedorov
    13:23:03.634 Initialize success
    13:23:18.742 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-2
    13:23:18.742 Disk 0 Vendor: SAMSUNG_ VT10 Size: 238418MB BusType: 3
    13:23:18.757 Disk 0 MBR read successfully
    13:23:18.757 Disk 0 MBR scan
    13:23:18.773 Disk 0 scanning sectors +488263545
    13:23:18.804 Disk 0 scanning C:\WINDOWS\system32\drivers
    13:23:26.522 Service scanning
    13:23:28.225 Disk 0 trace - called modules:
    13:23:28.257 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
    13:23:28.257 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f62778]
    13:23:28.257 3 CLASSPNP.SYS[f76c4fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-2[0x86a4c030]
    13:23:28.257 Scan finished successfully
    ++++++++++++++++

    Thanks,

    Mark

  4. #4
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
    • Run Spybot-S&D in Advanced Mode
    • If it is not already set to do this, go to the Mode menu
      select
      Advanced Mode
    • On the left hand side, click on Tools
    • Then click on the Resident icon in the list
    • Uncheck
      Resident TeaTimer
      and OK any prompts.
    • Restart your computer



    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully first.

    Please continue as follows:

    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.


    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New dds log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #5
    Junior Member
    Join Date
    Sep 2006
    Posts
    21

    Default Unexpected turn of events

    I followed the directions. Downloaded the program, shut down: tea timer, Avast and start up keeper. I ran the Combo fix, it had to download the recovery modual from Microsoft (which it did). It came to a screen where it was going to scan the comptuer (for 10 minuates or more); then I got the Blue Screen of Death.....

    The Error was : IRQL_NOT_LESS_OR_EQUAL

    then the technical data on the blue screen was:
    ***STOP: 0x0000000a(0x00000004,0x00000002,0x00000001,0x80535B59)

    Should I re-run Combo fix or do something else?

    -Mark

  6. #6
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Yes, try to re-run it.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #7
    Junior Member
    Join Date
    Sep 2006
    Posts
    21

    Default New info

    I have not tried to get to facebook yet......

    COMBO-FIX log:

