We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Yet ANOTHER problem.
Options
Comments
-
My bad, I forgot it wont remove folders
Just try removing it manually
If it wont go then manually remove everything (If anything) inside of it:idea:0 -
Combo Fix file.
I doubt if it matters but I couldn't find the file the first time (Saved it to desktop which disappeared when I rebooted) so I ran Combo a second time........Then I FOUND where it had placed the first file. Duh!!
ComboFix 10-09-15.02 - Terry 16/09/2010 14:11:27.7.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1584 [GMT 1:00]
Running from: g:\downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Terry\Desktop\CFScript.txt'.txt
AV: a-squared Anti-Malware *On-access scanning enabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
FILE ::
"c:\windows\IFinst27.exe"
"c:\windows\system32\BootMan.exe"
"c:\windows\system32\CF10921.exe"
.
((((((((((((((((((((((((( Files Created from 2010-08-16 to 2010-09-16 )))))))))))))))))))))))))))))))
.
2010-09-16 13:07 . 2010-09-16 13:07
d
w- c:\windows\LastGood
2010-09-15 10:53 . 2010-09-15 10:53
d
w- c:\documents and settings\Terry\Local Settings\Application Data\Stardock_Corporation
2010-09-14 17:26 . 2010-09-14 17:26
d
w- c:\documents and settings\Terry\Application Data\Stardock
2010-09-14 17:26 . 2010-09-14 17:26
dc-h--w- c:\documents and settings\All Users\Application Data\{56FC2B0D-3D08-45E7-B370-9A9DACA17E2F}
2010-09-14 17:26 . 2009-02-10 16:35 2681648 -c--a-w- c:\documents and settings\All Users\Application Data\{56FC2B0D-3D08-45E7-B370-9A9DACA17E2F}\SoundPackager_setup.exe
2010-09-13 16:33 . 2010-09-13 16:33 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-09-13 16:06 . 2010-09-13 16:12
d
w- C:\divx
2010-09-13 16:02 . 2010-09-13 16:27
d
w- c:\documents and settings\Terry\Application Data\Clip Extractor
2010-09-13 12:53 . 2010-09-13 12:53
d
w- c:\documents and settings\Terry\Application Data\Toolbar4
2010-09-13 12:53 . 2010-09-13 12:53
d
w- c:\program files\Microsoft.NET
2010-09-12 19:06 . 2010-09-12 19:06
d
w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-09-12 17:56 . 2010-09-12 17:56
d
w- c:\windows\system32\wbem\Repository
2010-09-11 21:31 . 2010-09-12 16:26
d
w- C:\RECYCLER(2)
2010-09-08 17:23 . 2010-09-08 17:23
d
w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-09-08 17:18 . 2010-09-08 17:18
d
w- c:\documents and settings\Terry\Local Settings\Application Data\Temp
2010-09-08 17:18 . 2010-09-08 17:18
d
w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-09-08 16:08 . 2010-07-11 05:54 57344 ----a-w- c:\windows\system32\CleanMem.exe
2010-09-08 16:08 . 2008-09-19 16:37 121856 ----a-w- c:\windows\system32\schtasks.exe
2010-09-08 16:08 . 2010-09-08 16:08
d
w- c:\windows\CleanMem
2010-09-08 11:36 . 2010-09-08 11:36
d
w- c:\program files\FamilySearch
2010-09-06 16:49 . 2010-09-06 16:49
d
w- c:\documents and settings\Terry\Local Settings\Application Data\Amazon
2010-09-06 16:49 . 2010-09-06 16:49
d
w- c:\program files\Amazon
2010-09-05 18:00 . 2010-05-21 13:14 221568
w- c:\windows\system32\MpSigStub.exe
2010-09-05 17:59 . 2010-09-05 17:59
d
w- c:\program files\Windows Defender
2010-09-01 18:51 . 2010-09-01 18:51
d
w- c:\documents and settings\All Users\Application Data\UAB
2010-09-01 18:51 . 2010-09-01 19:14
d
w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters Inc
2010-09-01 18:51 . 2010-09-01 18:51
d
w- c:\documents and settings\Terry\Local Settings\Application Data\PC_Drivers_Headquarters
2010-09-01 18:49 . 2010-09-01 18:49
d
w- c:\documents and settings\Terry\Application Data\GetRightToGo
2010-09-01 17:48 . 2010-09-01 17:49
d
w- c:\program files\jv16 PowerTools
2010-09-01 09:22 . 2010-09-15 17:04
d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-30 11:52 . 2010-08-30 11:52
d
w- c:\documents and settings\Terry\Application Data\VSRevoGroup
2010-08-28 13:09 . 2010-08-28 13:09
d
w- c:\program files\Coupon Printer
2010-08-28 13:01 . 2010-08-28 13:01
d
w- c:\program files\ACD Systems
2010-08-28 13:00 . 2010-08-28 13:00
