Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Virus?  (Read 27160 times)

0 Members and 1 Guest are viewing this topic.

TriciaM

    Topic Starter


    Beginner

    Virus?
    « on: September 29, 2009, 05:11:30 PM »
    I've tried searching the threads for this and could not find it...

    C:\\WINDOWS\ASSEMBLY\NativeImages|System.Web.Mobile.ni.dll

    This is what my Virus scan is stuck on. It's been stuck there for hours....I'm wondering if anyone knows what this is ?  Some more info:

    My computer has been slow the last several days.  If I visit websites (such as Ebay, other merchant sites), a message come up that says something like "True Vector has to shut down" (I'm pretty sure this is related to Zone Alarm.)   I've searched Zone Alarm's site for answers but cannot find anything. Any help is appreciated.

    harry 48



      Egghead

    • lay back , relax and chill out
    • Thanked: 129
      • Yes
      • Yes
      • Yes
      • Dribbling Pensioner
    • Certifications: List
    • Experience: Familiar
    • OS: Windows 7
    Re: Virus?
    « Reply #1 on: September 29, 2009, 05:21:52 PM »
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    go to above and complete post 3 logs here an expert will see them

    TriciaM

      Topic Starter


      Beginner

      Re: Virus?
      « Reply #2 on: September 29, 2009, 05:30:48 PM »
      Ok. It looks like it's going to take a while....I'll be back tonight when my kids go to bed...I did look to see what pack I had, though. I have 3.

      Thanks for the help.

      TriciaM

        Topic Starter


        Beginner

        Re: Virus?
        « Reply #3 on: September 29, 2009, 08:18:34 PM »
        Is is correct to say that if I have SP3 installed that I am good-to-do in respect to the SPs ?

        TriciaM

          Topic Starter


          Beginner

          Re: Virus?
          « Reply #4 on: September 30, 2009, 07:04:57 AM »
          **further info on the below problem** - I've since gotten an error message involving RAID or missing RAID.  This is after my computer shut down while running MBAM scan. Right before it shut down, MBAM scan was scanning and showing 7 infections. 

          Thought I needed to post this...as I came across this while doing the MalWarebytes scan. I may be using the incorrect terms so please bear with me....

          While conducting the MBAM scan, my computer abruptly "shut down".  I've seen this before...it gives me the black screen.  It gave me the error signature, then gives me the following:   C:\DOCUME~1\TRICIA~1\LOCALS~1\TEMP\WER122e.dir00\Mini093009-01.dmp

          I had to turn my computer off by using the power button (wouldn't let me exit out of the black screen...).

          « Last Edit: September 30, 2009, 08:44:33 AM by TriciaM »

          TriciaM

            Topic Starter


            Beginner

            SUPERAntiSpyware scan log
            « Reply #5 on: September 30, 2009, 09:01:23 AM »
            SUPERAntiSpyware Scan Log
            http://www.superantispyware.com

            Generated 09/30/2009 at 03:59 AM

            Application Version : 4.29.1002

            Core Rules Database Version : 4135
            Trace Rules Database Version: 2068

            Scan type       : Complete Scan
            Total Scan Time : 02:55:16

            Memory items scanned      : 625
            Memory threats detected   : 0
            Registry items scanned    : 6890
            Registry threats detected : 13
            File items scanned        : 103767
            File threats detected     : 19

            Trojan.WinFixer
               HKLM\Software\Classes\CLSID\{314C5152-F664-4A53-8FD4-109B82D866DF}
               HKCR\CLSID\{314C5152-F664-4A53-8FD4-109B82D866DF}
               HKCR\CLSID\{314C5152-F664-4A53-8FD4-109B82D866DF}\InprocServer32
               HKCR\CLSID\{314C5152-F664-4A53-8FD4-109B82D866DF}\InprocServer32#ThreadingModel
               C:\WINDOWS\SYSTEM32\SSTQP.DLL
               HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{314C5152-F664-4A53-8FD4-109B82D866DF}
               HKU\S-1-5-21-186917913-2315771567-692555066-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{314C5152-F664-4A53-8FD4-109B82D866DF}

            Adware.Vundo Variant
               HKU\S-1-5-21-186917913-2315771567-692555066-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9BD0828-1FD9-410C-A50F-43EBE65D310F}

            Adware.Tracking Cookie
               c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
               c:\documents and settings\tricia & roger\cookies\tricia & [email protected][1].txt
               c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
               c:\documents and settings\tricia & roger\cookies\tricia & [email protected][1].txt
               c:\documents and settings\tricia & roger\cookies\tricia_&_roger@countrywide[1].txt
               c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
               c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
               c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
               c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
               c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
               C:\Documents and Settings\Tricia & Roger\Cookies\tricia & [email protected]

            Trojan.ZenoSearch
               C:\WINDOWS\system32\msnav32.ax

            Trojan.Unknown Origin
               HKLM\Software\xpre
               HKLM\Software\xpre#execount

            Adware.Vundo Variant/Rel
               HKLM\SOFTWARE\Microsoft\aoprndtws
               HKLM\SOFTWARE\Microsoft\FCOVM
               HKU\S-1-5-21-186917913-2315771567-692555066-1006\Software\Microsoft\aldd
               HKU\S-1-5-21-186917913-2315771567-692555066-1006\Software\Microsoft\rdfa
               C:\WINDOWS\SYSTEM32\PQTSS.BAK1
               C:\WINDOWS\SYSTEM32\PQTSS.BAK2
               C:\WINDOWS\SYSTEM32\PQTSS.INI
               C:\WINDOWS\SYSTEM32\PQTSS.INI2

            Adware.ClickSpring/Yazzle
               C:\PROGRAM FILES\COMMON FILES\YAZZLE1281OINUNINSTALLER.EXE

            Adware.ClickSpring/PuritySCAN
               C:\WINDOWS\SYSTEM32\WNSAPISV.EXE

            TriciaM

              Topic Starter


              Beginner

              Re: Virus?
              « Reply #6 on: September 30, 2009, 09:32:40 AM »
              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 11:30:48 AM, on 9/30/2009
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
              C:\WINDOWS\system32\brsvc01a.exe
              C:\WINDOWS\system32\brss01a.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\SYSTEM32\Brmfrmps.exe
              C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
              C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
              C:\Program Files\AppStream\WindowsClient\bin\AppMgrService.exe
              C:\Program Files\Canon\CAL\CALMAIN.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
              C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
              C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
              C:\Program Files\Dell\Media Experience\PCMService.exe
              C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
              C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
              C:\WINDOWS\system32\dla\tfswctrl.exe
              C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
              C:\Program Files\Logitech\Video\CameraAssistant.exe
              C:\WINDOWS\system32\ElkCtrl.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
              C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
              C:\WINDOWS\Elmore Music Messenger.exe
              C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
              C:\Program Files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe
              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
              C:\Program Files\AppStream\WindowsClient\Bin\AppMgrGui.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
              C:\Program Files\TiVo\Desktop\TiVoNotify.exe
              C:\Program Files\TiVo\Desktop\TiVoServer.exe
              C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Trend Micro\Sniper.exe\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
              R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\elnIE.dll
              R3 - URLSearchHook: (no name) - ~37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - (no file)
              R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
              O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
              O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - (no file)
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
              O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
              O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
              O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
              O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
              O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
              O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
              O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
              O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
              O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
              O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
              O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
              O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
              O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
              O4 - HKLM\..\Run: [AppMgrGui] C:\Program Files\AppStream\WindowsClient\bin\exeForService.exe
              O4 - HKLM\..\Run: [Elmore Music Messenger] C:\WINDOWS\Elmore Music Messenger.exe
              O4 - HKLM\..\Run: [eligmini] C:\Program Files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe 0
              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
              O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
              O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry /auto:TivoServer
              O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
              O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
              O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Tricia & Roger\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
              O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
              O4 - HKUS\S-1-5-18\..\RunOnce: [TBInfo] iexplore.exe "http://www.earthlink.net/go/elnktoolbarinstall" (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\RunOnce: [TBInfo] iexplore.exe "http://www.earthlink.net/go/elnktoolbarinstall" (User 'Default user')
              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
              O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
              O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
              O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
              O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O15 - Trusted Zone: http://support.broderbund.com
              O15 - Trusted Zone: http://smartdownload.riverdeep.net
              O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
              O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
              O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
              O16 - DPF: {5DA9D8E0-5A57-11CF-9E36-00C0930198C0} (Pegasus ImagN' 32-bit (Windowed) ActiveX Control v4.00) - http://www.ansonncrod.org/imw32o40.cab
              O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136246925750
              O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidctl_vsp.closetmaid.com_downloader.cab
              O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components) - https://portal.uspsoig.gov/InternalSite/WhlCompMgr.cab
              O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
              O16 - DPF: {9841D1AE-9C0B-11D3-9452-00105A098C21} (Pegasus PrintPRO Control v2.0) - http://www.ansonncrod.org/prntpro2.CAB
              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
              O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
              O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.38.50/ttinst.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
              O18 - Protocol: bw+0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw+0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw-0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw-0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw00 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw00s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw10 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw10s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw20 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw20s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw30 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw30s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw40 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw40s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw50 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw50s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw60 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw60s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw70 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw70s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw80 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw80s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw90 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bw90s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwa0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwa0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwb0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwb0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwc0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwc0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwd0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwd0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwe0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwe0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwf0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwf0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
              O18 - Protocol: bwg0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwg0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwh0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwh0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwi0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwi0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwj0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwj0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwk0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwk0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwl0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwl0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwm0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwm0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwn0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwn0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwo0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwo0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwp0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwp0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwq0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwq0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwr0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwr0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bws0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bws0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwt0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwt0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwu0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwu0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwv0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwv0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bww0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bww0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwx0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwx0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwy0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwy0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwz0 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: bwz0s - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O18 - Protocol: offline-8876480 - {E11B92F2-2C05-42AD-BDE5-120D138B8CF4} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
              O20 - Winlogon Notify: ASWLNDLL - C:\WINDOWS\SYSTEM32\ASWLNDLL.dll
              O20 - Winlogon Notify: sstqp - C:\WINDOWS\system32\sstqp.dll (file missing)
              O23 - Service: AWE 5.1.0 Application Manager (AppMgrService) - AppStream Inc. - C:\Program Files\AppStream\WindowsClient\bin\AppMgrService.exe
              O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\SYSTEM32\Brmfrmps.exe
              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
              O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
              O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
              O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
              O23 - Service: EarthLinkSafeConnectAgent - Unknown owner - C:\Program Files\EarthLink\EarthLink Protection Control Center\Sana\Bin\SanaAgent.exe (file missing)
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
              O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
              O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

              --
              End of file - 27106 bytes

              TriciaM

                Topic Starter


                Beginner

                Re: Virus?
                « Reply #7 on: September 30, 2009, 09:34:12 AM »
                I was never able to complete the Malwarebytes Anti Malware scan.  That was when the shut-down (black screen) occurred. 

                Thanks for the help !

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: Virus?
                « Reply #8 on: September 30, 2009, 09:40:51 AM »
                Hello Tricia.

                Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

                Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

                * XP users Double click on dds to run it.
                * If your antivirus or firewall try to block DDS then please allow it to run.
                * When finished DDS will open two (2) logs.

                1) DDS.txt
                2) Attach.txt

                * Save both logs to your desktop.
                * Please copy and paste the entire contents of both logs in your next reply.

                Note: DDS will instruct you to post the Attach.txt log as an attachment.
                Please just post it as you would any other log by copy and pasting it into the reply.

                TriciaM

                  Topic Starter


                  Beginner

                  Re: Virus?
                  « Reply #9 on: September 30, 2009, 09:49:57 AM »
                  That's funny. (And thank you for the help, by the way.....)  I was just at another thread reading those very instructions....

                  Thanks..and I'll do that now..

                  TriciaM

                    Topic Starter


                    Beginner

                    Re: Virus?
                    « Reply #10 on: September 30, 2009, 09:57:14 AM »
                    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
                    IF REQUESTED, ZIP IT UP & ATTACH IT

                    DDS (Ver_09-09-29.01)

                    Microsoft Windows XP Home Edition
                    Boot Device: \Device\HarddiskVolume2
                    Install Date: 11/29/2004 10:16:53 PM
                    System Uptime: 9/30/2009 11:17:13 AM (0 hours ago)

                    Motherboard: Dell Inc.           |  | 0J3492
                    Processor:               Intel(R) Pentium(R) 4 CPU 3.40GHz | Microprocessor | 3391/800mhz

                    ==== Disk Partitions =========================

                    C: is FIXED (NTFS) - 71 GiB total, 7.518 GiB free.
                    D: is CDROM ()
                    E: is CDROM ()

                    ==== Disabled Device Manager Items =============

                    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
                    Description: 1394 Net Adapter
                    Device ID: V1394\NIC1394\8072EBB4D100
                    Manufacturer: Microsoft
                    Name: 1394 Net Adapter
                    PNP Device ID: V1394\NIC1394\8072EBB4D100
                    Service: NIC1394

                    ==== System Restore Points ===================

                    RP1692: 8/28/2009 11:02:16 AM - System Checkpoint
                    RP1693: 8/28/2009 11:22:14 PM - Software Distribution Service 3.0
                    RP1694: 8/30/2009 12:57:55 AM - Software Distribution Service 3.0
                    RP1695: 8/30/2009 9:13:57 PM - Software Distribution Service 3.0
                    RP1696: 8/31/2009 11:20:17 PM - System Checkpoint
                    RP1697: 9/1/2009 12:01:16 AM - Software Distribution Service 3.0
                    RP1698: 9/1/2009 11:01:15 PM - Software Distribution Service 3.0
                    RP1699: 9/2/2009 3:00:23 AM - Software Distribution Service 3.0
                    RP1700: 9/2/2009 10:43:19 PM - Software Distribution Service 3.0
                    RP1701: 9/3/2009 10:56:53 PM - System Checkpoint
                    RP1702: 9/4/2009 3:00:27 AM - Software Distribution Service 3.0
                    RP1703: 9/5/2009 10:22:18 AM - System Checkpoint
                    RP1704: 9/5/2009 10:13:27 PM - Software Distribution Service 3.0
                    RP1705: 9/6/2009 10:54:17 PM - Software Distribution Service 3.0
                    RP1706: 9/7/2009 11:16:06 PM - System Checkpoint
                    RP1707: 9/8/2009 3:00:35 AM - Software Distribution Service 3.0
                    RP1708: 9/8/2009 10:00:22 PM - Software Distribution Service 3.0
                    RP1709: 9/9/2009 10:48:25 PM - System Checkpoint
                    RP1710: 9/9/2009 11:05:36 PM - Software Distribution Service 3.0
                    RP1711: 9/10/2009 11:14:55 PM - System Checkpoint
                    RP1712: 9/11/2009 3:00:22 AM - Software Distribution Service 3.0
                    RP1713: 9/12/2009 9:33:21 AM - System Checkpoint
                    RP1714: 9/13/2009 1:18:37 AM - Software Distribution Service 3.0
                    RP1715: 9/14/2009 2:28:17 AM - System Checkpoint
                    RP1716: 9/14/2009 3:00:19 AM - Software Distribution Service 3.0
                    RP1717: 9/15/2009 7:09:05 AM - System Checkpoint
                    RP1718: 9/16/2009 1:17:47 AM - Software Distribution Service 3.0
                    RP1719: 9/16/2009 9:28:37 PM - Software Distribution Service 3.0
                    RP1720: 9/17/2009 11:37:17 PM - System Checkpoint
                    RP1721: 9/18/2009 12:36:45 AM - Software Distribution Service 3.0
                    RP1722: 9/19/2009 1:15:52 AM - System Checkpoint
                    RP1723: 9/19/2009 3:00:21 AM - Software Distribution Service 3.0
                    RP1724: 9/20/2009 12:55:37 PM - System Checkpoint
                    RP1725: 9/21/2009 12:11:13 AM - Software Distribution Service 3.0
                    RP1726: 9/21/2009 10:49:13 PM - Software Distribution Service 3.0
                    RP1727: 9/22/2009 10:56:36 PM - Software Distribution Service 3.0
                    RP1728: 9/23/2009 10:37:47 PM - Software Distribution Service 3.0
                    RP1729: 9/24/2009 10:57:59 PM - System Checkpoint
                    RP1730: 9/25/2009 3:00:17 AM - Software Distribution Service 3.0
                    RP1731: 9/26/2009 7:54:34 AM - System Checkpoint
                    RP1732: 9/27/2009 12:05:25 AM - Software Distribution Service 3.0
                    RP1733: 9/27/2009 11:35:52 PM - Software Distribution Service 3.0
                    RP1734: 9/28/2009 11:56:12 PM - Software Distribution Service 3.0
                    RP1735: 9/29/2009 9:29:02 AM - Software Distribution Service 3.0
                    RP1736: 9/29/2009 1:40:25 PM - Software Distribution Service 3.0
                    RP1737: 9/29/2009 10:40:37 PM - Configured Barbie Girls
                    RP1738: 9/29/2009 10:43:04 PM - Removed InstallShield Restore Point
                    RP1739: 9/29/2009 10:47:59 PM - Configured iTunes
                    RP1740: 9/29/2009 10:55:27 PM - Removed Logitech Desktop Messenger
                    RP1741: 9/29/2009 10:59:34 PM - Removed NetZeroInstallers
                    RP1742: 9/29/2009 11:14:49 PM - Removed Windows Live Favorites for Windows Live Toolbar
                    RP1743: 9/29/2009 11:15:15 PM - Removed Windows Live installer
                    RP1744: 9/29/2009 11:16:08 PM - Removed Windows Live Messenger
                    RP1745: 9/29/2009 11:16:55 PM - Removed Windows Live Sign-in Assistant
                    RP1746: 9/29/2009 11:19:29 PM - Removed Windows Live Toolbar
                    RP1747: 9/30/2009 12:54:46 AM - Installed SUPERAntiSpyware Free Edition
                    RP1748: 9/30/2009 3:00:38 AM - Software Distribution Service 3.0
                    RP1749: 9/30/2009 11:05:47 AM - Installed Java(TM) 6 Update 16
                    RP1750: 9/30/2009 11:11:25 AM - Removed Java(TM) 6 Update 7

                    ==== Installed Programs ======================

                    Adobe Flash Player 10 Plugin
                    Adobe Flash Player 9 ActiveX
                    Adobe Photoshop Album 2.0
                    Adobe Reader 7.0.9
                    Adobe Shockwave Player 11
                    AppStream Technology Windows Edition Client
                    ATI Control Panel
                    ATI Display Driver
                    Banctec Service Agreement
                    Broadcom Advanced Control Suite 2
                    Brother MFL-Pro Suite
                    Canon Camera Access Library
                    Canon Camera Support Core Library
                    Canon Camera WIA Driver
                    Canon EOS 5D WIA Driver
                    Canon RAW Image Task for ZoomBrowser EX
                    Canon Utilities CameraWindow
                    Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
                    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
                    Canon Utilities Digital Photo Professional 3.4
                    Canon Utilities EOS Utility
                    Canon Utilities MyCamera
                    Canon Utilities Original Data Security Tools
                    Canon Utilities PhotoStitch
                    Canon Utilities Picture Style Editor
                    Canon Utilities RemoteCapture Task for ZoomBrowser EX
                    Canon Utilities WFT-E1/E2/E3 Utility
                    Canon Utilities ZoomBrowser EX
                    Canon ZoomBrowser EX Memory Card Utility
                    CCleaner (remove only)
                    Compatibility Pack for the 2007 Office system
                    Critical Update for Windows Media Player 11 (KB959772)
                    Deal Info
                    Dell Digital Jukebox Driver
                    Dell Driver Reset Tool
                    Dell Media Experience
                    Dell Networking Guide
                    DellSupport
                    Disney's Toontown Online
                    Disney Toontown Online
                    EarthLink Accelerator
                    EarthLink Common Authentication
                    EarthLink MailBox
                    EarthLink Wireless High Speed
                    Easy-Link internet launch pad
                    Elmore Music Messenger
                    eMedia Guitar Method
                    GearDrvs
                    Get High Speed Internet!
                    Google Chrome
                    Google Earth
                    Google Toolbar for Internet Explorer
                    Google Updater
                    GuitarVision
                    Highlight Viewer (Windows Live Toolbar)
                    HijackThis 2.0.2
                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
                    Hotfix for Windows Internet Explorer 7 (KB947864)
                    Hotfix for Windows Media Format 11 SDK (KB929399)
                    Hotfix for Windows Media Player 11 (KB939683)
                    Hotfix for Windows XP (KB952287)
                    Hotfix for Windows XP (KB954550-v5)
                    Hotfix for Windows XP (KB961118)
                    Hotfix for Windows XP (KB970653-v3)
                    Intel Application Accelerator
                    Intel(R) 537EP V9x DF PCI Modem
                    InterActual Player
                    Internet Explorer Default Page
                    Jasc Paint Shop Photo Album
                    Jasc Paint Shop Pro 8 Dell Edition
                    Java 2 Runtime Environment, SE v1.4.2_03
                    Java(TM) 6 Update 16
                    Kid Pix Deluxe 4
                    Logitech QuickCam Software
                    Macromedia Shockwave Player
                    Malwarebytes' Anti-Malware
                    Map Button (Windows Live Toolbar)
                    Microsoft .NET Framework 1.1
                    Microsoft .NET Framework 1.1 Hotfix (KB928366)
                    Microsoft .NET Framework 2.0 Service Pack 2
                    Microsoft .NET Framework 3.0 Service Pack 2
                    Microsoft .NET Framework 3.5 SP1
                    Microsoft Compression Client Pack 1.0 for Windows XP
                    Microsoft Encarta Encyclopedia Standard 2004
                    Microsoft Internationalized Domain Names Mitigation APIs
                    Microsoft National Language Support Downlevel APIs
                    Microsoft Picture It! Photo Premium 9
                    Microsoft Plus! Digital Media Edition Installer
                    Microsoft Plus! Photo Story 2 LE
                    Microsoft Silverlight
                    Microsoft Streets and Trips 2004
                    Microsoft User-Mode Driver Framework Feature Pack 1.0
                    Microsoft Word 2002
                    Microsoft Works
                    Microsoft Works 2004 Setup Launcher
                    Microsoft Works Suite Add-in for Microsoft Word
                    Microsoft WSE 2.0 SP3 Runtime
                    Microsoft XML Parser
                    Mozilla Firefox (3.0.14)
                    MSXML 4.0 SP2 (KB925672)
                    MSXML 4.0 SP2 (KB927978)
                    MSXML 4.0 SP2 (KB936181)
                    MSXML 4.0 SP2 (KB954430)
                    Musicmatch for Windows Media Player
                    Musicmatch® Jukebox
                    PaperPort
                    PC Tune-Up
                    Pdf995
                    PdfEdit995
                    Picasa 3
                    Protection Control Center
                    QuickTime
                    RealPlayer
                    Redistributed Files
                    Road Runner Install
                    Security Update for CAPICOM (KB931906)
                    Security Update for Step By Step Interactive Training (KB898458)
                    Security Update for Step By Step Interactive Training (KB923723)
                    Security Update for Windows Internet Explorer 7 (KB928090)
                    Security Update for Windows Internet Explorer 7 (KB929969)
                    Security Update for Windows Internet Explorer 7 (KB931768)
                    Security Update for Windows Internet Explorer 7 (KB933566)
                    Security Update for Windows Internet Explorer 7 (KB937143)
                    Security Update for Windows Internet Explorer 7 (KB938127)
                    Security Update for Windows Internet Explorer 7 (KB939653)
                    Security Update for Windows Internet Explorer 7 (KB942615)
                    Security Update for Windows Internet Explorer 7 (KB944533)
                    Security Update for Windows Internet Explorer 7 (KB950759)
                    Security Update for Windows Internet Explorer 7 (KB953838)
                    Security Update for Windows Internet Explorer 7 (KB956390)
                    Security Update for Windows Internet Explorer 7 (KB958215)
                    Security Update for Windows Internet Explorer 7 (KB960714)
                    Security Update for Windows Internet Explorer 7 (KB961260)
                    Security Update for Windows Internet Explorer 7 (KB963027)
                    Security Update for Windows Internet Explorer 7 (KB969897)
                    Security Update for Windows Internet Explorer 8 (KB969897)
                    Security Update for Windows Internet Explorer 8 (KB971961)
                    Security Update for Windows Internet Explorer 8 (KB972260)
                    Security Update for Windows Media Player (KB911564)
                    Security Update for Windows Media Player (KB952069)
                    Security Update for Windows Media Player (KB968816)
                    Security Update for Windows Media Player (KB973540)
                    Security Update for Windows Media Player 10 (KB911565)
                    Security Update for Windows Media Player 10 (KB917734)
                    Security Update for Windows Media Player 10 (KB936782)
                    Security Update for Windows Media Player 11 (KB936782)
                    Security Update for Windows Media Player 11 (KB954154)
                    Security Update for Windows Media Player 6.4 (KB925398)
                    Security Update for Windows XP (KB923561)
                    Security Update for Windows XP (KB923689)
                    Security Update for Windows XP (KB938464-v2)
                    Security Update for Windows XP (KB938464)
                    Security Update for Windows XP (KB941569)
                    Security Update for Windows XP (KB946648)
                    Security Update for Windows XP (KB950760)
                    Security Update for Windows XP (KB950762)
                    Security Update for Windows XP (KB950974)
                    Security Update for Windows XP (KB951066)
                    Security Update for Windows XP (KB951376-v2)
                    Security Update for Windows XP (KB951376)
                    Security Update for Windows XP (KB951698)
                    Security Update for Windows XP (KB951748)
                    Security Update for Windows XP (KB952004)
                    Security Update for Windows XP (KB952954)
                    Security Update for Windows XP (KB953839)
                    Security Update for Windows XP (KB954211)
                    Security Update for Windows XP (KB954459)
                    Security Update for Windows XP (KB954600)
                    Security Update for Windows XP (KB955069)
                    Security Update for Windows XP (KB956391)
                    Security Update for Windows XP (KB956572)
                    Security Update for Windows XP (KB956744)
                    Security Update for Windows XP (KB956802)
                    Security Update for Windows XP (KB956803)
                    Security Update for Windows XP (KB956841)
                    Security Update for Windows XP (KB956844)
                    Security Update for Windows XP (KB957095)
                    Security Update for Windows XP (KB957097)
                    Security Update for Windows XP (KB958644)
                    Security Update for Windows XP (KB958687)
                    Security Update for Windows XP (KB958690)
                    Security Update for Windows XP (KB959426)
                    Security Update for Windows XP (KB960225)
                    Security Update for Windows XP (KB960715)
                    Security Update for Windows XP (KB960803)
                    Security Update for Windows XP (KB960859)
                    Security Update for Windows XP (KB961371)
                    Security Update for Windows XP (KB961373)
                    Security Update for Windows XP (KB961501)
                    Security Update for Windows XP (KB968537)
                    Security Update for Windows XP (KB969898)
                    Security Update for Windows XP (KB970238)
                    Security Update for Windows XP (KB971557)
                    Security Update for Windows XP (KB971633)
                    Security Update for Windows XP (KB971657)
                    Security Update for Windows XP (KB973346)
                    Security Update for Windows XP (KB973354)
                    Security Update for Windows XP (KB973507)
                    Security Update for Windows XP (KB973869)
                    Shockwave
                    Shutterfly Studio
                    Smart Menus (Windows Live Toolbar)
                    Sonic DLA
                    Sonic MyDVD
                    Sonic RecordNow!
                    Sonic Update Manager
                    SoundMAX
                    SUPERAntiSpyware Free Edition
                    Symantec Technical Support Web Controls
                    System Requirements Lab
                    Tarzan Activity Center
                    TaxCut 2004
                    TaxCut Deluxe 2005
                    TaxCut Premium 2006
                    TiVo Desktop
                    TotalAccess Core Applications
                    Uninstall Dual Mode Camera
                    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
                    Update for Windows Internet Explorer 8 (KB971180)
                    Update for Windows XP (KB951072-v2)
                    Update for Windows XP (KB951978)
                    Update for Windows XP (KB955839)
                    Update for Windows XP (KB967715)
                    Update for Windows XP (KB968389)
                    Update for Windows XP (KB973815)
                    VC 9.0 Runtime
                    Virtools 3D Life Player
                    Virtual Earth 3D (Beta)
                    Walmart MP3 Music Downloads
                    WebFldrs XP
                    Whale Communications' Client Components v3.6
                    Windows Genuine Advantage Notifications (KB905474)
                    Windows Genuine Advantage v1.3.0254.0
                    Windows Genuine Advantage Validation Tool (KB892130)
                    Windows Imaging Component
                    Windows Internet Explorer 7
                    Windows Internet Explorer 8
                    Windows Live Toolbar Extension (Windows Live Toolbar)
                    Windows Media Format 11 runtime
                    Windows Media Player 10
                    Windows Media Player 11
                    Windows XP Service Pack 3
                    Yahoo! Toolbar
                    ZoneAlarm Security Suite

                    ==== Event Viewer Messages From Past Week ========

                    9/30/2009 9:45:05 AM, error: System Error [1003]  - Error code 00008086, parameter1 00000000, parameter2 00000000, parameter3 00000000, parameter4 00000000.
                    9/30/2009 8:12:08 AM, error: System Error [1003]  - Error code 1000007e, parameter1 c0000005, parameter2 f778aefa, parameter3 f7d0fba4, parameter4 f7d0f8a0.
                    9/30/2009 8:01:49 AM, error: iaStor [9]  - The device, \Device\Ide\iaStor0, did not respond within the timeout period.
                    9/30/2009 11:51:20 AM, error: Service Control Manager [7016]  - The BrSplService service has reported an invalid current state 0.
                    9/30/2009 10:36:02 AM, error: PlugPlayManager [11]  - The device Root\LEGACY_INVOKER\0000 disappeared from the system without first being prepared for removal.
                    9/29/2009 9:54:47 AM, error: Service Control Manager [7034]  - The TrueVector Internet Monitor service terminated unexpectedly.  It has done this 1 time(s).
                    9/29/2009 9:16:28 PM, error: Service Control Manager [7034]  - The TrueVector Internet Monitor service terminated unexpectedly.  It has done this 8 time(s).
                    9/29/2009 7:38:44 PM, error: Service Control Manager [7034]  - The TrueVector Internet Monitor service terminated unexpectedly.  It has done this 7 time(s).
                    9/29/2009 2:05:30 PM, error: Service Control Manager [7034]  - The TrueVector Internet Monitor service terminated unexpectedly.  It has done this 6 time(s).
                    9/29/2009 12:55:20 PM, error: Service Control Manager [7034]  - The TrueVector Internet Monitor service terminated unexpectedly.  It has done this 4 time(s).
                    9/29/2009 12:18:06 PM, error: Service Control Manager [7034]  - The TrueVector Internet Monitor service terminated unexpectedly.  It has done this 3 time(s).
                    9/29/2009 11:57:42 AM, error: Service Control Manager [7034]  - The TrueVector Internet Monitor service terminated unexpectedly.  It has done this 2 time(s).
                    9/29/2009 11:27:38 PM, error: Service Control Manager [7034]  - The TrueVector Internet Monitor service terminated unexpectedly.  It has done this 9 time(s).
                    9/29/2009 11:15:23 PM, error: Service Control Manager [7023]  - The Application Management service terminated with the following error:  The specified module could not be found.
                    9/29/2009 1:14:25 PM, error: Service Control Manager [7034]  - The TrueVector Internet Monitor service terminated unexpectedly.  It has done this 5 time(s).

                    ==== End Of File ===========================

                    TriciaM

                      Topic Starter


                      Beginner

                      Re: Virus?
                      « Reply #11 on: September 30, 2009, 09:58:13 AM »
                      DDS (Ver_09-09-29.01) - NTFSx86 
                      Run by Tricia & Roger at 11:51:15.90 on Wed 09/30/2009
                      Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
                      Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1022.454 [GMT -4:00]

                      AV: Authentium Antivirus *On-access scanning enabled* (Updated)   {A4E803B3-4E6E-4271-B1CD-56FBC0992D36}
                      AV: ZoneAlarm Security Suite Antivirus *On-access scanning enabled* (Updated)   {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
                      FW: ZoneAlarm Security Suite Firewall *enabled*   {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

                      ============== Running Processes ===============

                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost -k DcomLaunch
                      svchost.exe
                      C:\WINDOWS\System32\svchost.exe -k netsvcs
                      C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
                      svchost.exe
                      svchost.exe
                      C:\WINDOWS\system32\brsvc01a.exe
                      C:\WINDOWS\system32\brss01a.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      svchost.exe
                      C:\WINDOWS\SYSTEM32\Brmfrmps.exe
                      C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
                      C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\WINDOWS\system32\svchost.exe -k imgsvc
                      C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
                      C:\Program Files\AppStream\WindowsClient\bin\AppMgrService.exe
                      C:\Program Files\Canon\CAL\CALMAIN.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                      C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
                      C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
                      C:\Program Files\Dell\Media Experience\PCMService.exe
                      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
                      C:\WINDOWS\system32\dla\tfswctrl.exe
                      C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
                      C:\Program Files\Logitech\Video\CameraAssistant.exe
                      C:\WINDOWS\system32\ElkCtrl.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
                      C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                      C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
                      C:\Program Files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe
                      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                      C:\Program Files\AppStream\WindowsClient\Bin\AppMgrGui.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
                      C:\Program Files\TiVo\Desktop\TiVoNotify.exe
                      C:\Program Files\TiVo\Desktop\TiVoServer.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Documents and Settings\Tricia & Roger\Desktop\dds.com

                      ============== Pseudo HJT Report ===============

                      uStart Page = hxxp://www.rr.com/
                      uDefault_Page_URL = hxxp://start.earthlink.net
                      uSearch Bar = hxxp://start.earthlink.net/AL/Search
                      uDefault_Search_URL = hxxp://www.earthlink.net/partner/more/msie/button/search.html
                      uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex}&startPage={startPage}
                      uWindow Title = Road Runner High Speed Online
                      mSearchAssistant = hxxp://start.earthlink.net/AL/Search
                      uURLSearchHooks: SrchHook Class: {44f9b173-041c-4825-a9b9-d914bd9dcbb3} - c:\program files\earthlink totalaccess\elnIE.dll
                      uURLSearchHooks: H - No File
                      uURLSearchHooks: H - No File
                      BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
                      BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
                      BHO: {656ec4b7-072b-4698-b504-2a414c1f0037} - IE_PopupBlocker Class
                      BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
                      BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
                      BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
                      BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
                      BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
                      BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                      TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
                      TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
                      TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
                      TB: JunoBar: {5854fac4-5bf0-47dd-b5a9-a5ea8cff3cf4} - c:\program files\juno\Toolbar.dll
                      TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
                      TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
                      TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
                      EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
                      uRun: [LogitechSoftwareUpdate] "c:\program files\logitech\video\ManifestEngine.exe" boot
                      uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
                      uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
                      uRun: [TivoTransfer] "c:\program files\common files\tivo shared\transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
                      uRun: [TivoNotify] "c:\program files\tivo\desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
                      uRun: [TivoServer] "c:\program files\tivo\desktop\TiVoServer.exe" /service /registry /auto:TivoServer
                      uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                      uRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe
                      uRun: [Google Update] "c:\documents and settings\tricia & roger\local settings\application data\google\update\GoogleUpdate.exe" /c
                      uRun: [E6TaskPanel] "c:\program files\earthlink totalaccess\TaskPanl.exe" -winstart
                      mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
                      mRun: [IAAnotif] c:\program files\intel\intel application accelerator\iaanotif.exe
                      mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
                      mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
                      mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
                      mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
                      mRun: [MMTray] "c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe"
                      mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
                      mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
                      mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
                      mRun: [MimBoot] c:\progra~1\musicm~1\musicm~2\mimboot.exe
                      mRun: [LogitechCameraAssistant] c:\program files\logitech\video\CameraAssistant.exe
                      mRun: [LogitechVideo[inspector]] c:\program files\logitech\video\InstallHelper.exe /inspect
                      mRun: [LogitechCameraService(E)] c:\windows\system32\ElkCtrl.exe /automation
                      mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
                      mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
                      mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
                      mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
                      mRun: [SetDefPrt] c:\program files\brother\brmfl04a\BrStDvPt.exe
                      mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun
                      mRun: [AppMgrGui] c:\program files\appstream\windowsclient\bin\exeForService.exe
                      mRun: [Elmore Music Messenger] c:\windows\Elmore Music Messenger.exe
                      mRun: [eligmini] c:\program files\fisher-price\easy-link internet launch pad\Easy-Link internet launch pad.exe 0
                      mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
                      mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
                      dRunOnce: [TBInfo] iexplore.exe "http://www.earthlink.net/go/elnktoolbarinstall"
                      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
                      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
                      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
                      StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\status~1.lnk - c:\program files\brother\brmfcmon\BrMfcWnd.exe
                      uPolicies-system: DisableTaskMgr = 1 (0x1)
                      IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
                      IE: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
                      IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
                      IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
                      IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
                      IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
                      LSP: c:\program files\earthlink totalaccess\accelerator\prplsf.dll
                      Trusted Zone: broderbund.com\support
                      Trusted Zone: mypublisher.com\www
                      Trusted Zone: riverdeep.net\smartdownload
                      Trusted Zone: uspsoig.gov\portal2003
                      Trusted Zone: musicmatch.com\online
                      DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
                      DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://activation.rr.com/install/downloads/tgctlcm.cab
                      DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/7/0/7/707a44ad-52ad-49af-b7ef-e21b6b0656e4/VirtualEarth3D.cab
                      DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?LinkID=39204
                      DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.costcophotocenter.com/CostcoActivia.cab
                      DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
                      DPF: {5DA9D8E0-5A57-11CF-9E36-00C0930198C0} - hxxp://www.ansonncrod.org/imw32o40.cab
                      DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
                      DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136246925750
                      DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} - hxxp://vsp.closetmaid.com/vsp/cmaidctl_vsp.closetmaid.com_downloader.cab
                      DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
                      DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} - hxxps://portal.uspsoig.gov/InternalSite/WhlCompMgr.cab
                      DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
                      DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
                      DPF: {9841D1AE-9C0B-11D3-9452-00105A098C21} - hxxp://www.ansonncrod.org/prntpro2.CAB
                      DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                      DPF: {B49C4597-8721-4789-9250-315DFBD9F525} - hxxp://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
                      DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - hxxp://a.download.toontown.com/sv1.0.38.50/ttinst.cab
                      DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
                      DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
                      DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
                      DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
                      Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
                      Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
                      Notify: ASWLNDLL - ASWLNDLL.dll
                      Notify: sstqp - c:\windows\system32\sstqp.dll
                      SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
                      SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

                      ================= FIREFOX ===================

                      FF - ProfilePath - c:\docume~1\tricia~1\applic~1\mozilla\firefox\profiles\10loo8z7.default\
                      FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
                      FF - plugin: c:\documents and settings\tricia & roger\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
                      FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
                      FF - plugin: c:\program files\google\picasa3\npPicasa2.dll
                      FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
                      FF - plugin: c:\program files\mozilla firefox\plugins\npvirtools.dll
                      FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
                      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
                      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
                      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
                      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
                      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
                      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
                      FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

                      ---- FIREFOX POLICIES ----
                      FF - user.js: yahoo.homepage.dontask - true
                      ============= SERVICES / DRIVERS ===============

                      R1 APPSTREAM;APPSTREAM;c:\windows\system32\drivers\AppStream.sys [2007-5-13 115284]
                      R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2009-4-14 150544]
                      R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-9-15 9968]
                      R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-9-15 74480]
                      R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-9-29 353672]
                      R2 AppMgrService;AWE 5.1.0 Application Manager;c:\program files\appstream\windowsclient\bin\AppMgrService.exe [2006-9-27 1990656]
                      R2 EarthLinkMonitor;EarthLink Monitor Service;c:\program files\earthlink totalaccess\wengine\wmonitor.exe [2005-1-26 65604]
                      R2 REGHOOK;REGHOOK;c:\windows\system32\drivers\RegHook.sys [2006-9-27 54879]
                      R2 TivoBeacon2;TiVo Beacon;c:\program files\common files\tivo shared\beacon\TiVoBeacon.exe [2006-7-11 857088]
                      R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
                      R2 VSPD;VSPD;c:\windows\system32\drivers\VSPD.sys [2006-9-27 31321]
                      S3 ADSFilter;ADSFilter - (Aluria Filter Driver);c:\windows\system32\drivers\ADSFilter.sys [2007-8-3 57456]
                      S3 ADSMonitor;ADSMonitor - (EarthLink Monitor Driver);c:\windows\system32\drivers\ADSMonitor.sys [2007-8-3 38384]
                      S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\BW2NDIS5.SYS [2004-11-1 17536]
                      S3 EarthLinkSafeConnectDriver;EarthLinkSafeConnectDriver;\??\c:\program files\earthlink\earthlink protection control center\sana\driver\platform_xp\safeconnectdriver.sys --> c:\program files\earthlink\earthlink protection control center\sana\driver\platform_xp\SafeConnectDriver.sys [?]
                      S3 EarthLinkSafeConnectFilter;EarthLinkSafeConnectFilter;\??\c:\program files\earthlink\earthlink protection control center\sana\driver\platform_xp\safeconnectfilter.sys --> c:\program files\earthlink\earthlink protection control center\sana\driver\platform_xp\SafeConnectFilter.sys [?]
                      S3 EarthLinkSafeConnectShim;EarthLinkSafeConnectShim;\??\c:\program files\earthlink\earthlink protection control center\sana\driver\platform_xp\safeconnectshim.sys --> c:\program files\earthlink\earthlink protection control center\sana\driver\platform_xp\SafeConnectShim.sys [?]
                      S3 JL2005C;Dual Mode Camera;c:\windows\system32\drivers\jl2005c.sys [2007-3-24 62762]
                      S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-9-15 7408]
                      S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-9-28 1174664]

                      =============== Created Last 30 ================

                      2009-09-30 11:24   <DIR>   --d-----   c:\program files\Trend Micro
                      2009-09-30 11:13   272   a-------   c:\windows\_delis32.ini
                      2009-09-30 10:54   <DIR>   --d-----   c:\program files\SystemRequirementsLab
                      2009-09-30 10:36   294,912   a-------   c:\windows\system32\FlexEng.dll
                      2009-09-30 10:07   53,248   a-------   c:\windows\system32\CSVer.dll
                      2009-09-30 09:59   <DIR>   --d-----   C:\Intel
                      2009-09-30 08:00   <DIR>   --d-----   c:\docume~1\tricia~1\applic~1\Malwarebytes
                      2009-09-30 08:00   38,224   a-------   c:\windows\system32\drivers\mbamswissarmy.sys
                      2009-09-30 08:00   19,160   a-------   c:\windows\system32\drivers\mbam.sys
                      2009-09-30 08:00   <DIR>   --d-----   c:\docume~1\alluse~1\applic~1\Malwarebytes
                      2009-09-30 08:00   <DIR>   --d-----   c:\program files\Malwarebytes' Anti-Malware
                      2009-09-30 00:55   <DIR>   --d-----   c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
                      2009-09-30 00:54   <DIR>   --d-----   c:\program files\SUPERAntiSpyware
                      2009-09-30 00:54   <DIR>   --d-----   c:\docume~1\tricia~1\applic~1\SUPERAntiSpyware.com
                      2009-09-29 23:41   <DIR>   --d-----   c:\program files\CCleaner
                      2009-09-09 21:57   153,088   --------   c:\windows\system32\dllcache\triedit.dll

                      ==================== Find3M  ====================

                      2009-09-30 11:51   1,347,926,304   a--sh---   c:\windows\system32\drivers\fidbox.dat
                      2009-09-30 11:17   18,051,452   a--sh---   c:\windows\system32\drivers\fidbox.idx
                      2009-09-29 18:53   36,412   a-------   c:\docume~1\tricia~1\applic~1\wklnhst.dat
                      2009-09-20 22:00   80,720   a-------   c:\docume~1\tricia~1\applic~1\GDIPFONTCACHEV1.DAT
                      2009-09-15 06:49   4,212   a---h---   c:\windows\system32\zllictbl.dat
                      2009-08-05 05:01   204,800   a-------   c:\windows\system32\mswebdvd.dll
                      2009-08-05 05:01   204,800   --------   c:\windows\system32\dllcache\mswebdvd.dll
                      2009-07-31 15:23   411,368   a-------   c:\windows\system32\deploytk.dll
                      2009-07-19 18:48   11,067,392   --------   c:\windows\system32\dllcache\ieframe.dll
                      2009-07-19 09:18   5,937,152   --------   c:\windows\system32\dllcache\mshtml.dll
                      2009-07-17 15:01   58,880   a-------   c:\windows\system32\atl.dll
                      2009-07-17 15:01   58,880   --------   c:\windows\system32\dllcache\atl.dll
                      2009-07-13 23:43   286,208   a-------   c:\windows\system32\wmpdxm.dll
                      2009-07-13 23:43   286,208   a-------   c:\windows\system32\dllcache\wmpdxm.dll
                      2009-07-13 23:43   10,841,088   --------   c:\windows\system32\dllcache\wmp.dll
                      2009-07-10 09:27   1,315,328   --------   c:\windows\system32\dllcache\msoe.dll
                      2009-07-03 13:09   915,456   a-------   c:\windows\system32\wininet.dll
                      2009-07-03 13:09   915,456   --------   c:\windows\system32\dllcache\wininet.dll
                      2009-07-03 13:09   12,800   --------   c:\windows\system32\dllcache\xpshims.dll
                      2009-07-03 13:09   206,848   a-------   c:\windows\system32\dllcache\occache.dll
                      2009-07-03 13:09   1,208,832   --------   c:\windows\system32\dllcache\urlmon.dll
                      2009-07-03 13:09   594,432   a-------   c:\windows\system32\dllcache\msfeeds.dll
                      2009-07-03 13:09   55,296   a-------   c:\windows\system32\dllcache\msfeedsbs.dll
                      2009-07-03 13:09   1,985,536   --------   c:\windows\system32\dllcache\iertutil.dll
                      2009-07-03 13:09   25,600   --------   c:\windows\system32\dllcache\jsproxy.dll
                      2009-07-03 13:09   184,320   a-------   c:\windows\system32\dllcache\iepeers.dll
                      2009-07-03 13:09   246,272   --------   c:\windows\system32\dllcache\ieproxy.dll
                      2009-07-03 13:09   386,048   --------   c:\windows\system32\dllcache\iedkcs32.dll
                      2009-07-03 07:01   173,056   --------   c:\windows\system32\dllcache\ie4uinit.exe
                      2008-10-08 16:30   32,768   ac-sh---   c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100820081009\index.dat
                      2009-09-30 11:52   1,347,933,472   a--sh---   c:\windows\system32\drivers\fidbox.dat

                      ============= FINISH: 11:52:44.90 ===============

                      TriciaM

                        Topic Starter


                        Beginner

                        Re: Virus?
                        « Reply #12 on: September 30, 2009, 01:20:35 PM »
                        Ok. I tried the Malwarebytes' scan again. This time, it completed the scan with no problems.  Here is the log.  Also, do you know what the story is on "Authentium Anti-Virus" is ?  At one point, there was a pop up that I was running two different anti virus real time scans/protection.   We use Zone Alarm.

                        Malwarebytes' Anti-Malware 1.41
                        Database version: 2876
                        Windows 5.1.2600 Service Pack 3

                        9/30/2009 3:15:41 PM
                        mbam-log-2009-09-30 (15-15-35).txt

                        Scan type: Quick Scan
                        Objects scanned: 99416
                        Time elapsed: 1 hour(s), 24 minute(s), 46 second(s)

                        Memory Processes Infected: 0
                        Memory Modules Infected: 0
                        Registry Keys Infected: 11
                        Registry Values Infected: 0
                        Registry Data Items Infected: 2
                        Folders Infected: 1
                        Files Infected: 3

                        Memory Processes Infected:
                        (No malicious items detected)

                        Memory Modules Infected:
                        (No malicious items detected)

                        Registry Keys Infected:
                        HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> No action taken.
                        HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> No action taken.
                        HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> No action taken.
                        HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> No action taken.
                        HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> No action taken.
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> No action taken.
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> No action taken.
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\CAC (Malware.Trace) -> No action taken.
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> No action taken.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> No action taken.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> No action taken.

                        Registry Values Infected:
                        (No malicious items detected)

                        Registry Data Items Infected:
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

                        Folders Infected:
                        C:\WINDOWS\SYSTEM32\f02WtR (Malware.Trace) -> No action taken.

                        Files Infected:
                        C:\WINDOWS\SYSTEM32\ClickToFindandFixErrors_US.ico (Malware.Trace) -> No action taken.
                        C:\WINDOWS\SYSTEM32\mcrh.tmp (Malware.Trace) -> No action taken.
                        C:\WINDOWS\cookies.ini (Malware.Trace) -> No action taken.

                        evilfantasy

                        • Malware Removal Specialist
                        • Moderator


                        • Genius
                        • Calm like a bomb
                        • Thanked: 493
                        • Experience: Experienced
                        • OS: Windows 11
                        Re: Virus?
                        « Reply #13 on: September 30, 2009, 04:44:54 PM »
                        http://www.authentium.com/mainv2/index.htm - Is a trusted software vendor. Someone must have installed it at some point and I di see it running but I don't see it installed. We will look for it and try to get it removed later.

                        The Malwarebytes log says No action taken after everything. Did you let MBAM fix everything after copying the log?

                        Please go to Add or Remove Programs and uninstall:

                        .
                        ----------

                        Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

                        Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

                        Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

                        Exit out of MessengerDisable then delete the two files that were put on the desktop.

                        ----------

                        If you already have ComboFix be sure to delete it and download a new copy.

                        Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

                        Link #1
                        Link #2

                        **Note:  It is important that it is saved directly to your Desktop

                        DO NOT run it yet!

                        Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

                        Delete these files/folders, as follows:

                        1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
                        It must be Notepad, not Wordpad.
                        2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

                        Code: [Select]
                        KillAll::

                        Driver::
                        Symantec Core LC

                        File::
                        c:\windows\_delis32.ini

                        DDS::
                        uURLSearchHooks: H - No File
                        uURLSearchHooks: H - No File
                        TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
                        TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
                        TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
                        TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
                        uPolicies-system: DisableTaskMgr = 1 (0x1)
                        Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
                        Notify: sstqp - c:\windows\system32\sstqp.dll


                        3. Go to the Notepad window and click Edit > Paste
                        4. Then click File > Save
                        5. Name the file CFScript.txt - Save the file to your Desktop
                        6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



                        ComboFix will begin to execute, just follow the prompts.
                        After reboot (in case it asks to reboot), it will produce a log for you.
                        Post that log (Combofix.txt) in your next reply.

                        Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

                        TriciaM

                          Topic Starter


                          Beginner

                          Re: Virus?
                          « Reply #14 on: September 30, 2009, 09:44:49 PM »
                          I am at a standstill..after about 3 hrs of trying to install Adobe Reader (my system tells me the install abruptly shut down, but doesn't give reason...). I feel like I've run in circles.  Anyway, I went on to try to run Combofix. It stops, gives me a warning about running two anti-virus programs...tells me to shut them off. I turned off one. The other is the Authentium, which I have not downloaded knowingly.  It probably was "attached" to something else, just like McAfee tried to download itself when I downloaded some Adobe about an hour ago (McAfee was checked with the checkmark, and if you didn't see it, you would have downloaded it unknowingly right along with your Adobe update....). Well.....My virus protection is off....I can't cancel out Combofix or else it will start running again (and could damage my computer, according to the warning that is on my screen).  So....I think I'll just give up now ? LOL