    +++++++++++++++++++++++++++
    ComboFix 11-04-02.03 - Mark Fedorov 04/03/2011 10:08:05.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.467 [GMT -4:00]
    Running from: c:\documents and settings\Mark Fedorov\Desktop\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\install.exe
    c:\program files\INSTALL.LOG
    c:\program files\UNWISE.EXE
    .
    Infected copy of c:\windows\system32\userinit.exe was found and disinfected
    Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-03-03 to 2011-04-03 )))))))))))))))))))))))))))))))
    .
    .
    2011-03-29 21:43 . 2011-03-29 21:44 -------- d-----w- c:\program files\ERUNT
    2011-03-29 20:54 . 2011-03-29 20:54 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee
    2011-03-29 20:51 . 2011-03-29 20:51 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
    2011-03-29 20:51 . 2011-03-29 20:51 -------- d-----w- c:\program files\McAfee Security Scan
    2011-03-25 03:09 . 2011-03-25 03:09 -------- d-----w- c:\documents and settings\Mark Fedorov\Local Settings\Application Data\assembly
    2011-03-25 03:08 . 2011-03-25 03:08 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
    2011-03-25 03:08 . 2011-03-25 03:08 -------- d-----w- c:\program files\TechSmith
    2011-03-25 03:08 . 2011-03-25 03:08 -------- d-----w- c:\documents and settings\Mark Fedorov\Local Settings\Application Data\TechSmith
    2011-03-25 03:06 . 2011-03-25 03:06 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2011-03-20 14:03 . 2011-02-23 13:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-03-17 23:13 . 2011-03-17 23:13 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-03-17 23:07 . 2011-03-17 23:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-03-17 23:06 . 2011-03-17 23:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2011-03-17 22:43 . 2011-04-01 17:29 -------- d-----w- c:\documents and settings\All Users\Lx_cats
    2011-03-17 22:25 . 2008-03-05 01:55 40960 ----a-w- c:\windows\system32\lxecvs.dll
    2011-03-17 22:25 . 2010-04-13 18:41 442368 ----a-w- c:\windows\system32\lxeccoin.dll
    2011-03-17 22:25 . 2009-11-04 12:14 157696 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\lxecdrpp.dll
    2011-03-17 22:25 . 2008-04-30 05:32 983121 ----a-w- c:\windows\system32\lxk_gf.dll
    2011-03-17 22:25 . 2009-11-09 06:59 86016 ----a-w- c:\windows\system32\lxecgcfg.dll
    2011-03-17 22:25 . 2009-10-21 09:06 110592 ----a-w- c:\windows\system32\lxeccuir.dll
    2011-03-17 22:25 . 2009-10-21 09:06 294912 ----a-w- c:\windows\system32\lxeccui.dll
    2011-03-17 22:25 . 2001-08-18 02:36 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
    2011-03-17 22:25 . 2001-08-18 02:36 87040 ----a-w- c:\windows\system32\dllcache\wiafbdrv.dll
    2011-03-17 22:24 . 2011-03-17 22:24 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
    2011-03-17 22:24 . 2010-04-14 19:08 213672 ----a-w- c:\windows\system32\LXECwupd.exe
    2011-03-17 22:24 . 2010-02-22 09:08 372736 ----a-w- c:\windows\system32\LXECwupd.dll
    2011-03-17 22:22 . 2011-03-17 22:25 -------- d-----w- c:\program files\Lexmark
    2011-03-17 22:18 . 2011-03-17 23:47 -------- d-----w- c:\program files\Lexmark Pro800-Pro900 Series
    2011-03-17 22:18 . 2009-02-20 08:48 23552 ----a-w- c:\windows\system32\LXECsmr.dll
    2011-03-17 22:18 . 2009-02-20 08:48 299008 ----a-w- c:\windows\system32\LXECsm.dll
    2011-03-12 16:28 . 2011-03-12 16:28 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-02-23 14:04 . 2010-08-28 00:13 40648 ----a-w- c:\windows\avastSS.scr
    2011-02-23 14:04 . 2007-05-04 01:24 190016 ----a-w- c:\windows\system32\aswBoot.exe
    2011-02-23 13:56 . 2008-04-06 20:21 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2011-02-23 13:55 . 2007-05-04 01:24 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2011-02-23 13:55 . 2007-05-04 01:24 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2011-02-23 13:55 . 2007-05-04 01:24 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2011-02-23 13:55 . 2007-05-04 01:24 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2011-02-23 13:54 . 2007-05-04 01:24 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2011-02-23 13:54 . 2008-04-06 20:21 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2011-02-04 22:48 . 2005-08-16 09:18 456192 ----a-w- c:\windows\system32\encdec.dll
    2011-02-04 22:48 . 2005-08-16 09:18 291840 ----a-w- c:\windows\system32\sbe.dll
    2011-02-02 07:58 . 2005-08-16 09:37 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2011-01-27 11:57 . 2005-08-16 09:37 677888 ----a-w- c:\windows\system32\mstsc.exe
    2011-01-21 14:44 . 2005-08-16 09:18 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2011-01-07 14:09 . 2005-08-16 09:18 290048 ----a-w- c:\windows\system32\atmfd.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2011-02-23 14:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 282624]
    "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "lxecmon.exe"="c:\program files\Lexmark Pro800-Pro900 Series\lxecmon.exe" [2011-01-23 770728]
    "EzPrint"="c:\program files\Lexmark Pro800-Pro900 Series\ezprint.exe" [2011-01-23 148280]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RunNarrator"="Narrator.exe" [2008-04-14 53760]
    .
    c:\documents and settings\Mark Fedorov\Start Menu\Programs\Startup\
    Startup Guard.lnk - c:\program files\Startup Guard 3\startupguard.exe [2011-2-1 778240]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.199\SSScheduler.exe [2011-2-23 272528]
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk /p \??\F:\0autocheck autochk *
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2010-09-21 04:07 932288 ------r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
    2008-04-17 18:14 98616 ------w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
    2007-07-17 16:03 868352 ------w- c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
    2008-05-06 08:42 202088 ------w- c:\program files\TomTom HOME 2\HOMERunner.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Meade\\AutostarSuite\\AutostarSuite.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
    "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
    "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
    "c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\WINDOWS\\system32\\lxeccoms.exe"=
    "c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
    .
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3/20/2011 10:03 AM 371544]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/6/2008 4:21 PM 301528]
    R1 bckd;bckd;c:\windows\system32\drivers\bckd.sys [1/13/2009 7:39 PM 72992]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/6/2008 4:21 PM 19544]
    R2 bckwfs;Blue Coat K9 Web Protection;c:\program files\Blue Coat K9 Web Protection\k9filter.exe [2/7/2007 7:01 PM 1078560]
    R2 lxec_device;lxec_device;c:\windows\system32\lxeccoms.exe -service --> c:\windows\system32\lxeccoms.exe -service [?]
    R2 QuickBooksDB18;QuickBooksDB18;c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB18 --> c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB18 [?]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/6/2009 8:03 PM 133104]
    S2 lxecCATSCustConnectService;lxecCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxecserv.exe [3/17/2011 6:25 PM 193192]
    S3 Cobra_GPS;%Cobra_GPS.SvcDesc%;c:\windows\system32\drivers\Cobra_GPS.sys [4/13/2010 1:09 PM 15318]
    S3 JL2004A;JL2004A Photo Viewer;c:\windows\system32\Drivers\pv_wdm.sys --> c:\windows\system32\Drivers\pv_wdm.sys [?]
    S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [4/10/2010 5:05 PM 266544]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.199\McCHSvc.exe [2/23/2011 10:51 AM 237008]
    S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys --> c:\windows\system32\DRIVERS\motccgp.sys [?]
    S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [3/8/2009 4:45 PM 8320]
    S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\DRIVERS\motodrv.sys --> c:\windows\system32\DRIVERS\motodrv.sys [?]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-07 00:02]
    .
    2011-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-07 00:02]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    LSP: c:\progra~1\WHALEC~1\CLIENT~1\31265D~1.0\WhlLSP.dll
    TCP: {4DB6DBAA-9257-4BDA-8E68-023D8E034030} = 208.59.247.45,208.59.247.46
    .
    - - - - ORPHANS REMOVED - - - -
    .
    MSConfigStartUp-mumservice - c:\program files\Motorola\Software Update\mumservice.exe
    MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    AddRemove-Virtual Moon Altas Image Libraries - c:\progra~1\UNWISE.EXE
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-04-03 10:32
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'explorer.exe'(348)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Alwil Software\Avast5\AvastSvc.exe
    c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\eHome\ehRecvr.exe
    c:\windows\eHome\ehSched.exe
    c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
    c:\windows\system32\lxeccoms.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    c:\program files\Canon\CAL\CALMAIN.exe
    c:\windows\ehome\mcrdsvc.exe
    c:\windows\stsystra.exe
    c:\windows\system32\dllhost.exe
    .
    **************************************************************************
    .
    Completion time: 2011-04-03 10:46:27 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-04-03 14:46
    .
    Pre-Run: 93,165,649,920 bytes free
    Post-Run: 93,316,296,704 bytes free
    .
    - - End Of File - - 5E564CC0DE03E6A6A57D72807B7C2FB4
    ++++++++++++++++++++




    New DDS log post Combo-Fix:
    Attach.zip Attached
    +++++++++++++++++++
    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Mark Fedorov at 11:12:40.62 on Sun 04/03/2011
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.487 [GMT -4:00]
    .
    AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: Norton Internet Worm Protection *Disabled*
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost.exe -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
    C:\WINDOWS\system32\lxeccoms.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\stsystra.exe
    C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
    C:\Program Files\Lexmark Pro800-Pro900 Series\lxecmon.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\McAfee Security Scan\3.0.199\SSScheduler.exe
    C:\Program Files\Startup Guard 3\startupguard.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Documents and Settings\Mark Fedorov\Local Settings\Temporary Internet Files\Content.IE5\V9I7NJ7S\dds[1].scr
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 10\SnagitBHO.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
    TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
    TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
    TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
    mRun: [SigmatelSysTrayApp] stsystra.exe
    mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [lxecmon.exe] "c:\program files\lexmark pro800-pro900 series\lxecmon.exe"
    mRun: [EzPrint] "c:\program files\lexmark pro800-pro900 series\ezprint.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    dRunOnce: [RunNarrator] Narrator.exe
    StartupFolder: c:\docume~1\markfe~1\startm~1\programs\startup\startu~1.lnk - c:\program files\startup guard 3\startupguard.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.199\SSScheduler.exe
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    LSP: c:\progra~1\whalec~1\client~1\31265d~1.0\WhlLSP.dll
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
    DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15031/CTSUEng.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/56.39/uploader2.cab
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178497609035
    DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX27.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} - hxxps://my.airproducts.com:/InternalSite/WhlCompMgr.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15034/CTPID.cab
    TCP: {4DB6DBAA-9257-4BDA-8E68-023D8E034030} = 208.59.247.45,208.59.247.46
    Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
    Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-20 371544]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2008-4-6 301528]
    R1 bckd;bckd;c:\windows\system32\drivers\bckd.sys [2009-1-13 72992]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-6 19544]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-27 42184]
    R2 bckwfs;Blue Coat K9 Web Protection;c:\program files\blue coat k9 web protection\k9filter.exe [2007-2-7 1078560]
    R2 lxec_device;lxec_device;c:\windows\system32\lxeccoms.exe -service --> c:\windows\system32\lxeccoms.exe -service [?]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 QuickBooksDB18;QuickBooksDB18;c:\progra~1\intuit\quickb~2\qbdbmgrn.exe -hvquickbooksdb18 --> c:\progra~1\intuit\quickb~2\QBDBMgrN.exe -hvQuickBooksDB18 [?]
    R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-1-11 1174152]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-7-6 133104]
    S2 lxecCATSCustConnectService;lxecCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxecserv.exe [2011-3-17 193192]
    S3 Cobra_GPS;%Cobra_GPS.SvcDesc%;c:\windows\system32\drivers\Cobra_GPS.sys [2010-4-13 15318]
    S3 JL2004A;JL2004A Photo Viewer;c:\windows\system32\drivers\pv_wdm.sys --> c:\windows\system32\drivers\pv_wdm.sys [?]
    S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2010-4-10 266544]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.0.199\McCHSvc.exe [2011-2-23 237008]
    S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
    S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-3-8 8320]
    S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys --> c:\windows\system32\drivers\motodrv.sys [?]
    .
    =============== Created Last 30 ================
    .
    2011-04-02 21:13:04 -------- d-sha-r- C:\cmdcons
    2011-04-02 21:09:05 98816 ----a-w- c:\windows\sed.exe
    2011-04-02 21:09:05 89088 ----a-w- c:\windows\MBR.exe
    2011-04-02 21:09:05 256512 ----a-w- c:\windows\PEV.exe
    2011-04-02 21:09:05 161792 ----a-w- c:\windows\SWREG.exe
    2011-03-29 20:51:55 -------- d-----w- c:\docume~1\alluse~1\applic~1\McAfee Security Scan
    2011-03-29 20:51:38 -------- d-----w- c:\program files\McAfee Security Scan
    2011-03-25 03:09:08 -------- d-----w- c:\docume~1\markfe~1\locals~1\applic~1\assembly
    2011-03-25 03:08:10 -------- d-----w- c:\docume~1\markfe~1\locals~1\applic~1\TechSmith
    2011-03-25 03:06:49 -------- d-----w- c:\program files\common files\Wise Installation Wizard
    2011-03-20 14:03:00 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-03-17 23:13:57 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-03-17 23:07:32 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-03-17 22:43:25 -------- d-----w- c:\documents and settings\all users\Lx_cats
    2011-03-17 22:25:31 40960 ----a-w- c:\windows\system32\lxecvs.dll
    2011-03-17 22:25:30 442368 ----a-w- c:\windows\system32\lxeccoin.dll
    2011-03-17 22:25:30 157696 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\lxecdrpp.dll
    2011-03-17 22:25:26 983121 ----a-w- c:\windows\system32\lxk_gf.dll
    2011-03-17 22:25:25 86016 ----a-w- c:\windows\system32\lxecgcfg.dll
    2011-03-17 22:25:25 294912 ----a-w- c:\windows\system32\lxeccui.dll
    2011-03-17 22:25:25 110592 ----a-w- c:\windows\system32\lxeccuir.dll
    2011-03-17 22:25:17 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
    2011-03-17 22:25:17 87040 ----a-w- c:\windows\system32\dllcache\wiafbdrv.dll
    2011-03-17 22:24:23 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
    2011-03-17 22:24:09 372736 ----a-w- c:\windows\system32\LXECwupd.dll
    2011-03-17 22:24:09 213672 ----a-w- c:\windows\system32\LXECwupd.exe
    2011-03-17 22:22:50 -------- d-----w- c:\program files\Lexmark
    2011-03-17 22:18:33 -------- d-----w- c:\program files\Lexmark Pro800-Pro900 Series
    2011-03-17 22:18:32 299008 ----a-w- c:\windows\system32\LXECsm.dll
    2011-03-17 22:18:32 23552 ----a-w- c:\windows\system32\LXECsmr.dll
    2011-03-12 16:28:40 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
    .
    ==================== Find3M ====================
    .
    2011-02-23 14:04:21 40648 ----a-w- c:\windows\avastSS.scr
    2011-02-04 22:48:32 456192 ----a-w- c:\windows\system32\encdec.dll
    2011-02-04 22:48:30 291840 ----a-w- c:\windows\system32\sbe.dll
    2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
    2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
    .
    ============= FINISH: 11:15:07.93 ===============
    THANKS,