d
w- c:\program files\Hide Wizard
2010-08-28 11:17 . 2004-08-04 10:00 753236 -c--a-w- c:\windows\system32\dllcache\rvseres.dll
2010-08-28 11:16 . 2010-06-18 13:36 3558912 -c--a-w- c:\windows\system32\dllcache\moviemk.exe
2010-08-28 11:16 . 2008-04-14 00:12 7680 -c--a-w- c:\windows\system32\dllcache\wmm2ext.dll
2010-08-28 11:16 . 2008-04-14 00:12 5632 -c--a-w- c:\windows\system32\dllcache\wmm2res2.dll
2010-08-28 11:16 . 2008-04-14 00:12 502272 -c--a-w- c:\windows\system32\dllcache\wmm2fxa.dll
2010-08-28 11:16 . 2008-04-14 00:12 4256768 -c--a-w- c:\windows\system32\dllcache\wmm2res.dll
2010-08-28 11:16 . 2008-04-14 00:12 4096 -c--a-w- c:\windows\system32\dllcache\wmm2eres.dll
2010-08-28 11:16 . 2008-04-14 00:12 402432 -c--a-w- c:\windows\system32\dllcache\wmm2filt.dll
2010-08-28 11:16 . 2008-04-14 00:12 325632 -c--a-w- c:\windows\system32\dllcache\wmm2fxb.dll
2010-08-28 11:16 . 2008-04-14 00:12 167936 -c--a-w- c:\windows\system32\dllcache\wmm2ae.dll
2010-08-28 11:07 . 2008-04-14 00:12 102400 -c--a-w- c:\windows\system32\dllcache\msjro.dll
2010-08-28 11:05 . 2010-08-28 11:05
d
w- c:\program files\Stardock
2010-08-28 11:05 . 2010-08-28 11:05
d
w- c:\program files\PC Tools Firewall Plus
2010-08-28 11:04 . 2010-08-28 11:04
d
w- c:\program files\Everything
2010-08-28 11:04 . 2010-08-28 11:04
d
w- c:\program files\AlienGUIse
2010-08-27 14:02 . 2010-08-27 14:02
d
w- c:\documents and settings\Terry\Local Settings\Application Data\https://www.dvbportal.de
2010-08-26 13:21 . 2010-08-26 13:21
d
w- c:\program files\Ashampoo
2010-08-23 13:10 . 2010-08-23 13:10 2944904 ----a-w- c:\documents and settings\Terry\Application Data\Mozilla\Firefox\Profiles\hcc9h5r6.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe
2010-08-23 10:17 . 2010-08-30 09:44
d
w- C:\ks360
2010-08-23 08:20 . 2010-08-20 07:03 100280 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGMLauncher.exe
2010-08-22 22:34 . 2010-08-22 22:34
d
w- c:\program files\DIFX
2010-08-22 22:34 . 2010-08-22 22:34
d
w- c:\program files\infineon
2010-08-22 22:34 . 2009-05-12 14:53 16896 ----a-w- c:\windows\system32\drivers\FlashUsb.sys
2010-08-22 22:22 . 2010-08-22 22:22
d
w- c:\program files\LG Electronics
2010-08-22 17:36 . 2010-08-23 05:41 329656 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
2010-08-22 17:36 . 2010-08-23 04:21 1071032 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGUserCSTool.exe
2010-08-22 17:36 . 2010-08-20 07:03 100280 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\LGMLauncher.exe
2010-08-22 17:36 . 2010-08-20 06:14 524288 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGMUpgradeDL.dll
2010-08-22 17:36 . 2010-08-19 08:49 106496 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGMobileDL.dll
2010-08-22 17:36 . 2010-05-20 05:49 206784 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CAppUninstall.exe
2010-08-22 17:36 . 2010-03-16 07:31 24576 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGMobileDLRapi.dll
2010-08-22 17:36 . 2006-05-04 07:33 53248 ----a-w- c:\windows\system32\CommonDL.dll
2010-08-22 17:35 . 2010-08-23 02:39
d
w- c:\documents and settings\All Users\Application Data\LGMOBILEAX
2010-08-17 22:51 . 2010-08-17 22:51 80090 ----a-w- c:\documents and settings\Terry\Application Data\SMBIOSSP.exe
2010-08-17 22:18 . 2010-08-29 12:07
d
w- c:\documents and settings\Terry\Local Settings\Application Data\Deployment
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-15 12:55 . 2008-08-04 17:04
d
w- c:\documents and settings\Terry\Application Data\Canon
2010-09-15 10:42 . 2009-10-28 09:09
d
w- c:\documents and settings\Terry\Application Data\GoodSync
2010-09-13 16:33 . 2010-07-06 18:40
d
w- c:\documents and settings\All Users\Application Data\DivX
2010-09-13 12:52 . 2010-06-16 21:05
d
w- c:\documents and settings\All Users\Application Data\OnlineArmor
2010-09-13 11:50 . 2008-09-12 18:28
d
w- c:\program files\Panda Security
2010-09-12 16:28 . 2009-09-20 08:30
d
w- c:\program files\Microsoft Silverlight
2010-09-12 16:26 . 2010-08-02 16:49
d
w- c:\program files\Ask.com
2010-09-12 12:24 . 2008-08-05 15:59
d
w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-09-08 17:17 . 2008-08-05 12:09
d
w- c:\program files\Google
2010-09-07 15:12 . 2010-07-02 16:57 38848 ----a-w- c:\windows\avastSS.scr
2010-09-07 15:11 . 2008-08-04 22:01 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-01 19:14 . 2009-02-04 16:24
d
w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2010-09-01 09:32 . 2008-08-05 16:09
d
w- c:\documents and settings\Terry\Application Data\Media Player Classic
2010-08-30 09:46 . 2009-03-20 09:15
d
w- c:\documents and settings\Terry\Application Data\NetStat Agent
2010-08-30 09:44 . 2010-04-15 21:42
d
w- c:\program files\Palm
2010-08-30 09:44 . 2009-10-27 10:44
d
w- c:\program files\Canon
2010-08-30 09:44 . 2009-02-06 12:48
d
w- c:\program files\Microsoft Works
2010-08-30 09:44 . 2008-08-05 09:47
d
w- c:\documents and settings\All Users\Application Data\comodo
2010-08-29 20:00 . 2010-08-15 17:48
d
w- c:\documents and settings\Terry\Application Data\Spotify
2010-08-29 15:32 . 2008-12-20 10:09
d
w- c:\documents and settings\Terry\Application Data\Amazon
2010-08-28 13:04 . 2009-10-28 09:09
d
w- c:\program files\Siber Systems
2010-08-28 11:05 . 2008-08-04 15:15
d--h--w- c:\program files\InstallShield Installation Information
2010-08-28 09:45 . 2008-12-14 20:17
d
w- c:\documents and settings\Terry\Application Data\Azureus
2010-08-27 14:51 . 2008-10-01 10:07
d
w- c:\program files\MPlayer for Windows
2010-08-27 09:19 . 2008-12-14 20:15
d
w- c:\program files\Vuze
2010-08-26 13:24 . 2010-06-08 08:41
d
w- c:\documents and settings\Terry\Application Data\Ashampoo
2010-08-17 13:17 . 2010-08-17 13:17 58880 ----a-w- c:\windows\system32\SET14.tmp
2010-08-15 17:48 . 2010-08-15 17:48 655360 ----a-w- c:\documents and settings\Terry\Application Data\Spotify\Gracenote\gnsdk_sdkmanager.dll
2010-08-15 17:48 . 2010-08-15 17:48 282624 ----a-w- c:\documents and settings\Terry\Application Data\Spotify\Gracenote\gnsdk_musicid_file.dll
2010-08-15 17:48 . 2010-08-15 17:48 208896 ----a-w- c:\documents and settings\Terry\Application Data\Spotify\Gracenote\gnsdk_dsp.dll
2010-08-05 10:07 . 2009-05-29 14:34
d
w- c:\program files\StarBurn
2010-08-04 09:27 . 2008-08-04 15:09 88608 ----a-w- c:\documents and settings\Terry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-22 19:41 . 2010-07-24 17:18 153600 ----a-w- c:\windows\system32\AI_ContextMenu.dll
2010-07-22 15:49 . 2010-07-22 15:49 590848 ----a-w- c:\windows\system32\SETA.tmp
2010-07-22 05:57 . 2010-07-22 05:57 5120
w- c:\windows\system32\SETB.tmp
2010-07-11 23:21 . 2010-07-06 23:05 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-11 22:52 . 2010-07-11 22:52 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-11 22:52 . 2010-07-11 22:52 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-11 22:40 . 2010-07-11 22:40 84054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-07-11 22:40 . 2010-07-11 22:40 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-11 22:16 . 2010-07-06 20:37 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-11 22:16 . 2010-07-06 20:37 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-06 20:37 . 2010-07-06 20:37 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-07-06 20:37 . 2010-07-06 20:37 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-07-06 20:26 . 2010-07-06 20:26 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-07-06 20:26 . 2010-07-06 20:26 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-07-06 20:05 . 2010-07-06 20:05 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-07-06 20:05 . 2010-07-06 20:05 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-07-06 20:05 . 2010-07-06 20:05 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-07-06 19:03 . 2010-07-06 19:03 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-07-06 19:03 . 2010-07-06 19:03 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-07-06 19:03 . 2010-07-06 19:03 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-07-06 19:03 . 2010-07-06 19:03 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-07-06 19:03 . 2010-07-06 19:03 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-07-06 19:03 . 2010-07-06 19:03 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-07-06 19:03 . 2010-07-06 19:03 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-06-30 12:31 . 2004-08-04 10:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-28 20:37 . 2008-08-04 22:01 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2008-08-04 22:01 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2008-08-04 22:01 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2008-08-04 22:01 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2008-08-04 22:01 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2008-08-04 22:01 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2008-08-04 22:01 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-24 12:22 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2004-08-04 10:00 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 21:00 . 2010-06-21 21:00 63488 ----a-w- c:\documents and settings\Terry\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-06-21 21:00 . 2010-01-10 00:03 117760 ----a-w- c:\documents and settings\Terry\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-06-21 15:27 . 2004-08-04 10:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 17:45 . 2010-06-18 17:45 293376 ----a-w- c:\windows\system32\SET10.tmp
2006-05-03 09:06 . 2008-11-20 09:47 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2008-11-20 09:47 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2008-11-20 09:47 216064 --sh--r- c:\windows\system32\nbDX.dll
."Unhappiness is not knowing what we want, and killing ourselves to get it."Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))Women and cats will do as they please, and men and dogs should relax and get used to the idea.0 -
((((((((((((((((((((((((((((( [EMAIL="SnapShot@2010-09-16_12.26.32"]SnapShot@2010-09-16_12.26.32[/EMAIL] )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 10:00 . 2010-08-17 13:17 58880 c:\windows\system32\dllcache\spoolsv.exe
- 2006-10-18 21:47 . 2006-10-18 21:47 317440 c:\windows\system32\MP4SDECD.dll
+ 2006-10-18 21:47 . 2010-03-30 11:24 317440 c:\windows\system32\mp4sdecd.dll
+ 2004-08-04 10:00 . 2010-06-18 17:45 293376 c:\windows\system32\dllcache\winsrv.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2004-08-04 10:00 . 2010-04-16 15:36 406016 c:\windows\system32\dllcache\usp10.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 406016 c:\windows\system32\dllcache\usp10.dll
+ 2004-08-04 10:00 . 2010-07-22 15:49 590848 c:\windows\system32\dllcache\rpcrt4.dll
+ 2010-03-30 11:24 . 2010-03-30 11:24 317440 c:\windows\system32\dllcache\mp4sdecd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-06-28 2837864]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2010-04-20 6678008]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-04 186904]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-20 282624]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
c:\documents and settings\Terry\Start Menu\Programs\Startup\
Alienware Dock.lnk - f:\program files\AlienGUIse\AlienwareDock\ObjectDock.exe [2008-9-17 2074360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= firefox.exe
"2"= opera.exe
"3"= chrome.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{1214FBE7-4464-4A7E-9958-B5851A7A30A3}"= "d:\program files\RecentX\RecentX\RXShell.dll" [2008-06-12 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "g:\superantispyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2010-04-20 925688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2010-05-02 11:53 548352 ----a-w- g:\superantispyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Calendar Magic.lnk]
backup=c:\windows\pss\Calendar Magic.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Terry^Start Menu^Programs^Startup^.lnk]
backup=c:\windows\pss\.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Terry^Start Menu^Programs^Startup^RecentX.lnk]
backup=c:\windows\pss\RecentX.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Terry^Start Menu^Programs^Startup^Secunia PSI.lnk]
backup=c:\windows\pss\Secunia PSI.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
2010-08-10 14:10 2349776 ----a-w- g:\advanced systemcare 3\AWC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioHQ]
2000-05-11 00:00 205312 ----a-w- c:\program files\Creative\SBLive\AudioHQ\ahqtb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avastUI.exe]
2010-06-28 20:57 2837864
w- c:\program files\Alwil Software\Avast5\AvastUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\B2C_AGENT]
2010-08-23 05:41 329656 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-16 19:04 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\captrue.exe]
2008-09-05 16:55 673280
w- j:\captrue\captrue.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2006-07-21 17:48 98304 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntegryDESK]
2005-03-22 12:45 618496 ----a-w- i:\integrydesk\IntegryDESK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 15:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pb_scheduler_agent]
2007-04-19 10:37 44544 ----a-w- g:\premium booster\scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
2010-09-04 21:58 160328 ----a-w- d:\roboform\robotaskbaricon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 --sha-r- i:\spybot - search & destroy\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-06-23 21:06 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-08-27 11:11 2424560 ----a-w- g:\superantispyware\SUPERANTISPYWARE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-08-22 11:21 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ThreatFire]
2008-11-17 13:04 263456 ----a-w- g:\threatfire\TFTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-04-15 22:45 151597 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ThreatFire"=2 (0x2)
"ioloSystemService"=2 (0x2)
"ioloFileInfoList"=2 (0x2)
"NBService"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"gusvc"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)
"cmdAgent"=2 (0x2)
"TeamViewer4"=2 (0x2)
"idsvc"=3 (0x3)
"NetBurnerService"=3 (0x3)
"IAANTMON"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
"SvcOnlineArmor"=2 (0x2)
"RapportMgmtService"=2 (0x2)
"OAcat"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"ACDaemon"=2 (0x2)
"a2free"=2 (0x2)
"a2AntiMalware"=3 (0x3)
"NanoServiceMain"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Spotify\\spotify.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [29/04/2009 22:56 40560]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [25/12/2008 12:41 51488]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [25/12/2008 12:41 39200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [04/08/2008 23:01 165456]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [05/08/2008 10:47 133064]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [05/08/2008 10:47 25160]
R1 NetBurn;Paragon NetBurning Driver;c:\windows\system32\drivers\NetBurn.sys [13/12/2008 14:48 84488]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [16/06/2010 22:04 228216]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [16/06/2010 22:04 24440]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [16/06/2010 22:04 29560]
R1 SASDIFSV;SASDIFSV;g:\superantispyware\SASDIFSV.SYS [28/07/2009 10:53 12872]
R1 SASKUTIL;SASKUTIL;g:\superantispyware\SASKUTIL.SYS [28/07/2009 10:53 67656]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [05/08/2008 09:42 95592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [04/08/2008 23:01 17744]
R2 dvdmmg;dvdmmg;c:\windows\system32\drivers\dvdmmg.sys [06/09/2007 11:15 5504]
R2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [16/06/2010 22:04 1284600]
R2 VDDriver;Virtual Disk Driver;d:\virtual disk\VDDriver.sys [22/05/2009 13:39 40952]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
R3 ArcCD;ArcCD Filter Driver Service;c:\windows\system32\drivers\ArcCD.sys [15/05/2010 18:24 36224]
R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [14/05/2009 12:05 16640]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [08/06/2010 19:01 0]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [08/06/2010 19:01 0]
S2 SCRCAMHRDRV;ScreenCamera HR;c:\windows\system32\drivers\SCRCAMHRDRV.sys [09/12/2009 10:48 234304]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [16/06/2010 22:04 3364856]
S3 BCASPROT;Advanced System Protector;c:\program files\Systweak\Advanced System Protector\sasprot32.sys [04/05/2009 17:42 6656]
S3 FlashUSB;FlashUSB;c:\windows\system32\drivers\FlashUsb.sys [22/08/2010 23:34 16896]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [24/03/2009 12:03 7808]
S3 SASENUM;SASENUM;g:\superantispyware\SASENUM.SYS [28/07/2009 10:53 12872]
S3 se_filter;System Explorer Filter Driver;c:\windows\system32\drivers\SE_Filter.sys [02/01/2009 12:18 9216]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [25/12/2008 12:41 33056]
S4 ArcUdfs;ArcUdfs FileSystem Driver Service;c:\windows\system32\drivers\ArcUdfs.sys [15/05/2010 18:24 134912]
S4 NetBurnerService;Net Burner iSCSI Service;g:\drive back-up\Net Burner Service\NetBurnerService.exe [13/12/2008 14:48 222984]
S4 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [15/03/2010 14:47 779496]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [05/08/2008 09:42 721904]
S4 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [27/05/2009 13:38 185640]
S4 ThreatFire;ThreatFire;g:\threatfire\TFService.exe service --> g:\threatfire\TFService.exe service [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - ArcRec
.
Contents of the 'Scheduled Tasks' folder
2010-09-16 c:\windows\Tasks\Clean System Memory.job
- c:\windows\system32\CleanMem.exe [2010-09-08 05:54]
2010-09-16 c:\windows\Tasks\GlaryInitialize.job
- g:\glary utilities\initialize.exe [2009-01-12 10:21]
2010-09-16 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2010-09-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-08-28 14:23]
2010-09-15 c:\windows\Tasks\User_Feed_Synchronization-{8ED07C76-0A78-4661-870E-CF91F4A2F154}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
2009-03-27 c:\windows\Tasks\Wise Registry Cleaner 4.job
- g:\wise registry cleaner\WiseRegistryCleaner.exe [2009-03-27 21:27]
.
.
Supplementary Scan
.
uStart Page = hxxp://uk.mc366.mail.yahoo.com/mc/welcome?.rand=1cja0cethg47r
mStart Page = hxxp://www.bigseekpro.com/clipextractor/{A9E3981F-6A11-4EF1-A702-3819AB03CE4F}
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
IE: Customize Menu - [URL="file:///d:/roboform/RoboFormComCustomizeIEMenu.html"]file://d:\roboform\RoboFormComCustomizeIEMenu.html[/URL]
IE: Fill Forms - [URL="file:///d:/roboform/RoboFormComFillForms.html"]file://d:\roboform\RoboFormComFillForms.html[/URL]
IE: Identities Editor - [URL="file:///d:/roboform/RoboFormComEditIdent.html"]file://d:\roboform\RoboFormComEditIdent.html[/URL]
IE: Locate Spot on Map by GPS - f:\iexif 2.3\IExifMap.htm
IE: Password Generator - [URL="file:///d:/roboform/RoboFormComPasswordGenerator.html"]file://d:\roboform\RoboFormComPasswordGenerator.html[/URL]
IE: RoboForm Toolbar - [URL="file:///d:/roboform/RoboFormComShowToolbar.html"]file://d:\roboform\RoboFormComShowToolbar.html[/URL]
IE: Save Forms - [URL="file:///d:/roboform/RoboFormComSavePass.html"]file://d:\roboform\RoboFormComSavePass.html[/URL]
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: View Exif/GPS/IPTC with IExif - f:\iexif 2.3\IExifCom.htm
IE: Zoom &in
IE: Zoom &out
Trusted Zone: google.com\maps
DPF: {0A43D7AC-D6C1-4622-B309-BF975F427C0E} - hxxps://internetbankingplus2.firstdirect.com/ibplus/frontdoorFD.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-16 14:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
LOCKED REGISTRY KEYS
[HKEY_USERS\S-1-5-21-746137067-606747145-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
[HKEY_USERS\S-1-5-21-746137067-606747145-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{63B97F04-9032-2D21-7BE0-EA7F7AE7EE4B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"nanhidfkkcpkpahaeliapjmohhon"=hex:6a,61,65,67,68,69,66,68,66,65,6b,6d,6d,63,
68,6f,65,68,6b,70,00,0c
"madhoahnjofkbbmejiepajomch"=hex:6a,61,65,67,68,69,66,68,66,65,6b,6d,6d,63,68,
6f,65,68,6b,70,00,56
"abbaoepgoddjdfkamchgkahkhkddfmehpc"=hex:61,62,6b,68,62,64,67,68,65,6c,67,67,
64,67,6c,6a,64,62,6a,64,63,6d,70,67,70,6a,70,6e,61,6e,6a,63,62,66,00,77
"maoppejgogbliogaieoebfhdhf"=hex:64,62,64,68,6d,66,65,66,6b,65,6e,68,6a,68,6a,
63,64,63,66,69,61,62,70,63,61,68,6c,70,6a,61,6d,68,62,65,69,6a,69,64,6c,6b,\
[HKEY_USERS\S-1-5-21-746137067-606747145-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8AA92D77-C3A3-884A-7EA8-1CD3D0BBD18D}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\EncryptionInterface*]
"l_encryption_d"="585A4A574A5F"
.
DLLs Loaded Under Running Processes
- - - - - - - > 'winlogon.exe'(520)
g:\superantispyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3044)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\mmfinfo.dll
c:\windows\system32\mkunicode.dll
c:\program files\Common Files\Ahead\Lib\NeroDigitalExt.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
Completion time: 2010-09-16 14:19:35
ComboFix-quarantined-files.txt 2010-09-16 13:19
ComboFix2.txt 2010-09-16 12:28
ComboFix3.txt 2010-09-15 15:25
ComboFix4.txt 2010-09-11 20:49
ComboFix5.txt 2010-09-16 13:09
Pre-Run: 26,425,864,192 bytes free
Post-Run: 26,402,508,800 bytes free
- - End Of File - - 7F13A0FDE42E5D882328384B9BFECE37
I am now following the other instructions and will return as soon as."Unhappiness is not knowing what we want, and killing ourselves to get it."Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))Women and cats will do as they please, and men and dogs should relax and get used to the idea.0 -
Phew. just ran Glary (Took forever) and I thought it worth mentioning that approx a dozen times I had to hit 'retry' TWICE each time to get it to continue. (once wouldn't do it) so does that mean it 'Skipped' that file or that it just had difficulty with the CD (Dell).
off now to D/L Dr Web. Back soon....ish"Unhappiness is not knowing what we want, and killing ourselves to get it."Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))Women and cats will do as they please, and men and dogs should relax and get used to the idea.0 -
Not sure about glary
Ive never had a problem myself. Im also confused by you mentioning a CD? You mean CD Player?
Dr web will take hours when its running afull system scan (If its really bad, or the hardrives pretty full I really do mean HOURS (like 12 or whatever)):idea:0 -
Now resorted to laptop. Yep sure right about the time taken. about another hour to go I suspect.
Sorry to confuse re cd. I meant the Dell operating system disc.
Glary stopped when looking for files on the disc, about a dozen times."Unhappiness is not knowing what we want, and killing ourselves to get it."Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))Women and cats will do as they please, and men and dogs should relax and get used to the idea.0 -
Back with main computer now.
DrWeb finished (7 hours) and nothing found."Unhappiness is not knowing what we want, and killing ourselves to get it."Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))Women and cats will do as they please, and men and dogs should relax and get used to the idea.0 -
Looks like your clean:idea:0
-
Look like it.
Thanks for your time Rik.:T:beer:
Feels a lot better now."Unhappiness is not knowing what we want, and killing ourselves to get it."Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))Women and cats will do as they please, and men and dogs should relax and get used to the idea.0 -
Sorry it took so long:idea:0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351K Banking & Borrowing
- 253.1K Reduce Debt & Boost Income
- 453.6K Spending & Discounts
- 244.1K Work, Benefits & Business
- 599K Mortgages, Homes & Bills
- 177K Life & Family
- 257.4K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards