Active X, Firefox, and HJT log

scrumptousscrumptous Florida
edited March 2009 in Spyware & Virus Removal
A roommate has been playing around by adding a password to log onto to the computer. After changing this, hotmail, myspace, or facebook wouldn't open up because of Java Script. I think roomy made some control settings changes. Myspace kept warning about page not loading correctly because of Active X. I wasn't having a problem with Firefox until today. It won't even load now. When I open Firefox, it says address not found. I've had trouble with Firefox doing this before. I would always uninstall and reinstall, and it would work fine for a couple of days. I need help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:21:23 PM, on 1/19/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ACTIV Software\ACTIVdriver\ActivDRVservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Zumie\zumie.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Zumie\zumie.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\ACTIV Software\ACTIVdriver\ACTIVcontrol.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (file missing)
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ActivDRVAutostart] C:\Program Files\ACTIV Software\ACTIVdriver\ACTIVcontrol.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O23 - Service: ACTIVdriver Control (ActivDRVcontrol) - ACTIV Software Ltd - C:\Program Files\ACTIV Software\ACTIVdriver\ActivDRVservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Zumie Search Service - Zumie.com - C:\Program Files\Zumie\zumie.exe

--
End of file - 10144 bytes

Comments

  • scrumptousscrumptous Florida
    edited February 2009
    There's been no replies to my first log. Am I doing this correctly?
  • scrumptousscrumptous Florida
    edited February 2009
    Here's the new HJT log....thanks again!



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:37:00 PM, on 2/28/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18372)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\Explorer.EXE
    c:\Program Files\Norton Internet Security\ISSVC.exe
    c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\sm56hlpr.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\InterMute\SpySubtract\SpySub.exe
    C:\HP\KBD\KBD.EXE
    c:\windows\system\hpsysdrv.exe
    C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
    O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
    O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    --
    End of file - 8019 bytes
  • TroganTrogan London, UK
    edited March 2009
    I will look at the logs later tonight.

    -Trogan
  • TroganTrogan London, UK
    edited March 2009
    Hi,

    Please do the following...

    1. Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.
    This program is for XP and Windows 2000 only!
    • Double-click ATF Cleaner.exe to open it.
    • Under Main select the following:
      • Windows Temp
      • Current User Temp
      • All Users Temp
      • Temporary Internet Files
      • Java Cache
    *The other boxes are optional*
    Then click the Empty Selected button.

    Click Exit on the Main menu to close the program.

    2. Please download Malwarebytes' Anti-Malware to your desktop.
    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to
      • Update Malwarebytes' Anti-Malware
      • and Launch Malwarebytes' Anti-Malware
    • then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. please copy and paste the log into your next reply
      • If you accidently close it, the log file is saved here and will be named like this:
      • C:\\Documents and Settings\\Username\\Application Data\\Malwarebytes\\Malwarebytes' Anti-Malware\\Logs\\mbam-log-date (time).txt

    3. I need to see another log from HijackThis.
    • Run Hijackthis.
    • Click on Open the Misc Tools section.
    • Next click on Open uninstall manager.
    • Press the Save list button.
    • Save the file to your desktop, with the default name of uninstall_list
    • Copy & Paste the entire contents of that file in your in your next post.

    4. Please post the following...

    Uninstall list
    Malwarebytes log
    New HijackThis log
  • scrumptousscrumptous Florida
    edited March 2009
    Trogan wrote:
    Hi,

    Please do the following...

    1. Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.
    This program is for XP and Windows 2000 only!
    • Double-click ATF Cleaner.exe to open it.
    • Under Main select the following:
      • Windows Temp
      • Current User Temp
      • All Users Temp
      • Temporary Internet Files
      • Java Cache
    *The other boxes are optional*
    Then click the Empty Selected button.

    Click Exit on the Main menu to close the program.

    2. Please download Malwarebytes' Anti-Malware to your desktop.
    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to
      • Update Malwarebytes' Anti-Malware
      • and Launch Malwarebytes' Anti-Malware
    • then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. please copy and paste the log into your next reply
      • If you accidently close it, the log file is saved here and will be named like this:
      • C:\\Documents and Settings\\Username\\Application Data\\Malwarebytes\\Malwarebytes' Anti-Malware\\Logs\\mbam-log-date (time).txt

    3. I need to see another log from HijackThis.
    • Run Hijackthis.
    • Click on Open the Misc Tools section.
    • Next click on Open uninstall manager.
    • Press the Save list button.
    • Save the file to your desktop, with the default name of uninstall_list
    • Copy & Paste the entire contents of that file in your in your next post.