    -Mark

  8. #8
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi again,


    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    DDS::
    TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
    TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.


    Uninstall this old Java:
    J2SE Runtime Environment 5.0 Update 6



    * Go here to run an online scanner from ESET.
    • Note: You will need to use Internet explorer for this scan
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to install
    • Click Start
    • Make sure that the option Remove found threats is not checkmarked.
    • Click Scan
    • Wait for the scan to finish.


    Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log. Any issues left?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  9. #9
    Junior Member
    Join Date
    Sep 2006
    Posts
    21

    Default Next

    Combo fix log:

    ComboFix 11-04-02.03 - Mark Fedorov 04/03/2011 19:53:01.2.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.576 [GMT -4:00]
    Running from: c:\documents and settings\Mark Fedorov\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Mark Fedorov\Desktop\CFScript.txt
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-03-04 to 2011-04-04 )))))))))))))))))))))))))))))))
    .
    .
    2011-03-29 21:43 . 2011-03-29 21:44 -------- d-----w- c:\program files\ERUNT
    2011-03-29 20:54 . 2011-03-29 20:54 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee
    2011-03-29 20:51 . 2011-03-29 20:51 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
    2011-03-29 20:51 . 2011-03-29 20:51 -------- d-----w- c:\program files\McAfee Security Scan
    2011-03-25 03:09 . 2011-03-25 03:09 -------- d-----w- c:\documents and settings\Mark Fedorov\Local Settings\Application Data\assembly
    2011-03-25 03:08 . 2011-03-25 03:08 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
    2011-03-25 03:08 . 2011-03-25 03:08 -------- d-----w- c:\program files\TechSmith
    2011-03-25 03:08 . 2011-03-25 03:08 -------- d-----w- c:\documents and settings\Mark Fedorov\Local Settings\Application Data\TechSmith
    2011-03-25 03:06 . 2011-03-25 03:06 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2011-03-20 14:03 . 2011-02-23 13:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-03-17 23:13 . 2011-03-17 23:13 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-03-17 23:07 . 2011-03-17 23:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-03-17 23:06 . 2011-03-17 23:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2011-03-17 22:43 . 2011-04-01 17:29 -------- d-----w- c:\documents and settings\All Users\Lx_cats
    2011-03-17 22:25 . 2008-03-05 01:55 40960 ----a-w- c:\windows\system32\lxecvs.dll
    2011-03-17 22:25 . 2010-04-13 18:41 442368 ----a-w- c:\windows\system32\lxeccoin.dll
    2011-03-17 22:25 . 2009-11-04 12:14 157696 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\lxecdrpp.dll
    2011-03-17 22:25 . 2008-04-30 05:32 983121 ----a-w- c:\windows\system32\lxk_gf.dll
    2011-03-17 22:25 . 2009-11-09 06:59 86016 ----a-w- c:\windows\system32\lxecgcfg.dll
    2011-03-17 22:25 . 2009-10-21 09:06 110592 ----a-w- c:\windows\system32\lxeccuir.dll
    2011-03-17 22:25 . 2009-10-21 09:06 294912 ----a-w- c:\windows\system32\lxeccui.dll
    2011-03-17 22:25 . 2001-08-18 02:36 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
    2011-03-17 22:25 . 2001-08-18 02:36 87040 ----a-w- c:\windows\system32\dllcache\wiafbdrv.dll
    2011-03-17 22:24 . 2011-03-17 22:24 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
    2011-03-17 22:24 . 2010-04-14 19:08 213672 ----a-w- c:\windows\system32\LXECwupd.exe
    2011-03-17 22:24 . 2010-02-22 09:08 372736 ----a-w- c:\windows\system32\LXECwupd.dll
    2011-03-17 22:22 . 2011-03-17 22:25 -------- d-----w- c:\program files\Lexmark
    2011-03-17 22:18 . 2011-03-17 23:47 -------- d-----w- c:\program files\Lexmark Pro800-Pro900 Series
    2011-03-17 22:18 . 2009-02-20 08:48 23552 ----a-w- c:\windows\system32\LXECsmr.dll
    2011-03-17 22:18 . 2009-02-20 08:48 299008 ----a-w- c:\windows\system32\LXECsm.dll
    2011-03-12 16:28 . 2011-03-12 16:28 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-02-23 14:04 . 2010-08-28 00:13 40648 ----a-w- c:\windows\avastSS.scr
    2011-02-23 14:04 . 2007-05-04 01:24 190016 ----a-w- c:\windows\system32\aswBoot.exe
    2011-02-23 13:56 . 2008-04-06 20:21 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2011-02-23 13:55 . 2007-05-04 01:24 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2011-02-23 13:55 . 2007-05-04 01:24 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2011-02-23 13:55 . 2007-05-04 01:24 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2011-02-23 13:55 . 2007-05-04 01:24 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2011-02-23 13:54 . 2007-05-04 01:24 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2011-02-23 13:54 . 2008-04-06 20:21 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2011-02-04 22:48 . 2005-08-16 09:18 456192 ----a-w- c:\windows\system32\encdec.dll
    2011-02-04 22:48 . 2005-08-16 09:18 291840 ----a-w- c:\windows\system32\sbe.dll
    2011-02-02 07:58 . 2005-08-16 09:37 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2011-01-27 11:57 . 2005-08-16 09:37 677888 ----a-w- c:\windows\system32\mstsc.exe
    2011-01-21 14:44 . 2005-08-16 09:18 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2011-01-07 14:09 . 2005-08-16 09:18 290048 ----a-w- c:\windows\system32\atmfd.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2011-02-23 14:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 282624]
    "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "lxecmon.exe"="c:\program files\Lexmark Pro800-Pro900 Series\lxecmon.exe" [2011-01-23 770728]
    "EzPrint"="c:\program files\Lexmark Pro800-Pro900 Series\ezprint.exe" [2011-01-23 148280]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RunNarrator"="Narrator.exe" [2008-04-14 53760]
    .
    c:\documents and settings\Mark Fedorov\Start Menu\Programs\Startup\
    Startup Guard.lnk - c:\program files\Startup Guard 3\startupguard.exe [2011-2-1 778240]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.199\SSScheduler.exe [2011-2-23 272528]
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk /p \??\F:\0autocheck autochk *
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2010-09-21 04:07 932288 ------r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
    2008-04-17 18:14 98616 ------w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
    2007-07-17 16:03 868352 ------w- c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
    2008-05-06 08:42 202088 ------w- c:\program files\TomTom HOME 2\HOMERunner.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Meade\\AutostarSuite\\AutostarSuite.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
    "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
    "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
    "c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\WINDOWS\\system32\\lxeccoms.exe"=
    "c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
    .
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3/20/2011 10:03 AM 371544]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/6/2008 4:21 PM 301528]
    R1 bckd;bckd;c:\windows\system32\drivers\bckd.sys [1/13/2009 7:39 PM 72992]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/6/2008 4:21 PM 19544]
    R2 bckwfs;Blue Coat K9 Web Protection;c:\program files\Blue Coat K9 Web Protection\k9filter.exe [2/7/2007 7:01 PM 1078560]
    R2 lxec_device;lxec_device;c:\windows\system32\lxeccoms.exe -service --> c:\windows\system32\lxeccoms.exe -service [?]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/6/2009 8:03 PM 133104]
    S2 lxecCATSCustConnectService;lxecCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxecserv.exe [3/17/2011 6:25 PM 193192]
    S2 QuickBooksDB18;QuickBooksDB18;c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB18 --> c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB18 [?]
    S3 Cobra_GPS;%Cobra_GPS.SvcDesc%;c:\windows\system32\drivers\Cobra_GPS.sys [4/13/2010 1:09 PM 15318]
    S3 JL2004A;JL2004A Photo Viewer;c:\windows\system32\Drivers\pv_wdm.sys --> c:\windows\system32\Drivers\pv_wdm.sys [?]
    S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [4/10/2010 5:05 PM 266544]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.199\McCHSvc.exe [2/23/2011 10:51 AM 237008]
    S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys --> c:\windows\system32\DRIVERS\motccgp.sys [?]
    S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [3/8/2009 4:45 PM 8320]
    S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\DRIVERS\motodrv.sys --> c:\windows\system32\DRIVERS\motodrv.sys [?]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-07 00:02]
    .
    2011-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-07 00:02]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    LSP: c:\progra~1\WHALEC~1\CLIENT~1\31265D~1.0\WhlLSP.dll
    TCP: {4DB6DBAA-9257-4BDA-8E68-023D8E034030} = 208.59.247.45,208.59.247.46
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-04-03 20:08
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'explorer.exe'(920)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2011-04-03 20:12:30
    ComboFix-quarantined-files.txt 2011-04-04 00:12
    ComboFix2.txt 2011-04-03 14:46
    .
    Pre-Run: 93,146,148,864 bytes free
    Post-Run: 93,120,798,720 bytes free
    .
    - - End Of File - - D63C535BC89643245157EBFA7D664854

    ****************

    I deleted the Java application

    Ran the ESET scan... no log came out but it said it was ok, here is dds:
    ++++++++++++++++
    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Mark Fedorov at 22:45:06.15 on Sun 04/03/2011
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.446 [GMT -4:00]
    .
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: Norton Internet Worm Protection *Disabled*
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost.exe -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\lxeccoms.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Lexmark Pro800-Pro900 Series\lxecmon.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    C:\Program Files\McAfee Security Scan\3.0.199\SSScheduler.exe
    C:\Program Files\Startup Guard 3\startupguard.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\Mark Fedorov\Local Settings\Temporary Internet Files\Content.IE5\TJD7UGB2\dds[1].scr
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 10\SnagitBHO.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
    TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
    mRun: [SigmatelSysTrayApp] stsystra.exe
    mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [lxecmon.exe] "c:\program files\lexmark pro800-pro900 series\lxecmon.exe"
    mRun: [EzPrint] "c:\program files\lexmark pro800-pro900 series\ezprint.exe"
    mRun: [SunJavaUpdateSched] c:\program files\java\jre6\bin\jusched.exe
    dRunOnce: [RunNarrator] Narrator.exe
    StartupFolder: c:\docume~1\markfe~1\startm~1\programs\startup\startu~1.lnk - c:\program files\startup guard 3\startupguard.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.199\SSScheduler.exe
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\npjpi160_24.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    LSP: c:\progra~1\whalec~1\client~1\31265d~1.0\WhlLSP.dll
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
    DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15031/CTSUEng.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/56.39/uploader2.cab
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178497609035
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX27.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} - hxxps://my.airproducts.com:/InternalSite/WhlCompMgr.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15034/CTPID.cab
    TCP: {4DB6DBAA-9257-4BDA-8E68-023D8E034030} = 208.59.247.45,208.59.247.46
    Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
    Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-20 371544]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2008-4-6 301528]
    R1 bckd;bckd;c:\windows\system32\drivers\bckd.sys [2009-1-13 72992]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-6 19544]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-27 42184]
    R2 bckwfs;Blue Coat K9 Web Protection;c:\program files\blue coat k9 web protection\k9filter.exe [2007-2-7 1078560]
    R2 lxec_device;lxec_device;c:\windows\system32\lxeccoms.exe -service --> c:\windows\system32\lxeccoms.exe -service [?]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-1-11 1174152]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-7-6 133104]
    S2 lxecCATSCustConnectService;lxecCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxecserv.exe [2011-3-17 193192]
    S2 QuickBooksDB18;QuickBooksDB18;c:\progra~1\intuit\quickb~2\qbdbmgrn.exe -hvquickbooksdb18 --> c:\progra~1\intuit\quickb~2\QBDBMgrN.exe -hvQuickBooksDB18 [?]
    S3 Cobra_GPS;%Cobra_GPS.SvcDesc%;c:\windows\system32\drivers\Cobra_GPS.sys [2010-4-13 15318]
    S3 JL2004A;JL2004A Photo Viewer;c:\windows\system32\drivers\pv_wdm.sys --> c:\windows\system32\drivers\pv_wdm.sys [?]
    S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2010-4-10 266544]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.0.199\McCHSvc.exe [2011-2-23 237008]
    S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
    S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-3-8 8320]
    S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys --> c:\windows\system32\drivers\motodrv.sys [?]
    .
    =============== Created Last 30 ================
    .
    2011-04-04 00:43:29 -------- d-----w- c:\program files\ESET
    2011-04-03 23:50:55 -------- d-----w- C:\ComboFix
    2011-04-02 21:13:04 -------- d-sha-r- C:\cmdcons
    2011-04-02 21:09:05 98816 ----a-w- c:\windows\sed.exe
    2011-04-02 21:09:05 89088 ----a-w- c:\windows\MBR.exe
    2011-04-02 21:09:05 256512 ----a-w- c:\windows\PEV.exe
    2011-04-02 21:09:05 161792 ----a-w- c:\windows\SWREG.exe
    2011-03-29 20:51:55 -------- d-----w- c:\docume~1\alluse~1\applic~1\McAfee Security Scan
    2011-03-29 20:51:38 -------- d-----w- c:\program files\McAfee Security Scan
    2011-03-25 03:09:08 -------- d-----w- c:\docume~1\markfe~1\locals~1\applic~1\assembly
    2011-03-25 03:08:10 -------- d-----w- c:\docume~1\markfe~1\locals~1\applic~1\TechSmith
    2011-03-25 03:06:49 -------- d-----w- c:\program files\common files\Wise Installation Wizard
    2011-03-20 14:03:00 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-03-17 23:13:57 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-03-17 23:07:32 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-03-17 22:43:25 -------- d-----w- c:\documents and settings\all users\Lx_cats
    2011-03-17 22:25:31 40960 ----a-w- c:\windows\system32\lxecvs.dll
    2011-03-17 22:25:30 442368 ----a-w- c:\windows\system32\lxeccoin.dll
    2011-03-17 22:25:30 157696 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\lxecdrpp.dll
    2011-03-17 22:25:26 983121 ----a-w- c:\windows\system32\lxk_gf.dll
    2011-03-17 22:25:25 86016 ----a-w- c:\windows\system32\lxecgcfg.dll
    2011-03-17 22:25:25 294912 ----a-w- c:\windows\system32\lxeccui.dll
    2011-03-17 22:25:25 110592 ----a-w- c:\windows\system32\lxeccuir.dll
    2011-03-17 22:25:17 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
    2011-03-17 22:25:17 87040 ----a-w- c:\windows\system32\dllcache\wiafbdrv.dll
    2011-03-17 22:24:23 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
    2011-03-17 22:24:09 372736 ----a-w- c:\windows\system32\LXECwupd.dll
    2011-03-17 22:24:09 213672 ----a-w- c:\windows\system32\LXECwupd.exe
    2011-03-17 22:22:50 -------- d-----w- c:\program files\Lexmark
    2011-03-17 22:18:33 -------- d-----w- c:\program files\Lexmark Pro800-Pro900 Series
    2011-03-17 22:18:32 299008 ----a-w- c:\windows\system32\LXECsm.dll
    2011-03-17 22:18:32 23552 ----a-w- c:\windows\system32\LXECsmr.dll
    2011-03-12 16:28:40 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
    .
    ==================== Find3M ====================
    .
    2011-02-23 14:04:21 40648 ----a-w- c:\windows\avastSS.scr
    2011-02-04 22:48:32 456192 ----a-w- c:\windows\system32\encdec.dll
    2011-02-04 22:48:30 291840 ----a-w- c:\windows\system32\sbe.dll
    2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
    2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
    .
    ============= FINISH: 22:46:23.28 ===============
    ++++++++++++++
    attached is attached...

    Facebook seems to be working now, thanks.

  10. #10
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    If no other issues left, it's time to secure your system to prevent against further intrusions.


    THESE STEPS ARE VERY IMPORTANT

    Let's reset system restore
    Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

    1. Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    2. Reboot.

    3. Turn ON System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK.
    NOTE: only do this ONCE,NOT on a regular basis



    Now lets uninstall ComboFix:
    • Click START then RUN
    • Now copy-paste Combofix /uninstall in the runbox and click OK



    UPDATING WINDOWS AND INTERNET EXPLORER

    IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

    If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


    Make your Internet Explorer more secure

    This can be done by following these simple instructions:
    From within Internet Explorer click on the Tools menu and then click on Options.
    Click once on the Security tab
    Click once on the Internet icon so it becomes highlighted.
    Click once on the Custom Level button.
    Change the Download signed ActiveX controls to Prompt
    Change the Download unsigned ActiveX controls to Disable
    Change the Initialize and script ActiveX controls not marked as safe to Disable
    Change the Installation of desktop items to Prompt
    Change the Launching programs and files in an IFRAME to Prompt
    Change the Navigate sub-frames across different domains to Prompt
    When all these settings have been made, click on the OK button.
    If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.


    Download and run Secunia Personal Software Inspector (PSI) and fix its findings.


    Just a final reminder for you. I am trying to stress these two points.
    UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
    Make sure all of your security programs are up to date.
    Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


    Once again, please post and tell me how things are going with your system... problems etc.

    Have a great day,
    Blade
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •