Ivorytower
New member
I have lurked on and off for a while but I have finally joined up to plead for help. I think I really broke my OS this time. Hijackthis will not run. Most malware removal tools seem to fail and the browsers are well and truly hijacked.
I have isolated the system (pulled the network cable) and managed to run DDS to get some kind of log, any kind. I would have preferred hijack this logs but I simply couldn't get it to run.
______________________________________
DDS (Ver_09-05-14.01) - NTFSx86
Run by Master at 19:10:23.82 on Sun 07/06/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.3582.3022 [GMT 10:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Internet\Comodo Firewall Pro\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Internet\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Internet\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Utilities\BlueSoleil\BTNtService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Utilities\nHancer\nHancerService.exe
C:\Program Files\Audio\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\DVDRW\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Utilities\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Utilities\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Internet\Comodo Firewall Pro\cfp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Utilities\DAEMON Tools\daemon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Utilities\BlueSoleil\BlueSoleil.exe
C:\Program Files\Utilities\Nostromo\nost_LM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Master\Desktop\Recovery\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.abc.net.au/iview/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} -
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [NVIDIA nTune] "c:\program files\audio\ntune\nTuneCmd.exe" clear
uRun: [DAEMON Tools] "c:\program files\utilities\daemon tools\daemon.exe" -lang 1033
uRun: [SpybotSD TeaTimer] c:\program files\internet\spybot - search & destroy\TeaTimer.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [SpriteService] "c:\program files\sprite software\sprite backup\SpriteService.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [JMB36X IDE Setup] c:\windows\jm\JMInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\JMRaidSetup.exe boot
mRun: [EasyTuneV] c:\program files\gigabyte\et5\ETcall.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [RemoteControl] "c:\program files\dvdrw\powerdvd\PDVDServ.exe"
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [WireLessMouse ] c:\program files\utilities\multimedia combo set\MouseDrv.exe
mRun: [WireLessKeyboard ] c:\program files\utilities\multimedia combo set\PS2USBKbdDrv.exe
mRun: [Dit] Dit.exe
mRun: [COMODO Firewall Pro] "c:\program files\internet\comodo firewall pro\cfp.exe" -h
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [COMODO Internet Security] "c:\program files\internet\comodo firewall pro\cfp.exe" -h
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avgnt] "c:\program files\internet\avira\antivir desktop\avgnt.exe" /min
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32
dRunOnce: [IE7-11] rundll32 advpack.dll,LaunchINFSection NR_IE7en.inf,AfterUserStart
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueso~1.lnk - c:\program files\utilities\bluesoleil\BlueSoleil.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\loadou~1.lnk - c:\program files\utilities\nostromo\nost_LM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download All by FlashGet - c:\program files\internet\flashget\jc_all.htm
IE: Download using FlashGet - c:\program files\internet\flashget\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Open Link Target in Firefox - file://c:\documents and settings\master\application data\mozilla\firefox\profiles\tmc51llt.default\extensions\{5d558c43-550f-4b12-84ab-0d8abda9f975}\firefoxviewlink.html
IE: View This Page in Firefox - file://c:\documents and settings\master\application data\mozilla\firefox\profiles\tmc51llt.default\extensions\{5d558c43-550f-4b12-84ab-0d8abda9f975}\firefoxviewpage.html
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\internet\flashget\flashget.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {36ECAF82-3300-8F84-092E-AFF36D6C7040} - {86529161-034E-4F8A-88D2-3C625E612E04} - c:\program files\utilities\winhttrack\WinHTTrackIEBar.dll
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 85.255.112.101,85.255.112.113
TCP: {05B5AC85-3927-49BF-A58E-319AC8B81DD4} = 85.255.112.101,85.255.112.113
TCP: {0A0DC48B-8EC8-4F20-B57B-C3C92166D0B3} = 85.255.112.101,85.255.112.113
TCP: {3FFFA5CC-5CDF-48EF-BD6F-6F66BF1AD04A} = 85.255.112.101,85.255.112.113
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\internet\coreftp\pftpns.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\master\applic~1\mozilla\firefox\profiles\94si2l9p.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://partnerpage.google.com/highvale.net
FF - component: c:\documents and settings\master\application data\mozilla\firefox\profiles\94si2l9p.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\google\google updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\program files\video\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\video\divx\divx web player\npdivx32.dll
FF - plugin: c:\program files\video\vlc\npvlc.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\internet\avira\antivir desktop\avgio.sys [2009-5-1 11608]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2008-2-16 132640]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2008-2-16 24096]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\internet\avira\antivir desktop\sched.exe [2009-5-1 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\internet\avira\antivir desktop\avguard.exe [2009-5-1 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-1 55640]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\internet\comodo firewall pro\cmdagent.exe [2008-2-16 692496]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [2008-5-31 14976]
R3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [2003-7-24 22821]
R3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [2007-9-14 13440]
=============== Created Last 30 ================
2009-06-07 18:52 4,042 a------- c:\windows\system32\tmp.reg
2009-06-07 18:35 <DIR> --d----- c:\program files\Trend Micro
2009-06-07 17:36 3,018,864 a------- c:\temp\ComboFix.exe
2009-06-07 17:18 <DIR> --d----- c:\temp\Programs
2009-06-07 17:02 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-06-07 12:49 1,483,128 a------- c:\temp\SetupOneCare.exe
2009-06-07 12:31 <DIR> --d----- c:\program files\common files\PC Tools
2009-06-07 10:34 <DIR> --d----- c:\temp\t205249-how-to-delete-trojans-and-worms-from-registry_files
2009-06-07 10:32 <DIR> --d----- c:\temp\quickfix_files
2009-06-07 10:31 <DIR> --d----- c:\temp\Trend Micro HouseCall - Free Online Virus and Spyware Scan - Trend Micro UK_files
2009-06-07 10:31 <DIR> --d----- c:\temp\McAfee Threat Center_files
2009-06-07 10:30 <DIR> --d----- c:\temp\DisableSysRestore_files
2009-06-07 08:40 <DIR> --d----- c:\temp\File Assassin
2009-06-07 08:12 3,371,384 a------- c:\temp\mbam-setup.exe
2009-05-16 22:07 <DIR> --d----- c:\program files\NeoSmart Technologies
2009-05-14 01:18 <DIR> --dsh--- c:\documents and settings\master\IECompatCache
2009-05-12 16:33 <DIR> --dsh--- c:\documents and settings\master\PrivacIE
2009-05-12 16:05 <DIR> --dsh--- c:\documents and settings\master\IETldCache
2009-05-12 16:03 <DIR> --d----- c:\windows\ie8updates
2009-05-12 16:03 102,400 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-05-12 16:01 <DIR> -cd-h--- c:\windows\ie8
==================== Find3M ====================
2009-06-07 19:09 13,440 a------- c:\windows\system32\drivers\USBCRFT.SYS
2009-05-16 11:43 132,640 a------- c:\windows\system32\drivers\cmdGuard.sys
2009-05-15 19:07 168,208 a------- c:\windows\system32\guard32.dll
2009-05-15 19:07 24,096 a------- c:\windows\system32\drivers\cmdhlp.sys
2009-05-04 14:07 16,608 a------- c:\windows\gdrv.sys
2009-04-03 19:25 31,029 a------- c:\windows\DIIUnin.dat
2009-04-03 19:15 94,208 a------- c:\windows\DIIUnin.exe
2009-04-03 19:15 2,829 a------- c:\windows\DIIUnin.pif
2008-05-15 19:49 17,488 a------- c:\docume~1\master\applic~1\GDIPFONTCACHEV1.DAT
2008-02-14 14:28 29 a------- c:\program files\version.ini
2008-02-14 14:23 231,944 a------- c:\program files\gwflash.exe
2007-12-27 16:29 22,328 a------- c:\docume~1\master\applic~1\PnkBstrK.sys
2007-09-21 19:42 19,008 a------- c:\program files\markfun.a64
2007-08-21 19:49 125,504 a------- c:\program files\MarkFunDrv.dll
2007-08-21 19:49 17,912 a------- c:\program files\markfun.w32
2007-04-05 04:31 248,640 a------- c:\program files\update.exe
2007-03-30 04:36 301 a------- c:\program files\update.ini
2007-03-02 04:48 240,448 a------- c:\program files\gwf32.exe
2006-11-23 23:47 207,680 a------- c:\program files\BIOS_Run.exe
2006-11-23 23:40 60,224 a------- c:\program files\HUADRV.DLL
2006-11-03 18:09 528 a------- c:\program files\CONFIG.INI
2005-04-27 19:40 6,800 a------- c:\program files\W95_HUA.vxd
============= FINISH: 19:10:46.50 ===============
I have the attach.txt log file if it helps.
I hope someone can assist. This one is really beyond my ability. I think I have followed the "before you post" to the best of my ability. Please forgive me if I have erred.
Thanks in advance
I have isolated the system (pulled the network cable) and managed to run DDS to get some kind of log, any kind. I would have preferred hijack this logs but I simply couldn't get it to run.
______________________________________
DDS (Ver_09-05-14.01) - NTFSx86
Run by Master at 19:10:23.82 on Sun 07/06/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.3582.3022 [GMT 10:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Internet\Comodo Firewall Pro\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Internet\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Internet\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Utilities\BlueSoleil\BTNtService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Utilities\nHancer\nHancerService.exe
C:\Program Files\Audio\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\DVDRW\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Utilities\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Utilities\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Internet\Comodo Firewall Pro\cfp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Utilities\DAEMON Tools\daemon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Utilities\BlueSoleil\BlueSoleil.exe
C:\Program Files\Utilities\Nostromo\nost_LM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Master\Desktop\Recovery\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.abc.net.au/iview/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} -
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [NVIDIA nTune] "c:\program files\audio\ntune\nTuneCmd.exe" clear
uRun: [DAEMON Tools] "c:\program files\utilities\daemon tools\daemon.exe" -lang 1033
uRun: [SpybotSD TeaTimer] c:\program files\internet\spybot - search & destroy\TeaTimer.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [SpriteService] "c:\program files\sprite software\sprite backup\SpriteService.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [JMB36X IDE Setup] c:\windows\jm\JMInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\JMRaidSetup.exe boot
mRun: [EasyTuneV] c:\program files\gigabyte\et5\ETcall.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [RemoteControl] "c:\program files\dvdrw\powerdvd\PDVDServ.exe"
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [WireLessMouse ] c:\program files\utilities\multimedia combo set\MouseDrv.exe
mRun: [WireLessKeyboard ] c:\program files\utilities\multimedia combo set\PS2USBKbdDrv.exe
mRun: [Dit] Dit.exe
mRun: [COMODO Firewall Pro] "c:\program files\internet\comodo firewall pro\cfp.exe" -h
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [COMODO Internet Security] "c:\program files\internet\comodo firewall pro\cfp.exe" -h
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avgnt] "c:\program files\internet\avira\antivir desktop\avgnt.exe" /min
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32
dRunOnce: [IE7-11] rundll32 advpack.dll,LaunchINFSection NR_IE7en.inf,AfterUserStart
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueso~1.lnk - c:\program files\utilities\bluesoleil\BlueSoleil.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\loadou~1.lnk - c:\program files\utilities\nostromo\nost_LM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download All by FlashGet - c:\program files\internet\flashget\jc_all.htm
IE: Download using FlashGet - c:\program files\internet\flashget\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Open Link Target in Firefox - file://c:\documents and settings\master\application data\mozilla\firefox\profiles\tmc51llt.default\extensions\{5d558c43-550f-4b12-84ab-0d8abda9f975}\firefoxviewlink.html
IE: View This Page in Firefox - file://c:\documents and settings\master\application data\mozilla\firefox\profiles\tmc51llt.default\extensions\{5d558c43-550f-4b12-84ab-0d8abda9f975}\firefoxviewpage.html
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\internet\flashget\flashget.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {36ECAF82-3300-8F84-092E-AFF36D6C7040} - {86529161-034E-4F8A-88D2-3C625E612E04} - c:\program files\utilities\winhttrack\WinHTTrackIEBar.dll
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 85.255.112.101,85.255.112.113
TCP: {05B5AC85-3927-49BF-A58E-319AC8B81DD4} = 85.255.112.101,85.255.112.113
TCP: {0A0DC48B-8EC8-4F20-B57B-C3C92166D0B3} = 85.255.112.101,85.255.112.113
TCP: {3FFFA5CC-5CDF-48EF-BD6F-6F66BF1AD04A} = 85.255.112.101,85.255.112.113
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\internet\coreftp\pftpns.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\master\applic~1\mozilla\firefox\profiles\94si2l9p.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://partnerpage.google.com/highvale.net
FF - component: c:\documents and settings\master\application data\mozilla\firefox\profiles\94si2l9p.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\google\google updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\program files\video\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\video\divx\divx web player\npdivx32.dll
FF - plugin: c:\program files\video\vlc\npvlc.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\internet\avira\antivir desktop\avgio.sys [2009-5-1 11608]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2008-2-16 132640]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2008-2-16 24096]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\internet\avira\antivir desktop\sched.exe [2009-5-1 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\internet\avira\antivir desktop\avguard.exe [2009-5-1 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-1 55640]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\internet\comodo firewall pro\cmdagent.exe [2008-2-16 692496]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [2008-5-31 14976]
R3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [2003-7-24 22821]
R3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [2007-9-14 13440]
=============== Created Last 30 ================
2009-06-07 18:52 4,042 a------- c:\windows\system32\tmp.reg
2009-06-07 18:35 <DIR> --d----- c:\program files\Trend Micro
2009-06-07 17:36 3,018,864 a------- c:\temp\ComboFix.exe
2009-06-07 17:18 <DIR> --d----- c:\temp\Programs
2009-06-07 17:02 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-06-07 12:49 1,483,128 a------- c:\temp\SetupOneCare.exe
2009-06-07 12:31 <DIR> --d----- c:\program files\common files\PC Tools
2009-06-07 10:34 <DIR> --d----- c:\temp\t205249-how-to-delete-trojans-and-worms-from-registry_files
2009-06-07 10:32 <DIR> --d----- c:\temp\quickfix_files
2009-06-07 10:31 <DIR> --d----- c:\temp\Trend Micro HouseCall - Free Online Virus and Spyware Scan - Trend Micro UK_files
2009-06-07 10:31 <DIR> --d----- c:\temp\McAfee Threat Center_files
2009-06-07 10:30 <DIR> --d----- c:\temp\DisableSysRestore_files
2009-06-07 08:40 <DIR> --d----- c:\temp\File Assassin
2009-06-07 08:12 3,371,384 a------- c:\temp\mbam-setup.exe
2009-05-16 22:07 <DIR> --d----- c:\program files\NeoSmart Technologies
2009-05-14 01:18 <DIR> --dsh--- c:\documents and settings\master\IECompatCache
2009-05-12 16:33 <DIR> --dsh--- c:\documents and settings\master\PrivacIE
2009-05-12 16:05 <DIR> --dsh--- c:\documents and settings\master\IETldCache
2009-05-12 16:03 <DIR> --d----- c:\windows\ie8updates
2009-05-12 16:03 102,400 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-05-12 16:01 <DIR> -cd-h--- c:\windows\ie8
==================== Find3M ====================
2009-06-07 19:09 13,440 a------- c:\windows\system32\drivers\USBCRFT.SYS
2009-05-16 11:43 132,640 a------- c:\windows\system32\drivers\cmdGuard.sys
2009-05-15 19:07 168,208 a------- c:\windows\system32\guard32.dll
2009-05-15 19:07 24,096 a------- c:\windows\system32\drivers\cmdhlp.sys
2009-05-04 14:07 16,608 a------- c:\windows\gdrv.sys
2009-04-03 19:25 31,029 a------- c:\windows\DIIUnin.dat
2009-04-03 19:15 94,208 a------- c:\windows\DIIUnin.exe
2009-04-03 19:15 2,829 a------- c:\windows\DIIUnin.pif
2008-05-15 19:49 17,488 a------- c:\docume~1\master\applic~1\GDIPFONTCACHEV1.DAT
2008-02-14 14:28 29 a------- c:\program files\version.ini
2008-02-14 14:23 231,944 a------- c:\program files\gwflash.exe
2007-12-27 16:29 22,328 a------- c:\docume~1\master\applic~1\PnkBstrK.sys
2007-09-21 19:42 19,008 a------- c:\program files\markfun.a64
2007-08-21 19:49 125,504 a------- c:\program files\MarkFunDrv.dll
2007-08-21 19:49 17,912 a------- c:\program files\markfun.w32
2007-04-05 04:31 248,640 a------- c:\program files\update.exe
2007-03-30 04:36 301 a------- c:\program files\update.ini
2007-03-02 04:48 240,448 a------- c:\program files\gwf32.exe
2006-11-23 23:47 207,680 a------- c:\program files\BIOS_Run.exe
2006-11-23 23:40 60,224 a------- c:\program files\HUADRV.DLL
2006-11-03 18:09 528 a------- c:\program files\CONFIG.INI
2005-04-27 19:40 6,800 a------- c:\program files\W95_HUA.vxd
============= FINISH: 19:10:46.50 ===============
I have the attach.txt log file if it helps.
I hope someone can assist. This one is really beyond my ability. I think I have followed the "before you post" to the best of my ability. Please forgive me if I have erred.
Thanks in advance