    4. Please post the following...

    Uninstall list
    Malwarebytes log
    New HijackThis log



    Here's the unistall list, Malwarebytes log, and the new HJT....
    Uninstall:Adobe Acrobat - Reader 6.0.2 Update
    Adobe Flash Player 10 ActiveX
    Adobe Reader 6.0.1
    Blasterball 2 from Compaq (remove only)
    Blasterball 2 Holidays from Compaq (remove only)
    Blasterball 2 Remix from Compaq (remove only)
    Bounce Symphony from Compaq (remove only)
    CC_ccProxyExt
    ccCommon
    ccPxyCore
    Compaq Connections
    Compaq Organize
    Final Drive Nitro from Compaq (remove only)
    Help and Support Additions
    HijackThis 2.0.2
    Hotfix for Windows XP (KB952287)
    HP Boot Optimizer
    InterVideo WinDVD Player
    iTunes
    J2SE Runtime Environment 5.0
    KBD
    Lexibox Deluxe from Compaq (remove only)
    LiveReg (Symantec Corporation)
    LiveUpdate 3.0 (Symantec Corporation)
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Office Standard Edition 2003
    Microsoft Plus! Dancer LE
    Microsoft Plus! Digital Media Edition Installer
    Microsoft Plus! Photo Story 2 LE
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Motorola SM56 Speakerphone Modem
    MSRedist
    MSXML 4.0 SP2 (KB954430)
    Norton AntiSpam
    Norton AntiVirus 2005
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security 2005 (Symantec Corporation)
    Norton Security Center
    Norton WMI Update
    Norton WMI Update
    Overball from Compaq (remove only)
    PC-Doctor for Windows
    Polar Bowler from Compaq (remove only)
    Polar Golfer from Compaq (remove only)
    PowerTeacher Gradebook
    PS2
    Python 2.2 pywin32 extensions (build 203)
    Python 2.2.3
    QuickTime
    RealPlayer
    Remove Adobe Photoshop Album 2.0 Starter Edition installer
    Remove Microsoft Money 2005 installer
    Remove Quicken New User Edition installer
    Rhapsody Player Engine
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB943055)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944653)
    Security Update for Windows XP (KB945553)
    Security Update for Windows XP (KB946026)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950749)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB960715)
    Shooting Stars Pool from Compaq (remove only)
    SiS VGA Utilities
    Slyder from Compaq (remove only)
    Sonic Express Labeler
    Sonic MyDVD Plus
    Sonic RecordNow Audio
    Sonic RecordNow Copy
    Sonic RecordNow Data
    Sonic Update Manager
    SPBBC
    SpySubtract
    SymNet
    Tradewinds from Compaq (remove only)
    Update for Windows Internet Explorer 8 (KB961813)
    Update for Windows XP (KB894391)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB908531)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Windows Installer 3.1 (KB893803)
    Windows Internet Explorer 8 Release Candidate 1
    Windows Live Messenger
    Windows Media Format Runtime
    Windows Media Player 10
    Windows XP Hotfix - KB867282
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB883667
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888239
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890175
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    Yahoo! Messenger
    Yahoo! Toolbar

    Mbam Log:Malwarebytes' Anti-Malware 1.34
    Database version: 1817
    Windows 5.1.2600 Service Pack 2

    3/4/2009 8:40:50 PM
    mbam-log-2009-03-04 (20-40-50).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 167035
    Time elapsed: 1 hour(s), 50 minute(s), 23 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    New HJT log:Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:47:01 PM, on 3/4/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18372)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\Explorer.EXE
    c:\Program Files\Norton Internet Security\ISSVC.exe
    c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\sm56hlpr.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\InterMute\SpySubtract\SpySub.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HP\KBD\KBD.EXE
    c:\windows\system\hpsysdrv.exe
    C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
    C:\WINDOWS\system32\WISPTIS.EXE
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\RunOnce: [ypagerps] cmd.exe /C del "C:\PROGRA~1\Yahoo!\MESSEN~1\ypagerps.dll"
    O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
    O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
    O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    --
    End of file - 8768 bytes
  • TroganTrogan London, UK
    edited March 2009
    Hi,

    Please do the following...

    1. Click Start > Run > type in appwiz.cpl and hit enter. From the list uninstall the following, if present:

    Adobe Reader 6.0.1
    J2SE Runtime Environment 5.0


    2. You should download and install the newest version of the free Adobe Reader for reading pdf files, due to vulnerabilities in earlier versions of Reader and Acrobat.
    All versions numbered lower than 8.1.2 are vulnerable.
    • Go HERE to download the latest version of Adobe Reader.
    • Save this file to your desktop and run it to install the latest version of Adobe Reader.
    If you prefer a simple reader, without plug-ins, that is smaller and faster, take a look at the free Foxit Reader here : http://www.foxitsoftware.com/downloads/
    I would recommend the older Foxit version 2.3 only, without the toolbar. Foxit version 3.0 has the undesirable ASK toolbar.

    You can keep your full version of Adobe Acrobat 6, but you should use it for editing and creation of pdf's only, NOT for opening pdf's on the net.
    You can still call Adobe Acrobat 6 from Start, All Programs

    3. Download and install Java SE Runtime Environment (JRE) 6 Update 12

    4. Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be promted to install an ActiveX component from Kaspersky, Click Yes.

    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)
      • Scan Options:
        Scan Archives
        Scan Mail Bases


        [*]Click OK
        [*]Now under select a target to scan:
          Select
        My Computer

        [*]This will program will start and scan your system.
        [*]The scan will take a while so be patient and let it run.
        [*]Once the scan is complete it will display if your system has been infected.
        • Now click on the Save Report As button:
        • Change Save as type: to Text file
        • Save this as Kaspersky scan to your Desktop
        [*]Post the Kaspersky report in your next reply.


        5. Please post the following...

        Kaspersky report
        New HijackThis log

        Also, is your Norton Anti-Virus up-to-date?
      • scrumptousscrumptous Florida
        edited March 2009
        Trogan wrote:
        Hi,

        Please do the following...

        1. Click Start > Run > type in appwiz.cpl and hit enter. From the list uninstall the following, if present:

        Adobe Reader 6.0.1
        J2SE Runtime Environment 5.0


        2. You should download and install the newest version of the free Adobe Reader for reading pdf files, due to vulnerabilities in earlier versions of Reader and Acrobat.
        All versions numbered lower than 8.1.2 are vulnerable.
        • Go HERE to download the latest version of Adobe Reader.
        • Save this file to your desktop and run it to install the latest version of Adobe Reader.
        If you prefer a simple reader, without plug-ins, that is smaller and faster, take a look at the free Foxit Reader here : http://www.foxitsoftware.com/downloads/
        I would recommend the older Foxit version 2.3 only, without the toolbar. Foxit version 3.0 has the undesirable ASK toolbar.

        You can keep your full version of Adobe Acrobat 6, but you should use it for editing and creation of pdf's only, NOT for opening pdf's on the net.
        You can still call Adobe Acrobat 6 from Start, All Programs

        3. Download and install Java SE Runtime Environment (JRE) 6 Update 12

        4. Please do an online scan with Kaspersky WebScanner

        Click on Kaspersky Online Scanner

        You will be promted to install an ActiveX component from Kaspersky, Click Yes.

        Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
        • The program will launch and then begin downloading the latest definition files:
        • Once the files have been downloaded click on NEXT
        • Now click on Scan Settings
        • In the scan settings make that the following are selected:
          • Scan using the following Anti-Virus database:
            Extended (if available otherwise Standard)
          • Scan Options:
            Scan Archives
            Scan Mail Bases


            [*]Click OK
            [*]Now under select a target to scan:
              Select
            My Computer

            [*]This will program will start and scan your system.
            [*]The scan will take a while so be patient and let it run.
            [*]Once the scan is complete it will display if your system has been infected.
            • Now click on the Save Report As button:
            • Change Save as type: to Text file
            • Save this as Kaspersky scan to your Desktop
            [*]Post the Kaspersky report in your next reply.


            5. Please post the following...

            Kaspersky report
            New HijackThis log

            Also, is your Norton Anti-Virus up-to-date?

            I uninstalled Adobe 6.0.1 and JSE Runtime. I also installed the Adobe Reader and Foxit. It wouldn't let me run the Kaspersky. When I tried, said I had additional plugins to install. Clicked on that, and it wouldn't work. Clicked to manually install. Once I did this, I tried Kaspersky again, and I got the same thing. I'm doing everything on Firefox because I can't Internet Explorer to open now. Any idea what's going on with that. Attached is the new HJT log. I have the Norton Internet Security which has the anti-virus.


            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 11:23:38 PM, on 3/6/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16791)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
            c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            c:\Program Files\Norton Internet Security\ISSVC.exe
            c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\WINDOWS\sm56hlpr.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\InterMute\SpySubtract\SpySub.exe
            C:\HP\KBD\KBD.EXE
            C:\WINDOWS\ALCXMNTR.EXE
            c:\windows\system\hpsysdrv.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\WINDOWS\system32\msiexec.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
            O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
            O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
            O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
            O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
            O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
            O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
            O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
            O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
            O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

            --
            End of file - 9689 bytes
          • TroganTrogan London, UK
            edited March 2009
            Hi,

            Please do the following...

            1. Open HijackThis
            - Click the Do a system scan only button
            - Check the following entries (below)

            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


            - Close ALL open windows (especially Internet Explorer!)
            - Click Fix Checked
            Close HiajckThis

            2. Download ComboFix from one of these locations:

            Link 1
            Link 2
            Link 3

            * IMPORTANT!!! Save ComboFix.exe to your Desktop
            • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools See HERE for help
            • Double click on ComboFix.exe & follow the prompts.
            • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
            • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
            **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
            RcAuto1.gif

            Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
            whatnext.png

            Click on Yes, to continue scanning for malware.

            When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

            Also...
            The HijackThis log in your previous post shows you had IE8, but your current log shows you have IE7. Did you uninstall IE8?
            Do you get any error messages when trying to open IE?
          • scrumptousscrumptous Florida
            edited March 2009
            Trogan wrote:
            Hi,

            Please do the following...

            1. Open HijackThis
            - Click the Do a system scan only button
            - Check the following entries (below)

            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


            - Close ALL open windows (especially Internet Explorer!)
            - Click Fix Checked
            Close HiajckThis

            2. Download ComboFix from one of these locations:

            Link 1
            Link 2
            Link 3

            * IMPORTANT!!! Save ComboFix.exe to your Desktop
            • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools See HERE for help
            • Double click on ComboFix.exe & follow the prompts.
            • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
            • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
            **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
            RcAuto1.gif

            Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
            whatnext.png

            Click on Yes, to continue scanning for malware.

            When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

            Also...
            The HijackThis log in your previous post shows you had IE8, but your current log shows you have IE7. Did you uninstall IE8?
            Do you get any error messages when trying to open IE?

            I think I tried to update to IE8, but that still wouldn't work. I'm not sure if I did an uninstall or not. When I click on the Internet Explorer icon, it acts like it wants to open, but it won't. Sometimes it will flash, but still not load.

            I finally got Kaspersky to scan. I'm working on that now. Just as soon as it finishes, I'll send that log.


            Here is the ComboFix log:
            ComboFix 09-03-06.02 - Compaq_Owner 2009-03-09 18:56:28.1 - NTFSx86
            Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.51 [GMT -4:00]
            Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe
            .

            ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
            .

            c:\program files\Zumie
            c:\program files\Zumie\home.js
            c:\program files\Zumie\readme.html
            c:\program files\Zumie\uninstall.exe
            c:\program files\Zumie\zopt.exe
            c:\program files\Zumie\zumie.dll
            c:\program files\Zumie\zumie.exe
            c:\windows\IE4 Error Log.txt
            D:\Autorun.inf
            F:\AUTORUN.INF

            .
            ((((((((((((((((((((((((( Files Created from 2009-02-09 to 2009-03-09 )))))))))))))))))))))))))))))))
            .

            2009-03-09 18:50 . 2009-03-02 04:46 <DIR> d
            C:\32788R22FWJFW
            2009-03-07 00:18 . 2009-03-07 00:17 410,984 --a
            c:\windows\system32\deploytk.dll
            2009-03-07 00:18 . 2009-03-07 00:17 73,728 --a
            c:\windows\system32\javacpl.cpl
            2009-03-06 23:54 . 2009-03-06 23:54 <DIR> d
            c:\program files\Common Files\Adobe AIR
            2009-03-06 09:57 . 2009-03-06 10:08 <DIR> d
            c:\windows\system32\CatRoot_bak
            2009-03-06 09:56 . 2008-08-14 06:00 2,180,352
            c:\windows\system32\dllcache\ntoskrnl.exe
            2009-03-06 09:56 . 2008-08-14 05:58 2,136,064
            c:\windows\system32\dllcache\ntkrnlmp.exe
            2009-03-06 09:56 . 2008-08-14 05:22 2,057,728
            c:\windows\system32\dllcache\ntkrnlpa.exe
            2009-03-06 09:56 . 2008-08-14 05:22 2,015,744
            c:\windows\system32\dllcache\ntkrpamp.exe
            2009-03-05 19:52 . 2009-03-05 19:52 <DIR> d
            c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
            2009-03-05 19:52 . 2009-02-11 11:19 38,496 --a
            c:\windows\system32\drivers\mbamswissarmy.sys
            2009-03-05 19:52 . 2009-02-11 11:19 15,504 --a
            c:\windows\system32\drivers\mbam.sys
            2009-03-05 19:36 . 2008-10-24 07:10 453,632
            c:\windows\system32\dllcache\mrxsmb.sys
            2009-03-05 01:56 . 2008-06-13 09:10 272,128
            c:\windows\system32\drivers\bthport.sys
            2009-03-05 01:56 . 2008-06-13 09:10 272,128
            c:\windows\system32\dllcache\bthport.sys
            2009-03-05 01:53 . 2004-08-04 00:00 221,184 --a
            c:\windows\system32\wmpns.dll
            2009-03-05 01:53 . 2001-08-17 23:36 171,008 --a
            c:\windows\system32\LXAESUI.DLL
            2009-03-05 01:53 . 2009-03-05 01:53 1,891 -rahs---- c:\windows\system32\drivers\103C_HP_CPC_PX796AA-ABA SR1517CL NA530_YC_0Pres_QCNH521_E53NAheRED3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.15_T051019_WXH2_L409_M384_J160_7AMD_8Sempron_91.81_#070824_N10390900_Z10573052_G10396330.MRK
            2009-03-05 01:52 . 2005-07-13 19:31 <DIR> d
            c:\documents and settings\Compaq_Owner\WINDOWS
            2009-03-05 01:52 . 2009-03-05 01:58 <DIR> d
            c:\documents and settings\Compaq_Owner\Application Data\Symantec
            2009-03-05 01:52 . 2005-07-13 19:46 <DIR> d
            c:\documents and settings\Compaq_Owner\Application Data\SampleView
            2009-03-05 01:52 . 2005-07-13 19:51 <DIR> d
            c:\documents and settings\Compaq_Owner\Application Data\InterMute
            2009-03-05 01:52 . 2005-07-13 19:30 <DIR> d
            c:\documents and settings\Compaq_Owner\Application Data\Apple Computer
            2009-03-05 01:52 . 2009-03-05 01:20 <DIR> d
            c:\documents and settings\Compaq_Owner
            2009-03-05 01:51 . 2005-07-13 19:31 <DIR> d
            c:\windows\system32\config\systemprofile\WINDOWS
            2009-03-05 01:51 . 2005-07-13 19:55 <DIR> d
            c:\windows\system32\config\systemprofile\Application Data\Symantec
            2009-03-05 01:51 . 2005-07-13 19:46 <DIR> d
            c:\windows\system32\config\systemprofile\Application Data\SampleView
            2009-03-05 01:51 . 2005-07-13 19:51 <DIR> d
            c:\windows\system32\config\systemprofile\Application Data\InterMute
            2009-03-05 01:51 . 2005-07-13 19:30 <DIR> d
            c:\windows\system32\config\systemprofile\Application Data\Apple Computer
            2009-03-05 01:26 . 2005-06-28 11:21 22,752 --a
            c:\windows\system32\spupdsvc.exe
            2009-03-05 01:20 . 2009-03-07 20:56 <DIR> dr-hs---- c:\windows\system32\dllcache
            2009-03-05 01:20 . 2009-03-05 01:20 <DIR> d--hs---- c:\documents and settings\Compaq_Owner\UserData
            2009-03-05 01:20 . 2009-03-05 01:20 <DIR> d
            c:\documents and settings\Compaq_Owner\Contacts
            2009-03-05 01:19 . 2009-03-05 01:19 <DIR> d----c--- c:\windows\system32\DRVSTORE
            2009-03-05 01:19 . 2008-12-20 19:15 6,066,688
            c:\windows\system32\dllcache\ieframe.dll
            2009-03-05 01:19 . 2007-04-17 05:32 2,455,488
            c:\windows\system32\dllcache\ieapfltr.dat
            2009-03-05 01:19 . 2007-03-08 01:10 991,232
            c:\windows\system32\dllcache\ieframe.dll.mui
            2009-03-05 01:19 . 2008-12-20 19:15 459,264
            c:\windows\system32\dllcache\msfeeds.dll
            2009-03-05 01:19 . 2008-12-20 19:15 383,488
            c:\windows\system32\dllcache\ieapfltr.dll
            2009-03-05 01:19 . 2008-12-20 19:15 267,776
            c:\windows\system32\dllcache\iertutil.dll
            2009-03-05 01:19 . 2008-12-20 19:15 63,488
            c:\windows\system32\dllcache\icardie.dll
            2009-03-05 01:19 . 2008-12-20 19:15 52,224
            c:\windows\system32\dllcache\msfeedsbs.dll
            2009-03-05 01:19 . 2008-12-19 05:10 13,824
            c:\windows\system32\dllcache\ieudinit.exe
            2009-03-05 01:16 . 2009-03-05 01:17 <DIR> d
            C:\b2b2fa71699c690a5f7518
            2009-03-05 00:40 . 2009-03-05 00:40 <DIR> d
            c:\documents and settings\Compaq_Owner\Application Data\Yahoo!
            2009-03-04 22:45 . 2009-03-04 22:45 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\Template
            2009-03-04 22:45 . 2009-03-04 22:45 0 --a
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\wklnhst.dat
            2009-03-04 19:48 . 2009-03-05 19:52 <DIR> d
            c:\program files\Malwarebytes' Anti-Malware
            2009-03-04 19:48 . 2009-03-04 19:48 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\Malwarebytes
            2009-03-04 19:48 . 2009-03-04 19:48 <DIR> d
            c:\documents and settings\All Users\Application Data\Malwarebytes
            2009-02-20 17:22 . 2009-02-26 22:01 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\LimeWire
            2009-02-18 17:54 . 2009-02-18 17:54 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\SUPERAntiSpyware.com
            2009-02-16 16:07 . 2009-02-16 16:07 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\AdobeUM
            2009-02-12 23:30 . 2009-02-12 23:30 <DIR> d--hs---- c:\documents and settings\Compaq_Owner.GUESS\IECompatCache
            2009-02-12 23:26 . 2009-02-12 23:26 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\Yahoo!
            2009-02-12 22:23 . 2009-02-19 00:25 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Contacts
            2009-02-12 22:03 . 2009-02-12 22:03 <DIR> d--hs---- c:\documents and settings\Compaq_Owner.GUESS\PrivacIE
            2009-02-12 22:02 . 2009-02-12 22:02 <DIR> d--hs---- c:\documents and settings\Compaq_Owner.GUESS\IETldCache
            2009-02-12 21:58 . 2009-02-12 21:58 <DIR> d
            c:\windows\ie8updates
            2009-02-12 21:56 . 2009-02-12 21:57 <DIR> d--h-c--- c:\windows\ie8
            2009-02-12 21:32 . 2005-07-13 19:31 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\WINDOWS
            2009-02-12 21:32 . 2009-02-12 21:39 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\Symantec
            2009-02-12 21:32 . 2005-07-13 19:46 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\SampleView
            2009-02-12 21:32 . 2005-07-13 19:51 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\InterMute
            2009-02-12 21:32 . 2005-07-13 19:30 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS\Application Data\Apple Computer
            2009-02-12 21:32 . 2009-03-02 22:46 <DIR> d
            c:\documents and settings\Compaq_Owner.GUESS
            2009-02-12 21:07 . 2009-03-05 01:30 <DIR> dr-h
            C:\MSOCache
            2009-02-11 19:24 . 2009-02-11 19:24 <DIR> d
            c:\windows\l2schemas
            2009-02-11 19:21 . 2009-02-11 19:24 <DIR> d
            c:\windows\ServicePackFiles
            2009-02-11 19:12 . 2009-02-11 19:12 <DIR> d
            c:\windows\EHome

            .
            (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2009-03-08 22:37
            d
            w c:\program files\Common Files\Symantec Shared
            2009-03-07 04:00
            d
            w c:\program files\NOS
            2009-03-07 04:00
            d
            w c:\documents and settings\All Users\Application Data\NOS
            2009-03-07 03:51
            d
            w c:\program files\Common Files\Adobe
            2009-03-07 03:42
            d
            w c:\program files\Java
            2009-03-05 08:06
            d
            w c:\program files\Yahoo!
            2009-03-05 05:56
            d
            w c:\program files\Easy Internet signup
            2009-03-05 05:19
            d
            w c:\program files\MSN Messenger
            2009-03-05 04:52
            d
            w c:\program files\Symantec
            2009-02-27 02:07
            d
            w c:\program files\SUPERAntiSpyware
            2009-02-20 20:44
            d
            w c:\program files\LimeWire
            2009-02-05 03:28
            d
            w c:\documents and settings\All Users\Application Data\AOL OCP
            2009-02-05 03:26
            d
            w c:\program files\Common Files\Software Update Utility
            2009-02-05 03:26
            d
            w c:\program files\AIM6
            2009-02-05 03:25
            d
            w c:\program files\Viewpoint
            2009-02-05 03:25
            d
            w c:\documents and settings\All Users\Application Data\Viewpoint
            2009-02-05 03:25
            d
            w c:\documents and settings\All Users\Application Data\acccore
            2009-02-05 03:24
            d
            w c:\documents and settings\All Users\Application Data\AOL
            2009-02-05 03:23
            d
            w c:\program files\Common Files\AOL
            2009-02-03 00:04
            d
            w c:\program files\FSX Flight Weather Report
            2009-02-03 00:04
            d
            w c:\program files\Common Files\SWF Studio
            2009-01-23 02:56
            d
            w c:\program files\Ratbag
            2009-01-21 02:38
            d
            w c:\documents and settings\All Users\Application Data\Yahoo!
            2009-01-17 02:35 3,594,752
            w c:\windows\system32\dllcache\mshtml.dll
            2008-12-19 09:10 70,656
            w c:\windows\system32\dllcache\ie4uinit.exe
            2008-12-19 05:25 634,024
            w c:\windows\system32\dllcache\iexplore.exe
            2008-12-19 05:23 161,792
            w c:\windows\system32\dllcache\ieakui.dll
            2008-12-11 11:57 333,184 ----a-w c:\windows\system32\dllcache\srv.sys
            .

            ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* empty entries & legit default entries are not shown
            REGEDIT4

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]
            "msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
            "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 58984]
            "HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
            "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
            "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-07-13 180269]
            "ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2004-07-28 221184]
            "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
            "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-07 148888]
            "SiSPower"="SiSPower.dll" [2005-01-05 c:\windows\system32\SiSPower.dll]
            "SMSERIAL"="sm56hlpr.exe" [2005-01-24 c:\windows\sm56hlpr.exe]
            "AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]

            c:\documents and settings\All Users\Start Menu\Programs\Startup\
            Compaq Connections.lnk - c:\program files\Compaq Connections\6750491\Program\Compaq Connections.exe [2005-07-13 45056]
            SpySubtract.lnk - c:\program files\InterMute\SpySubtract\sslaunch.exe [2005-07-13 73728]

            [HKEY_LOCAL_MACHINE\software\microsoft\security center]
            "AntiVirusDisableNotify"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
            "DisableMonitoring"=dword:00000001

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
            "EnableFirewall"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "c:\\Program Files\\iTunes\\iTunes.exe"=
            "c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
            "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
            "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
            "c:\\Program Files\\MSN Messenger\\livecall.exe"=
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=


            --- Other Services/Drivers In Memory ---

            *NewlyCreated* - HTTPFILTER

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9b408d0-bc63-11d9-842c-806d6172696f}]
            \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
            .
            Contents of the 'Scheduled Tasks' folder

            2009-03-05 c:\windows\Tasks\Easy Internet Sign-up.job
            - c:\program files\Easy Internet signup\HPSdpApp.exe [2005-03-03 21:04]

            2009-03-05 c:\windows\Tasks\SpySubtract.job
            - c:\progra~1\INTERM~1\SPYSUB~1\SpySub.exe [2005-07-13 19:33]
            .
            - - - - ORPHANS REMOVED - - - -

            ShellExecuteHooks-{FA010552-4A27-4cb1-A1BB-3E2D697F1639} - (no file)


            .
            Supplementary Scan
            .
            uStart Page = hxxp://www.myspace.com/
            uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
            uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
            mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
            uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
            IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
            IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
            IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
            IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
            IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
            IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
            .

            **************************************************************************

            catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2009-03-09 18:59:00
            Windows 5.1.2600 Service Pack 2 NTFS

            scanning hidden processes ...

            scanning hidden autostart entries ...

            scanning hidden files ...

            scan completed successfully
            hidden files: 0

            **************************************************************************
            .
            Completion time: 2009-03-09 19:00:29
            ComboFix-quarantined-files.txt 2009-03-09 23:00:21

            Pre-Run: 93,508,767,744 bytes free
            Post-Run: 93,626,036,224 bytes free

            203 --- E O F --- 2009-03-07 23:58:40
          • TroganTrogan London, UK
            edited March 2009
            Hi,

            Please do the following...

            1. Please download Flash_Disinfector.exe by sUBs and save it to your desktop:
            • Double-click Flash_Disinfector.exe to run it.
            • Follow any prompts that may appear.
            • Wait until the program has finished scanning, then please exit the program.
              The tool may ask you to insert your flash drive, or other removable drives. Please do so and allow the tool to clean it up as well.

            Please restart your computer.
            Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that is plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

            2. Find and delete the following folders in RED:

            C:\32788R22FWJFW
            C:\b2b2fa71699c690a5f7518

            3. Please update Malwarebytes and run a new scan.

            4. Please post the following...

            Malwarebytes log
            New HijackThis log

            Also, please post the Kaspersky report if you completed the scan.
            I have the Norton Internet Security which has the anti-virus.
            But does it still receive updates? or not?
          • scrumptousscrumptous Florida
            edited March 2009
            Trogan wrote:
            Hi,

            Please do the following...

            1. Please download Flash_Disinfector.exe by sUBs and save it to your desktop:
            • Double-click Flash_Disinfector.exe to run it.
            • Follow any prompts that may appear.
            • Wait until the program has finished scanning, then please exit the program.
              The tool may ask you to insert your flash drive, or other removable drives. Please do so and allow the tool to clean it up as well.

            Please restart your computer.
            Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that is plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

            2. Find and delete the following folders in RED:

            C:\32788R22FWJFW
            C:\b2b2fa71699c690a5f7518

            3. Please update Malwarebytes and run a new scan.

            4. Please post the following...

            Malwarebytes log
            New HijackThis log

            Also, please post the Kaspersky report if you completed the scan.


            But does it still receive updates? or not?


            I've deleted the two folders you mentioned. I'm attaching the Kaspersky scan, Malwarebytes scan, and a new HJT log. I still get updates with Norton.

            KASPERSKY ONLINE SCANNER 7 REPORT
            Thursday, March 19, 2009
            Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
            Kaspersky Online Scanner 7 version: 7.0.25.0
            Program database last update: Sunday, March 15, 2009 19:43:38
            Records in database: 1909319

            Scan settings:
            Scan using the following database: extended
            Scan archives: yes
            Scan mail databases: yes

            Scan area - My Computer:
            C:\
            D:\
            E:\
            F:\
            G:\
            H:\
            I:\
            J:\

            Scan statistics:
            Files scanned: 99349
            Threat name: 3
            Infected objects: 3
            Suspicious objects: 0
            Duration of the scan: 02:26:23


            File name / Threat name / Threats count
            C:\Documents and Settings\Compaq_Owner.GUESS\My Documents\LimeWire\Saved\chicken fried.snd Infected: Trojan-Downloader.WMA.GetCodec.s 1
            C:\Program Files\Online Services\AOL90US\comps\toolbar\toolbr.EXE Infected: not-a-virus:AdWare.Win32.SearchIt.t 1
            C:\Qoobox\Quarantine\C\Program Files\Zumie\zopt.exe.vir Infected: not-a-virus:AdWare.Win32.OneStep.x 1

            The selected area was scanned.


            Malwarebytes' Anti-Malware 1.34
            Database version: 1822
            Windows 5.1.2600 Service Pack 2

            3/19/2009 9:52:45 PM
            mbam-log-2009-03-19 (21-52-45).txt

            Scan type: Full Scan (C:\|)
            Objects scanned: 169961
            Time elapsed: 1 hour(s), 34 minute(s), 14 second(s)

            Memory Processes Infected: 0
            Memory Modules Infected: 0
            Registry Keys Infected: 0
            Registry Values Infected: 0
            Registry Data Items Infected: 0
            Folders Infected: 0
            Files Infected: 0

            Memory Processes Infected:
            (No malicious items detected)

            Memory Modules Infected:
            (No malicious items detected)

            Registry Keys Infected:
            (No malicious items detected)

            Registry Values Infected:
            (No malicious items detected)

            Registry Data Items Infected:
            (No malicious items detected)

            Folders Infected:
            (No malicious items detected)

            Files Infected:
            (No malicious items detected)


            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 9:57:28 PM, on 3/19/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16791)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
            c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            c:\Program Files\Norton Internet Security\ISSVC.exe
            c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            C:\WINDOWS\Explorer.EXE
            c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\WINDOWS\sm56hlpr.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\WINDOWS\ALCXMNTR.EXE
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
            C:\Program Files\InterMute\SpySubtract\SpySub.exe
            C:\HP\KBD\KBD.EXE
            C:\Program Files\Mozilla Firefox\firefox.exe
            c:\windows\system\hpsysdrv.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
            O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
            O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
            O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
            O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
            O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
            O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
            O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
            O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
            O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
            O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

            --
            End of file - 8927 bytes
          • TroganTrogan London, UK
            edited March 2009
            Hi,

            I apologise for the long delay. I've been away and didn't have access to the Internet.

            The logs look clean. How is the computer now?
          • scrumptousscrumptous Florida
            edited March 2009
            Trogan wrote:
            Hi,

            I apologise for the long delay. I've been away and didn't have access to the Internet.

            The logs look clean. How is the computer now?

            Still slow. Internet Explorer still won't open. These are things I have installed on this computer and was wondering if I needed ALL of them: SpySubtract, Venus Spy Trap, Ad-Watch 2007, AVG-Anti-Spyware, Spyware Doctor, Super Anti-Spyware, Ad-Aware 2007 Anti-Malware. Am I over protected with Spyware???
          • TroganTrogan London, UK
            edited March 2009
            Hi,
            These are things I have installed on this computer and was wondering if I needed ALL of them: SpySubtract, Venus Spy Trap, Ad-Watch 2007, AVG-Anti-Spyware, Spyware Doctor, Super Anti-Spyware, Ad-Aware 2007 Anti-Malware. Am I over protected with Spyware???
            Yes, that is a lot. I would suggest that you keep only keep Malwarebytes' and uninstall the others you have.

            Do that and let me know if that helps.
          • scrumptousscrumptous Florida
            edited March 2009
            Trogan wrote:
            Hi,

            Yes, that is a lot. I would suggest that you keep only keep Malwarebytes' and uninstall the others you have.

            Do that and let me know if that helps.

            I've uninstalled whatever I could from the Control Panel (add/remove). What I couldn't find there, I just deleted. I'll keep a check on how the computer performs since I've done that. My Internet Explorer still won't open. Is there any way you can see what's going on with that? I'd like to get it opening because Mozilla sometimes will not open for me, and I have to uninstall and reinstall it. If it won't open, and Internet Explorer won't open, how am I to open a browser?
          • TroganTrogan London, UK
            edited March 2009
            I don't think you posted the Kaspersky report. If you have the report, could you post it please, otherwise do a new scan and post the report.
          Sign In or Register to comment.