Internet Redirect - iexplorer - shutting down select programs - help?

Hi

I don't think ComboFix update caused the issue there. Since those recovery steps didn't work I'm afraid there's no other possibility left than reformat. You could try to attach the drive to other system as slave drive to backup pictures, music and videos.
 
Thanks for your assistance with this attempt. Please post your standard advise on proper protective configuration so I will have it for when I complete a new Windows installation.

Also - I'm fortunate to have multiple drives connected to the computer with many of my important files residing off the c drive. What procedure should I follow to make sure the malware isn't hiding in any of those files once I begin rebuilding?
 
Hi

Please, find below some tips to keep system safer in future:

UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

  • Download Adaware
    Adaware is a free program. It scans for known spyware on your computer. These scans should be run at least once every two weeks. For more information, see this tutorial
    The program is available for download here
  • Download Spybot
    Spybot is a scanner like adaware. It scans for spyware and other malicious programs. It is important to have both Adaware and Spybot on your computer because each program provides unique detection and pretection measures. Spybot has preventitive tools that stop programs from even installing on your computer.
    To see how to set this up as well as more spybot features, see here
    Spybot can be downloaded at this location
  • hosts file:
    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
    • This is why using a hosts file is optional!!
    Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
    If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    1. [*]Click the start button (at the lower left hand corner of your screen) [*]Click run [*]In the dialog box, type services.msc [*]hit enter, then locate dns client [*]Highlight it, then double-click it. [*]On the dropdown box, change the setting from automatic to manual. [*]Click ok
  • Get Anti Virus Software and keep it updated - Most AVs will update automatically, but if not I would recommend making updating the AV the first job every time the PC is connected to the internet. An AV that is using defs that are seven days old is not going to be much protection. If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out. Good free antivirus programs are:
    Antivir
    Avast!
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free or Comodo Firewall Pro (If you choose Comodo: Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and install firewall ONLY!).


Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Run the spybot and adaware regularly. (Once or twice a week minimum.)
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.



What procedure should I follow to make sure the malware isn't hiding in any of those files once I begin rebuilding?
You should scan your other drives with antivirus scanner. Also, running an online scan (with Kaspersky Online Scanner for example) wouldn't make any harm.
 
Update

Used recovery panel to restore autobackup by ERUNT from back a little further in time and was able to get Windows to start. Carefully ran instructions to run ComboFix and got the blue screen stop error again. Restored again and skipped the ComboFix step.

Deleted all old installations of Java and installed the JRE6 Update 13 as instructed.

Downloaded ATF and cleaned up all temp files.

The Kaspersky Online Scanner will not run. I get a script error in the bottom left hand corner of IE... when I double click that I get the standard script error window, but with no detail and I have to close the window multiple times to get back to IE7.

I currently get a single extra copy of iexplorer.exe in the processes Window. If I "end process" that process, it takes longer to come back, but still comes back. AND Microsoft Money still will not run.

What's my next step? -- a new hjt log follows in the next post.

Here's the uninstall file:
123 Free Solitaire
1Click DVD to Divx Avi 2.12
2Wire Wireless Client
AccuChef
Active Disk
Actual Checkers 2000 R
Adaptec EZ-SCSI Standard Edition 5.0
Adobe After Effects 5.5
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 ActiveX
Adobe Flash Player Plugin
Adobe GoLive 6.0
Adobe Illustrator 10.0.3
Adobe PageMaker 6.5
Adobe Photoshop 6.0
Adobe Photoshop 7.0
Adobe Reader 7.0.5 Language Support
Adobe Reader 7.1.0
Adobe SVG Viewer 3.0
Adobe Type Manager Deluxe 4.1
Adobe® Photoshop® Album Starter Edition 3.2
AniRez
Apple Mobile Device Support
Apple Software Update
ATI Display Driver
ATI Multimedia Center
Autodesk DWF Viewer
AWSPS 4.02
Beyond TV DVD Burning Foundation
Beyond TV DVD Burning Foundation
Calculator Powertoy for Windows XP
Chessmaster 8000
Command & Conquer Generals
Command & Conquer Red Alert 2
Command & Conquer Tiberian Sun
Command && Conquer Red Alert 2 - Yuri's Revenge
Command and ConquerTM Generals Zero Hour
Cover Art Downloader v1.2
Critical Update for Windows Media Player 11 (KB959772)
CuteFTP 5.0 XP
dBpowerAMP Music Converter
DesignPro 5.0 Limited Edition
Desktop Architect
Dialog Box Assistant 1.01
DING!
Director 8 Shockwave Studio
DirectVobSub (remove only)
DivX Codec
DivX Converter
DivX Player
DivX Web Player
Doppler 10 Pinpoint Alert
DR-92 Manager
Elecard MPEG Player
Empire Earth
Enable S3 for USB Device
ERUNT 1.1j
Eudora
FastTrak RAID controller utility
FontLook
getPlus(R) for Adobe
GetRight
GoldLeo DVD Ripper 2.2
Hauppauge WinTV Scheduler
Hauppauge WinTV2000
Hauppauge WinTV-PVR 150 Drivers
Hello (remove only)
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
hp deskjet 840c series
hp deskjet 840c series (Remove only)
HTMLPad 2004 Pro v5.0
HyperCD
ICQ
IKEA HomePlanner Kitchen
InterVideo FilterSDK for Hauppauge
Iomega App Services
IomegaWare
iSofter DVD Ripper Platinum 3.0.2007.228
iTunes
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment Standard Edition v1.3.1
Java 2 Runtime Environment, SE v1.4.2_06
Java(TM) 6 Update 2
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6 Update 1
JMail
LiveUpdate 2.5 (Symantec Corporation)
Logitech Desktop Messenger
Logitech MouseWare 9.41 .1
Macromedia Dreamweaver 4
Macromedia Extension Manager
Macromedia Flash 5
Macromedia FreeHand 9
Macromedia Generator 2
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
Media Cleaner Pro
Media Library Management Wizard
microKORG SoundEditor
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Age of Empires II
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Interactive CD Sampler
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money Plus
Microsoft Money Shared Libraries
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows Media Video 9 VCM
Microsoft Windows XP Video Decoder Checkup Utility
Microsoft Word 97 Time Mgmt Wizard Pack (Remove only)
Movavi Video Converter 6
Movie Maker Background Music Files
Movie Maker Sound Effects
Movie Maker Title Images
Mozilla Firefox (2.0.0.8)
MSN Entertainment Download Troubleshooter
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
Multimedia Card Reader
Musicmatch® Jukebox
Musicnotes Player V1.23.1 and Viewer
MySQL Connector/ODBC 3.51
Myst IV - Revelation
nanoPEG-Editor 2.2 Hauppauge Edition
Napster
NEC-Mitsubishi NaViSet
NetAccountability
Netflix Movie Viewer
Norton Ghost
NovaBACKUP
NovaBACKUP
NVIDIA Drivers
OpenMG Limited Patch 3.4-04-16-16-01
OpenMG Secure Module 3.4.01
Opera 9.10
Palm Desktop
Personal Color Viewer 2.0
Plus! MP3 Audio Converter LE
PolderbitS Sound Recorder and Editor
QTam Bitmap to Icon 3.5
QuickTime
Ray Dream Studio v5.0
Real Alternative 1.52 Lite
REALmagic Hollywood Plus
Red Alert Windows 95
Roxio Burn Engine
Roxio Easy Media Creator 7
Safari
SCRABBLE
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Shockwave
Sid Meier's Alpha Centauri
SimCity 3000
SnapStream Beyond TV 4.6.1
SnapStream Firefly Mini 1.0.2
Solid Oak Software WhatsMyDNS 1.8.2.23
Sonic CinePlayer MPEG Combo Pack
Sound Blaster PCI128
Spybot - Search & Destroy
SuperDVD Player V4.0
SureThing CD Labeler 4 SE
Ten Thumbs 4.3
Ten Thumbs Typing Tutor
TPP Storage Class Driver
TrayDay
TWC Customer Controls
Tweaki...for Power Users
Tweakui Powertoy for Windows XP
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
USB 2.0 Host Controller Driver
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Visual Studio 2005 Redist Package
VNC Free Edition 4.1.1
WavePad Uninstall
Westwood Shared Internet Components
Windows Communication Foundation
Windows Genuine Advantage v1.3.0254.0
Windows Imaging Component
Windows Media Bonus Pack for Windows XP
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Media Player Playlist Import to Excel Wizard
Windows Media Player Skin Importer
Windows Media Player Tray Control
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinRAR archiver
WinZip
WordPerfect Office 2002
WordPerfect Office 2002
Wtcc II
XviD MPEG-4 Video Codec
 
htj log 5/5

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:50:00 PM, on 5/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\cyb2k.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Startup: TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: 2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (file missing) (HKCU)
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} (Live365PlayerVIP Class) - http://www.live365.com/players/p365vip.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {5197842F-0557-48AE-9552-7594F7C98F04} (PWReset Control) - http://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - http://entimg.msn.com/client/msnediag3518.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} -
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk DWF Viewer Control) - http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax3518.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Backup Scheduler - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe
O23 - Service: Promise FastTrak Log Service (FastTrakSvc) - Promise Technology Inc. - C:\Program Files\Promise\FastTrak\FtrakSvc.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NovaStor NovaBACKUP Backup/Copy Engine (NsService) - NovaStor - C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Real time Backup Loader - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

--
End of file - 11132 bytes
 
Hi

I assume that uninstall list was taken before all old Java removes etc. Is that right?

Start hjt, do a system scan, check (if found):
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


Close browsers and fix checked.


AND Microsoft Money still will not run.
Can't recall if this was mentioned earlier. Do you get any error message?


Please try download and run DDS. Post back dds.txt contents.
 
Yes - uninstall list was generated before JAVA was removed.

hjt can not remove:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

The rest of the lines deleted successfully.

Microsoft Money says:

Error - Shutting down...
Money has experienced a problem and cannot continue.
If you are running low on memory, try closing some programs and running Money again.

Memory is not an issue so I can't explain the error.

Here's the DDS log - please note, I uninstalled AVG during this process and wanted to get protection going so this didn't get any worse - so I installed avast.


DDS (Ver_09-03-16.01) - FAT32x86
Run by David Wilson at 18:41:18.01 on Wed 05/06/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1134 [GMT -4:00]

AV: avast! antivirus 4.8.1335 [VPS 090506-0] *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\David Wilson\Desktop\dds.scr

============== Pseudo HJT Report ===============

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - e:\program files\getright\xx2gr.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: Plaxo: {81ca3009-6200-4a6d-93c6-f1e9a6821c7f} -
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {06E58E5E-F8CB-4049-991E-A41C03BD419E} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [LDM] \Program\BackWeb-8876480.exe
mRun: [PRISMSVR.EXE] "c:\windows\system32\PRISMSVR.EXE" /APPLY
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [ezShieldProtector for Px] c:\windows\system32\ezSP_Px.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [C2K] c:\windows\cyb2k.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\trayday.lnk - c:\program files\trayday\TrayDay.exe
StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - e:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\2wirew~1.lnk - c:\program files\2wire 802.11g wireless\PRISMCFG.exe
uPolicies-explorer: NoFavoritesMenu = 1 (0x1)
dPolicies-explorer: NoFavoritesMenu = 1 (0x1)
IE: {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - c:\program files\hello\PicasaCapture.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\system\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\system\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: Yahoo! Checkers - hxxp://download.games.yahoo.com/games/clients/y/kt0_x.cab
DPF: Yahoo! Chess - hxxp://download.yahoo.com/games/clients/y/cr1_x.cab
DPF: Yahoo! Hearts - hxxp://download.yahoo.com/games/clients/y/hr1_x.cab
DPF: Yahoo! Pool 2 - hxxp://download.yahoo.com/games/clients/y/por9_x.cab
DPF: {00000075-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxmsdec.CAB
DPF: {00000160-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {31564D57-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmvax.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - hxxp://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - hxxp://entimg.msn.com/client/msnediag3518.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} - hxxp://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab
DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxp://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C}
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778
DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - hxxp://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab
DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} - hxxp://www.live365.com/players/play365.cab
DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} - hxxp://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - hxxp://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - hxxp://entimg.msn.com/client/msnmusax3518.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - e:\program files\eudora\EUSHLEXT.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\davidw~1\applic~1\mozilla\firefox\profiles\5nzx41m4.default\
FF - prefs.js: browser.search.selectedEngine - Google

============= SERVICES / DRIVERS ===============

R0 amdagp10;AMD IG AGP Bus Filter;c:\windows\system32\drivers\amdagp10.sys [2003-3-25 22994]
R0 dcsnap;dcsnap;c:\windows\system32\drivers\dcsnap.sys [2008-10-11 77472]
R0 fasttrak;fasttrak;c:\windows\system32\drivers\Fasttrak.sys [2005-1-14 70656]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-6 114768]
R1 Cinemsup;Cinemsup;c:\windows\system32\drivers\cinemsup.sys [2002-7-19 6656]
R1 DCDisk;DCDisk;c:\windows\system32\drivers\DCDisk.sys [2008-10-11 155648]
R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2003-12-17 5632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-6 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-5-6 138680]
R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2001-8-23 14336]
R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\novastor\novastor novabackup\NsService.exe [2008-6-17 207936]
R2 Real time Backup Loader;Real time Backup Loader;c:\program files\novastor\novastor novabackup\dr\FsLoader.exe [2008-10-11 93248]
R3 4mmdat;4mmdat;c:\windows\system32\drivers\4mmdat.sys [2001-8-17 12288]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-5-6 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-5-6 352920]
S1 efbDisk;efbDisk; [x]
S2 Backup Scheduler;Backup Scheduler;c:\program files\novastor\novastor novabackup\dr\cbp\DCSchdlerSRVC.exe [2008-10-11 98304]
S3 ati2mpaa;ati2mpaa;c:\windows\system32\drivers\ati2mpaa.sys [2002-3-23 281856]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\system32\drivers\atirtcap.sys [2002-3-23 49920]
S3 DDCCI;DDC/CI monitor;c:\windows\system32\drivers\Moni2c.sys [2003-3-30 6494]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-10-4 33752]
S3 hcwPVRP2;Hauppauge WinTV PVR PCI II (Encoder);c:\windows\system32\drivers\hcwPVRP2.sys [2005-5-22 814464]
S3 zremote;zremote;c:\windows\system32\drivers\zremote.sys [2005-5-22 10368]

=============== Created Last 30 ================

2009-05-06 00:03 147,100 a---h--- c:\windows\system32\mlfcache.dat
2009-05-05 22:38 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-05 22:38 73,728 a------- c:\windows\system32\javacpl.cpl
2009-05-05 22:27 0 a------- c:\windows\system32\REN33.tmp
2009-05-05 22:27 0 a------- c:\windows\system32\REN32.tmp
2009-05-05 22:16 652 a------- c:\windows\system32\snetfil.dll
2009-05-05 22:16 540 a------- c:\windows\system32\srchfrgn.dll
2009-05-05 22:16 258 a------- c:\windows\system32\srchout.dll
2009-05-05 22:16 306 a------- c:\windows\system32\picsfil.dll
2009-05-05 22:16 194 a------- c:\windows\system32\igefil.dll
2009-05-05 22:16 116 a------- c:\windows\system32\nfil.dll
2009-05-05 22:16 34 a------- c:\windows\system32\macfil.dll
2009-05-05 22:16 18 a------- c:\windows\system32\lastupdate.dll
2009-05-05 22:16 400 a------- c:\windows\system32\bsnlst.dll
2009-05-05 22:16 100 a------- c:\windows\system32\bnrfil.dll
2009-05-05 22:11 2,709 a------- c:\windows\system32\gibbebx.dat
2009-05-05 22:10 1,024 ----h--- C:\diskfile1
2009-05-05 22:10 16,384 ----h--- C:\logicinf.bin
2009-05-05 22:01 60,416 a------- c:\windows\system32\drivers\Combo-Fix.sys
2009-05-05 21:58 389,120 a------- c:\windows\system32\CF11739.exe
2009-05-05 21:58 <DIR> --d----- C:\ComboFix
2009-05-05 21:58 389,120 a------- c:\windows\system32\CF11674.exe
2009-05-05 21:57 389,120 a------- c:\windows\system32\CF11570.exe
2009-05-05 21:53 2,709 a------- c:\windows\system32\dllgidoor.dat
2009-04-23 20:40 389,120 a------- c:\windows\system32\CF18599.exe
2009-04-23 20:39 389,120 a------- c:\windows\system32\CF18413.exe
2009-04-22 18:53 <DIR> a-dshr-- C:\cmdcons
2009-04-22 18:52 161,792 a------- c:\windows\SWREG.exe
2009-04-22 18:52 98,816 a------- c:\windows\sed.exe
2009-04-19 18:34 360,021 a------- C:\something.scr
2009-04-18 00:21 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-04-18 00:21 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-04-17 21:04 <DIR> --d----- c:\docume~1\davidw~1\applic~1\Malwarebytes
2009-04-17 21:04 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-17 21:04 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-17 21:04 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-04-17 21:04 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-17 19:53 66 a------- c:\windows\wininit.ini
2009-04-17 08:22 <DIR> --d----- C:\!KillBox
2009-04-16 21:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}
2009-04-14 09:44 <DIR> --d----- C:\fixwareout
2009-04-14 09:40 <DIR> --d----- c:\program files\Trend Micro
2009-04-13 21:09 <DIR> --d----- c:\program files\AVG
2009-04-13 21:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8

==================== Find3M ====================

2009-04-22 19:04 5,880 a------- c:\windows\system32\wfileu.drv
2009-02-09 07:13 1,846,784 -------- c:\windows\system32\win32k.sys
2009-02-09 07:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2008-12-16 19:23 726,008 a------- c:\documents and settings\david wilson\gotomypc_438.exe
2008-11-06 12:33 726,008 a------- c:\documents and settings\david wilson\gotomypc_437.exe
2001-11-06 00:23 266 ---sh--- c:\program files\desktop.ini
2001-11-06 00:23 11,079 ----h--- c:\program files\folder.htt
2001-01-19 12:04 21,841 a------- c:\program files\common files\tppupd2k.dll
2001-01-19 11:04 21,329 -------- c:\program files\common files\tppupd98.dll
2008-10-04 15:44 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100420081005\index.dat
2001-11-13 10:18 8 ---sh--- c:\windows\all users\drm\pdrm.dat

============= FINISH: 18:41:57.28 ===============
 
hjt can not remove:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

The rest of the lines deleted successfully.
Hi

Those are not malicious so we can leave them there :)


Microsoft Money says:

Error - Shutting down...
Money has experienced a problem and cannot continue.
If you are running low on memory, try closing some programs and running Money again.
Could you try to reinstall MS Money? It's possible that infection has harmed it.
 
New/continued symptoms:

1. Continued instance of IEXPLORE.EXE process in task manager - even when program is not running.

2. Executing commands in My Computer window causes Explorer.exe to re-start and triggers the execution of multiple instances of IEXPLORE.EXE. I can not copy and paste or drag files between folders without this happening. (Does windows XP use IEXPLORE to navigate folders??)

3. When typing in a web address, about half the time I get a white screen with the message (your explorer window is blocking attempts to redirect, please click here). If I don't click, the site I want eventually opens... if I do click, I end up somewhere else.

4. Uninstalling and then re-installing Money did not fix the problem with that program.
 
Hi

Let's get some more info and after that run ComboFix again.

Download GMER and save it your desktop:
  • Extract it to your desktop and double-click GMER.exe
  • Click rootkit-tab and then scan.
  • Don't check
    Show All
    box while scanning in progress!
  • When scanning is ready, click Copy.
  • This copies log to clipboard
  • Post log in your reply.

Please run ComboFix normally by double clicking it (let it update if asked for a permission). Post back its log & a fresh dds.txt log.
 
update

GMER ran successfully... log follows... but after a ComboFix scan got the blue screen of death again. Getting good at restore. At next available moment I'm planning to run ComboFix again and try to get a list of the .dll files it says it is deleating.

Note... though the subs folder under erdnt is the newest recovery file, it also results in a stop error. have to use a slightly older one. does this make sense?

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-08 19:26:43
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAC1306B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAC130574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAC130A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAC13014C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAC13064E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAC13008C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAC1300F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAC13076E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAC13072E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAC1308AE]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!TranslateMessage 7E418BF6 6 Bytes PUSH 02C01430; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 42F0F341 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DefWindowProcA 7E42C17E 6 Bytes PUSH 02C01770; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 430A187F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 430A1800 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 430A1844 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 430A178C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 430A17C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 430A18BA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 42F316F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetCloseHandle 7805DA59 6 Bytes PUSH 02BFFB38; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!HttpOpenRequestA 78064341 6 Bytes CALL 3B090335
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetConnectA 7806499A 6 Bytes PUSH 02BFED7C; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetReadFile 7806ABB4 6 Bytes PUSH 02BFF2A8; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetQueryDataAvailable 7806ADF5 6 Bytes PUSH 02BFF810; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!HttpSendRequestA 7806CD40 6 Bytes PUSH 02C00B84; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!HttpSendRequestW 78080825 6 Bytes PUSH 02C00648; RET

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[616] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[616] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}
Reg HKLM\SOFTWARE\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}
Reg HKLM\SOFTWARE\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}
Reg HKLM\SOFTWARE\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}
Reg HKLM\SOFTWARE\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}
Reg HKLM\SOFTWARE\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E8066BAB-BCF1-46CA-D8AA-605D8DE00F6D}

---- EOF - GMER 1.0.15 ----
 
Hi

Did you run ComboFix without that cfscript? It's important that you don't use the script but run normally by double-clicking ComboFix.exe file.
 
Well, run ComboFix again and try to write down item names seen there during the run.
 
Combofix Log - FINALLY!!

Ran ComboFix - did not get any indication of deleted files.
Got Stop Error
Restored
Ran ComboFix - did not get any indication of deleted files.
Got Stop Error
Rebooted and chose last know settings during bootprocess.
Successfully booted into Windows. Here is the ComboFix log

ComboFix 09-05-14.03 - David Wilson 05/14/2009 22:42.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1135 [GMT -4:00]
Running from: c:\documents and settings\David Wilson\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090514-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\diskfile1
C:\logicinf.bin
c:\windows\system32\bnrfil.dll
c:\windows\system32\bsnlst.dll
c:\windows\system32\co32andlo.dat
c:\windows\system32\cocoerrfo.dat
c:\windows\system32\dllto32to.dat
c:\windows\system32\gapiyshe.dat
c:\windows\system32\igefil.dll
c:\windows\system32\lastupdate.dll
c:\windows\system32\macfil.dll
c:\windows\system32\nfil.dll
c:\windows\system32\orptofo.dat
c:\windows\system32\picsfil.dll
c:\windows\system32\snetfil.dll
c:\windows\system32\srchfrgn.dll
c:\windows\system32\srchout.dll
c:\windows\system32\unicodem.exe
c:\windows\system32\usrgfil.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DCDISK
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Legacy_DCDISK
-------\Legacy_IPRIP
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Service_Iprip
-------\Legacy_DCDISK
-------\Legacy_IDSVCSPTISRV
-------\Legacy_IPRIP
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Service_idsvcSPTISRV
-------\Service_Iprip
-------\Legacy_DCDISK
-------\Legacy_IDSVCSPTISRV
-------\Legacy_IPRIP
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Service_idsvcSPTISRV
-------\Service_Iprip
-------\Legacy_DCDISK
-------\Legacy_IDSVCSPTISRV
-------\Legacy_IPRIP
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Service_idsvcSPTISRV
-------\Service_Iprip


((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.

2009-05-15 02:06 . 2009-05-15 02:06 -------- d-----w c:\documents and settings\David Wilson\Local Settings\Application Data\PCHealth
2009-05-13 11:50 . 2009-05-13 11:50 -------- d-sh--w C:\FOUND.043
2009-05-08 15:01 . 2009-05-08 15:01 0 --s-a-w c:\windows\system32\148114617.dat
2009-05-08 02:11 . 2009-05-08 02:11 -------- d-----w c:\program files\Microsoft Money Plus
2009-05-06 04:10 . 2009-05-06 04:10 -------- d-----w c:\program files\Alwil Software
2009-05-06 04:03 . 2009-05-06 04:03 147100 ---ha-w c:\windows\system32\mlfcache.dat
2009-05-06 02:38 . 2009-05-06 02:38 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-06 02:11 . 2009-05-06 02:11 2709 ----a-w c:\windows\system32\gibbebx.dat
2009-05-06 02:10 . 2009-05-15 03:07 15360 ---h--w C:\logicinf.bin
2009-05-06 01:53 . 2009-05-06 01:53 2709 ----a-w c:\windows\system32\dllgidoor.dat
2009-04-20 23:43 . 2009-04-20 23:43 -------- d-----w C:\rsit
2009-04-19 22:34 . 2009-04-19 22:29 360021 ----a-w C:\something.scr
2009-04-18 18:49 . 2009-04-18 18:49 -------- d-----w c:\program files\ERUNT
2009-04-18 14:09 . 2009-04-18 14:09 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-18 04:21 . 2009-04-18 04:21 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-18 04:21 . 2009-04-18 04:21 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\documents and settings\David Wilson\Application Data\Malwarebytes
2009-04-18 01:04 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-18 01:04 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-17 12:22 . 2009-04-17 12:22 -------- d-----w C:\!KillBox
2009-04-17 01:53 . 2009-04-17 01:53 184304 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-17 01:42 . 2009-04-17 01:42 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Seven Zip
2009-04-17 01:28 . 2009-04-17 01:28 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2009-04-17 01:28 . 2009-04-17 01:28 -------- d-----w c:\documents and settings\Administrator\Application Data\Apple Computer
2009-04-17 01:19 . 2009-04-17 01:19 -------- d-----w c:\documents and settings\Guest\Local Settings\Application Data\Seven Zip
2009-04-17 01:18 . 2009-04-17 01:18 -------- d-----w c:\documents and settings\Guest\Application Data\Apple Computer
2009-04-17 01:18 . 2009-04-17 01:18 -------- d-----w c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
2009-04-17 01:00 . 2009-04-17 01:00 -------- d-----w c:\documents and settings\All Users\Application Data\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}
2009-04-17 00:59 . 2009-04-17 00:59 -------- d-----w c:\documents and settings\David Wilson\Local Settings\Application Data\Seven Zip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-06 02:27 . 2009-05-06 02:27 0 ----a-w c:\windows\system32\REN33.tmp
2009-05-06 02:27 . 2009-05-06 02:27 0 ----a-w c:\windows\system32\REN32.tmp
2009-05-06 01:54 . 2002-08-14 03:28 39 ----a-w c:\windows\liccyval.dat
2009-04-22 23:05 . 2003-09-27 00:07 1222 ----a-w c:\windows\system32\usrfil.dll
2009-04-22 23:04 . 2002-08-14 03:28 5880 ----a-w c:\windows\system32\wfileu.drv
2009-04-14 13:40 . 2009-04-14 13:40 -------- d-----w c:\program files\Trend Micro
2009-04-14 01:09 . 2009-04-14 01:09 -------- d-----w c:\program files\AVG
2001-11-06 04:23 . 2000-05-13 03:43 266 --sh--w c:\program files\desktop.ini
2001-11-06 04:23 . 2000-05-13 03:43 11079 ---h--w c:\program files\folder.htt
2001-01-19 16:04 . 2005-02-06 20:12 21841 ----a-w c:\program files\Common Files\tppupd2k.dll
2001-01-19 15:04 . 2002-02-24 01:38 21329 ------w c:\program files\Common Files\tppupd98.dll
2007-10-09 05:33 . 2005-04-28 02:53 66408 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2007-10-09 05:33 . 2005-04-28 02:53 54112 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-10-09 05:33 . 2007-10-20 14:31 34688 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2007-10-09 05:33 . 2007-10-20 14:31 46456 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-10-09 05:33 . 2005-04-28 02:53 171880 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
2001-11-13 14:18 . 2001-11-13 14:18 8 --sh--w c:\windows\All Users\DRM\pdrm.dat
2008-05-19 02:07 . 2008-05-19 02:07 0 --sha-w c:\windows\All Users\DRM\Cache\Indiv02.tmp
.

------- Sigcheck -------

[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\SYSTEM32\DRIVERS\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\SYSTEM32\dllcache\tcpip.sys
[-] 2008-04-13 19:20 361344 ACCF5A9A1FFAA490F33DBA1C632B95E1 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2005-05-25 19:07 359936 63FDFEA54EB53DE2D863EE454937CE1E c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2006-01-13 16:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2007-10-30 15:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB893066$\tcpip.sys
[-] 2005-05-25 19:04 359808 88763A98A4C26C409741B4AA162720C9 c:\windows\$NtUninstallKB913446$\tcpip.sys
[-] 2006-01-13 01:28 359808 583E063FDC888CA30D05C2724B0D7EF4 c:\windows\$NtUninstallKB917953$\tcpip.sys
[-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB941644$\tcpip.sys
[-] 2007-10-30 16:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LDM"="\Program\BackWeb-8876480.exe" [BU]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRISMSVR.EXE"="c:\windows\system32\PRISMSVR.EXE" [2004-04-13 290905]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-14 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-14 86016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-06 148888]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
"nwiz"="nwiz.exe" - c:\windows\SYSTEM32\nwiz.exe [2007-02-14 1622016]

c:\documents and settings\David Wilson\Start Menu\Programs\Startup\
TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2003-12-6 204800]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL 10.lnk]
backup=c:\windows\pss\CorelCENTRAL 10.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^FastCheck Monitoring Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\FastCheck Monitoring Utility.lnk
backup=c:\windows\pss\FastCheck Monitoring Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
backup=c:\windows\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Dialog Box Assistant.lnk]
path=c:\documents and settings\David Wilson\Start Menu\Programs\Startup\Dialog Box Assistant.lnk
backup=c:\windows\pss\Dialog Box Assistant.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Webshots.lnk]
backup=c:\windows\pss\Webshots.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"LDM"=\Program\BackWeb-8876480.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"C2K"=c:\windows\cyb2k.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"EnsoniqMixer"=starter.exe
"AtiPTA"=Atiptaxx.exe
"AtiCwd32"=Aticwd32.exe
"AtiQiPcl"=AtiQiPcl.exe
"POINTER"=point32.exe
"LoadQM"=loadqm.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"QuickTime Task"=e:\program files\QuickTime\qttask.exe
"MMTray"=d:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\Doppler 10 Pinpoint Alert\\TrueWeather.exe"=
"c:\\WINDOWS\\System32\\mmc.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe"=
"f:\\Program Files\\Opera\\Opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\patchget.dat"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRegistrationService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVLibraryService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVNetworkService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRecordingEngine.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVGuideDataLoader.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVSettingsService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVTaskManagerService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVD3DShell.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\SetupWizard.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVWebServiceProxy.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 amdagp10;AMD IG AGP Bus Filter;c:\windows\SYSTEM32\DRIVERS\amdagp10.sys [3/25/2003 11:19 PM 22994]
R0 fasttrak;fasttrak;c:\windows\SYSTEM32\DRIVERS\Fasttrak.sys [1/14/2005 11:33 PM 70656]
R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [5/6/2009 12:10 AM 114768]
R1 GhPciScan;GhostPciScanner;c:\program files\Symantec\Norton Ghost 2003\GhPciScan.sys [12/17/2003 3:41 PM 5632]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [5/6/2009 12:10 AM 20560]
R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\NovaStor\NovaStor NovaBACKUP\NsService.exe [6/17/2008 4:56 PM 207936]
R2 Real time Backup Loader;Real time Backup Loader;c:\program files\NovaStor\NovaStor NovaBACKUP\DR\FsLoader.exe [10/11/2008 1:52 PM 93248]
R3 4mmdat;4mmdat;c:\windows\SYSTEM32\DRIVERS\4mmdat.sys [8/17/2001 1:52 PM 12288]
S2 Backup Scheduler;Backup Scheduler;c:\program files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe [10/11/2008 1:52 PM 98304]
S3 ati2mpaa;ati2mpaa;c:\windows\SYSTEM32\DRIVERS\ati2mpaa.sys [3/23/2002 9:50 AM 281856]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\SYSTEM32\DRIVERS\atirtcap.sys [3/23/2002 9:51 AM 49920]
S3 DDCCI;DDC/CI monitor;c:\windows\SYSTEM32\DRIVERS\Moni2c.sys [3/30/2003 12:19 PM 6494]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [10/4/2008 3:20 PM 33752]
S3 zremote;zremote;c:\windows\SYSTEM32\DRIVERS\zremote.sys [5/22/2005 1:27 PM 10368]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-05-08 c:\windows\Tasks\Uninstall Expiration Reminder.job
- c:\windows\System32\OOBE\oobebaln.exe [2003-01-09 00:12]

2009-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 16:34]
.
- - - - ORPHANS REMOVED - - - -

ShellIconOverlayIdentifiers-{7D688A77-C613-11D0-999B-00C04FD655E1} - (no file)
ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - e:\program files\EUDORA\EUSHLEXT.DLL
Notify-avgrsstarter - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/
IE: Download with GetRight
IE: E&xport to Microsoft Excel
IE: Open with GetRight Browser
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\SYSTEM\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
FF - ProfilePath - c:\documents and settings\David Wilson\Application Data\Mozilla\Firefox\Profiles\5nzx41m4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-14 23:12
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\$$$\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\$$$\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E8066BAB-BCF1-46CA-D8AA-605D8DE00F6D}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1268)
c:\windows\system32\nview.dll
c:\windows\system32\nvwddi.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
c:\program files\Promise\FastTrak\FtrakSvc.exe
c:\program files\Symantec\Norton Ghost 2003\GhostStartService.exe
c:\progra~1\Iomega\System32\AppServices.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\Iomega\AutoDisk\ADService.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\rundll32.exe
c:\program files\2Wire 802.11g Wireless\PRISMCFG.exe
.
**************************************************************************
.
Completion time: 2009-05-15 23:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-15 03:15
ComboFix2.txt 2009-04-22 23:01

Pre-Run: 32,170,213,376 bytes free
Post-Run: 32,158,941,184 bytes free

Current=1 Default=1 Failed=3 LastKnownGood=4 Sets=1,2,3,4
337 --- E O F --- 2009-03-15 07:03
 
Dds.txt

DDS (Ver_09-03-16.01) - FAT32x86
Run by David Wilson at 23:18:43.62 on Thu 05/14/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1095 [GMT -4:00]

AV: avast! antivirus 4.8.1335 [VPS 090514-0] *On-access scanning disabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\David Wilson\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://my.yahoo.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - e:\program files\getright\xx2gr.dll
BHO: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - __BHODemonDisabled
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} -
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: Plaxo: {81ca3009-6200-4a6d-93c6-f1e9a6821c7f} -
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {06E58E5E-F8CB-4049-991E-A41C03BD419E} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [LDM] \Program\BackWeb-8876480.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [PRISMSVR.EXE] "c:\windows\system32\PRISMSVR.EXE" /APPLY
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [ezShieldProtector for Px] c:\windows\system32\ezSP_Px.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\trayday.lnk - c:\program files\trayday\TrayDay.exe
StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - e:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\2wirew~1.lnk - c:\program files\2wire 802.11g wireless\PRISMCFG.exe
uPolicies-explorer: NoFavoritesMenu = 1 (0x1)
dPolicies-explorer: NoFavoritesMenu = 1 (0x1)
IE: Download with GetRight
IE: E&xport to Microsoft Excel
IE: Open with GetRight Browser
IE: {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - c:\program files\hello\PicasaCapture.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\system\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\system\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: Yahoo! Checkers - hxxp://download.games.yahoo.com/games/clients/y/kt0_x.cab
DPF: Yahoo! Chess - hxxp://download.yahoo.com/games/clients/y/cr1_x.cab
DPF: Yahoo! Hearts - hxxp://download.yahoo.com/games/clients/y/hr1_x.cab
DPF: Yahoo! Pool 2 - hxxp://download.yahoo.com/games/clients/y/por9_x.cab
DPF: {00000075-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxmsdec.CAB
DPF: {00000160-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {31564D57-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmvax.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - hxxp://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - hxxp://entimg.msn.com/client/msnediag3518.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} - hxxp://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab
DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxp://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778
DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - hxxp://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab
DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} - hxxp://www.live365.com/players/play365.cab
DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} - hxxp://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - hxxp://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - hxxp://entimg.msn.com/client/msnmusax3518.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\davidw~1\applic~1\mozilla\firefox\profiles\5nzx41m4.default\
FF - prefs.js: browser.search.selectedEngine - Google

============= SERVICES / DRIVERS ===============

R0 amdagp10;AMD IG AGP Bus Filter;c:\windows\system32\drivers\amdagp10.sys [2003-3-25 22994]
R0 fasttrak;fasttrak;c:\windows\system32\drivers\Fasttrak.sys [2005-1-14 70656]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-6 114768]
R1 Cinemsup;Cinemsup;c:\windows\system32\drivers\cinemsup.sys [2002-7-19 6656]
R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2003-12-17 5632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-6 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-5-6 138680]
R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\novastor\novastor novabackup\NsService.exe [2008-6-17 207936]
R2 Real time Backup Loader;Real time Backup Loader;c:\program files\novastor\novastor novabackup\dr\FsLoader.exe [2008-10-11 93248]
R3 4mmdat;4mmdat;c:\windows\system32\drivers\4mmdat.sys [2001-8-17 12288]
RUnknown DCDisk;DCDisk; [x]
RUnknown dcsnap;dcsnap; [x]
RUnknown Iprip;Iprip; [x]
S2 Backup Scheduler;Backup Scheduler;c:\program files\novastor\novastor novabackup\dr\cbp\DCSchdlerSRVC.exe [2008-10-11 98304]
S3 ati2mpaa;ati2mpaa;c:\windows\system32\drivers\ati2mpaa.sys [2002-3-23 281856]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\system32\drivers\atirtcap.sys [2002-3-23 49920]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-5-6 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-5-6 352920]
S3 DDCCI;DDC/CI monitor;c:\windows\system32\drivers\Moni2c.sys [2003-3-30 6494]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-10-4 33752]
S3 hcwPVRP2;Hauppauge WinTV PVR PCI II (Encoder);c:\windows\system32\drivers\hcwPVRP2.sys [2005-5-22 814464]
S3 zremote;zremote;c:\windows\system32\drivers\zremote.sys [2005-5-22 10368]
SUnknown idsvcSPTISRV;idsvcSPTISRV; [x]
UnknownUnknown efbDisk;efbDisk; [x]

=============== Created Last 30 ================

2009-05-13 07:50 <DIR> --dsh--- C:\FOUND.043
2009-05-08 11:01 0 a--s---- c:\windows\system32\148114617.dat
2009-05-07 22:11 <DIR> --d----- c:\program files\Microsoft Money Plus
2009-05-06 00:03 147,100 a---h--- c:\windows\system32\mlfcache.dat
2009-05-05 22:38 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-05 22:38 73,728 a------- c:\windows\system32\javacpl.cpl
2009-05-05 22:27 0 a------- c:\windows\system32\REN33.tmp
2009-05-05 22:27 0 a------- c:\windows\system32\REN32.tmp
2009-05-05 22:11 2,709 a------- c:\windows\system32\gibbebx.dat
2009-05-05 22:10 1,024 ----h--- C:\diskfile1
2009-05-05 22:10 15,360 ----h--- C:\logicinf.bin
2009-05-05 21:53 2,709 a------- c:\windows\system32\dllgidoor.dat
2009-04-22 18:53 <DIR> a-dshr-- C:\cmdcons
2009-04-22 18:52 161,792 a------- c:\windows\SWREG.exe
2009-04-22 18:52 98,816 a------- c:\windows\sed.exe
2009-04-19 18:34 360,021 a------- C:\something.scr
2009-04-18 00:21 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-04-18 00:21 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-04-17 21:04 <DIR> --d----- c:\docume~1\davidw~1\applic~1\Malwarebytes
2009-04-17 21:04 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-17 21:04 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-17 21:04 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-04-17 21:04 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-17 19:53 66 a------- c:\windows\wininit.ini
2009-04-17 08:22 <DIR> --d----- C:\!KillBox
2009-04-16 21:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}

==================== Find3M ====================

2009-04-22 19:04 5,880 a------- c:\windows\system32\wfileu.drv
2008-12-16 19:23 726,008 a------- c:\documents and settings\david wilson\gotomypc_438.exe
2008-11-06 12:33 726,008 a------- c:\documents and settings\david wilson\gotomypc_437.exe
2001-11-06 00:23 266 ---sh--- c:\program files\desktop.ini
2001-11-06 00:23 11,079 ----h--- c:\program files\folder.htt
2001-01-19 12:04 21,841 a------- c:\program files\common files\tppupd2k.dll
2001-01-19 11:04 21,329 -------- c:\program files\common files\tppupd98.dll
2008-10-04 15:44 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100420081005\index.dat
2001-11-13 10:18 8 ---sh--- c:\windows\all users\drm\pdrm.dat

============= FINISH: 23:19:14.06 ===============
 
Symptom Update

IEXPLORE.EXE still starts with OS. End Process turns it off and it stays off - but process iexplore.ex1 turns on and off continuously.

Double click My Computer/double click a HD and the IEXPLORE.EXE process starts multiple times again. And if force quite, will start again.

Script errors continue in IE... for example... if I choose Tools/Organize Favorites - I get an Internet Explorer Script Error... An error has occurred in the script on this page... but no detail in any of the Line/Char/Error/Code/URL fields. Choosing Yes or No has little effect as the box stays in place - clicking on the X in the RH corner about 30 times finally closes the dialog box.
 
One more thing

Avast just found a Trojan Horse - Win32:Delf-MBA -- but it's struggling to remove it.

I also noticed after e-mailing last night that my computer is running Internet Explorer from c:/Program Files/Internet Explorer and NOT from c:/Windows/IE7. It's the first directory that has a file called iexplore.ex1. My task manager continues to have an ever expanding number of instances of iexplore.ex1 which start up and then shut down and then start up and then shut down.
 
Hi,

Avast just found a Trojan Horse - Win32:Delf-MBA -- but it's struggling to remove it.
Where does Avast see the infection in?


Let's uninstall IE7 for now.

After that, please download OTListIt2
Save it to the Desktop
  • Close all windows and double-click on the OTListIt2.exe file
  • OK any warning about running OTListIt.
  • Place a check in the Scan All Users checkbox
  • Click the Run Scan button
  • When the scan is complete, two text files are produced on the Desktop: OTListIt.txt , and Extras.txt
Please post the OTListIt.txt and Extras.txt in your reply.
 
Back
Top