I did all the read this first here are the logs:
Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download
Database version: 8040
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
10/29/2011 7:04:53 AM
mbam-log-2011-10-29 (07-04-53).txt
Scan type: Quick scan
Objects scanned: 156818
Time elapsed: 6 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Explorer\Advanced\StartMenuLogoff (PUM.Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15641 - GMER - Rootkit Detector and Remover
Rootkit scan 2011-11-20 09:43:49
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 FUJITSU_MHV2080AH rev.00830096
Running: 6ioq7uc9.exe; Driver: C:\DOCUME~1\MARGAR~1\LOCALS~1\Temp\kxtcipog.sys
---- System - GMER 1.0.15 ----
SSDT 827428B0 ZwAlertResumeThread
SSDT 82742970 ZwAlertThread
SSDT 82759250 ZwAllocateVirtualMemory
SSDT 82754610 ZwAssignProcessToJobObject
SSDT 82756C80 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xEF8E2130]
SSDT 828573A0 ZwCreateMutant
SSDT 82788B30 ZwCreateSymbolicLinkObject
SSDT 82735888 ZwCreateThread
SSDT 827546D0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xEF8E23B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xEF8E2910]
SSDT 8276ED00 ZwDuplicateObject
SSDT 82744980 ZwFreeVirtualMemory
SSDT 8279A328 ZwImpersonateAnonymousToken
SSDT 82742830 ZwImpersonateThread
SSDT 827906E0 ZwLoadDriver
SSDT 8284DC78 ZwMapViewOfSection
SSDT 828572E0 ZwOpenEvent
SSDT 82754438 ZwOpenProcess
SSDT 82759320 ZwOpenProcessToken
SSDT 8278BAA0 ZwOpenSection
SSDT 82762DB0 ZwOpenThread
SSDT 82788C00 ZwProtectVirtualMemory
SSDT 826966C8 ZwResumeThread
SSDT 8273A208 ZwSetContextThread
SSDT 8284DB68 ZwSetInformationProcess
SSDT 8278B998 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xEF8E2B60]
SSDT 8275E290 ZwSuspendProcess
SSDT 82753480 ZwSuspendThread
SSDT 82757C68 ZwTerminateProcess
SSDT 827465E8 ZwTerminateThread
SSDT 82759218 ZwUnmapViewOfSection
SSDT 8273A288 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
? SYMEFA.SYS The system cannot find the file specified. !
init C:\WINDOWS\system32\drivers\tifm21.sys entry point in "init" section [0xF7E3FEBF]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\SearchIndexer.exe[876] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-20 10:04:28
-----------------------------
10:04:28.031 OS Version: Windows 5.1.2600 Service Pack 3
10:04:28.031 Number of processors: 1 586 0x2402
10:04:28.031 ComputerName: MADOFFICE UserName:
10:04:33.421 Initialize success
10:04:53.890 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
10:04:53.890 Disk 0 Vendor: FUJITSU_MHV2080AH 00830096 Size: 76319MB BusType: 3
10:04:55.921 Disk 0 MBR read successfully
10:04:55.921 Disk 0 MBR scan
10:04:55.937 Disk 0 unknown MBR code
10:04:55.968 Disk 0 scanning sectors +156296385
10:04:56.062 Disk 0 scanning C:\WINDOWS\system32\drivers
10:05:11.187 Service scanning
10:05:13.406 Modules scanning
10:05:38.218 Disk 0 trace - called modules:
10:05:38.265 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
10:05:38.281 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82b471f0]
10:05:38.296 3 CLASSPNP.SYS[f8547fd7] -> nt!IofCallDriver -> \Device\0000007d[0x82b8b9e8]
10:05:38.312 5 ACPI.sys[f83be620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82b8bd98]
10:05:38.890 Scan finished successfully
10:05:58.937 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Margarita Medina\Desktop\MBR.dat"
10:05:58.968 The log file has been saved successfully to "C:\Documents and Settings\Margarita Medina\Desktop\aswMBR.txt"
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Run by Margarita Medina at 10:07:49 on 2011-11-20
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.147 [GMT -8:00]
.
AV: Norton Security Suite *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Security Suite\Engine\3.8.3.6\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Security Suite\Engine\3.8.3.6\ccSvcHst.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIG YA.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.comcast.net/
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavi lion&pf=laptop
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\3.8.3.6\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\3.8.3.6\IPSBHO.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\3.8.3.6\coIEPlg.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Artisan 720(Network)] c:\windows\system32\spool\drivers\w32x86\3\e_fatig ya.exe /fu "c:\windows\temp\E_SC5.tmp" /EF "HKCU"
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start
mRun: [RecGuard] c:\windows\sminst\RecGuard.exe
mRun: [DeleteLog] c:\windows\system32\oobe\DeleteLog.exe
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
StartupFolder: c:\docume~1\margar~1\startm~1\programs\startup\eps ona~1.lnk - c:\documents and settings\margarita medina\local settings\temp\wzse0.tmp\common\epsonreg\EpsonReg.e xe
StartupFolder: c:\docume~1\margar~1\startm~1\programs\startup\wkc alrem.lnk - c:\program files\common files\microsoft shared\works shared\WkCalRem.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpp hot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\win dow~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{95453000-0D94-4E0D-922E-829E38A2D2CA} : DhcpNameServer = 192.168.0.1
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton security suite\engine\3.8.3.6\CoIEPlg.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\margarita medina\application data\mozilla\firefox\profiles\ult6ca1t.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn. dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl. dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\030803 0.006\SymEFA.sys [2011-10-31 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308030.00 6\BHDrvx86.sys [2011-10-31 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308030. 006\cchpx86.sys [2011-10-31 467592]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20111118. 030\IDSXpx86.sys [2011-11-19 356280]
R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\3.8.3.6\ccSvcHst.exe [2011-10-31 117648]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-11-9 106104]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFH WATI.sys [2005-8-22 231424]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\2011111 9.016\naveng.sys [2011-11-19 86136]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\2011111 9.016\navex15.sys [2011-11-19 1576312]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys --> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\dr ivers\mbam.sys [2010-8-21 22216]
S4 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-8-21 366152]
.
=============== Created Last 30 ================
.
2011-11-19 19:47:08 77824 ----a-w- c:\windows\system32\EBAPI.dll
2011-11-19 19:47:08 65536 ----a-w- c:\windows\system32\EEBUtil.dll
2011-11-19 19:47:08 55808 ----a-w- c:\windows\system32\EEBSDKIF.dll
2011-11-19 19:47:08 135168 ----a-w- c:\windows\system32\EEBAPI.dll
2011-11-19 19:47:08 110592 ----a-w- c:\windows\system32\EEBDSCVR.dll
2011-11-19 19:44:20 475410 ----a-w- c:\windows\system32\ensppmon.dll
2011-11-19 19:44:20 475410 ----a-w- c:\windows\system32\enppmon.dll
2011-11-19 19:44:20 458129 ----a-w- c:\windows\system32\ensppui.dll
2011-11-19 19:44:20 458129 ----a-w- c:\windows\system32\enppui.dll
2011-11-19 19:44:20 249344 ----a-w- c:\windows\system32\enspres.dll
2011-11-19 19:44:20 249344 ----a-w- c:\windows\system32\enpres.dll
2011-11-19 19:44:19 -------- d-----w- c:\program files\EpsonNet
2011-11-19 19:43:55 -------- d-----w- c:\program files\common files\EPSON
2011-11-19 19:43:04 93696 ----a-w- c:\windows\system32\E_FLBGYA.DLL
2011-11-19 19:43:04 63488 ----a-w- c:\windows\system32\E_FD4BGYA.DLL
2011-11-19 19:41:39 -------- d-----w- c:\documents and settings\all users\application data\EPSON
2011-11-19 19:40:33 -------- d-----w- c:\program files\Epson Software
2011-11-19 19:38:29 132560 ----a-w- c:\windows\system32\esdevapp.exe
2011-11-19 19:38:29 12800 ----a-w- c:\windows\system32\escdev.dll
2011-11-19 19:38:28 342016 ----a-w- c:\windows\system32\eswiaud.dll
2011-11-19 19:38:21 -------- d-----w- c:\program files\epson
2011-11-13 17:57:56 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-11-12 15:28:00 215920 ----a-w- c:\windows\system32\muweb.dll
2011-11-12 15:28:00 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2011-11-12 15:27:59 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-11-11 22:41:49 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-11 22:01:01 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-11-11 22:01:00 89048 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-11-11 22:01:00 801752 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-11-11 22:01:00 719832 ----a-w- c:\program files\mozilla firefox\mozcpp19.dll
2011-11-11 22:01:00 478168 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-11-11 22:01:00 2106216 ----a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2011-11-11 22:01:00 1998168 ----a-w- c:\program files\mozilla firefox\d3dx9_43.dll
2011-11-11 22:01:00 1989592 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-11-11 22:01:00 16856 ----a-w- c:\program files\mozilla firefox\plugin-container.exe
2011-11-11 22:01:00 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-11-07 03:31:41 -------- d-----w- c:\program files\MSECache
2011-11-03 14:59:54 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2011-10-31 21:11:02 48760 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symnd isv.sys
2011-10-31 21:11:02 217464 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symtd i.sys
2011-10-31 21:11:01 89976 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symfw .sys
2011-10-31 21:11:01 43696 ----a-w- c:\windows\system32\drivers\n360\0308030.006\srtsp x.sys
2011-10-31 21:11:01 36472 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symnd is.sys
2011-10-31 21:11:01 33144 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symid s.sys
2011-10-31 21:11:01 310320 ----a-w- c:\windows\system32\drivers\n360\0308030.006\SymEF A.sys
2011-10-31 21:11:01 308272 ----a-w- c:\windows\system32\drivers\n360\0308030.006\srtsp .sys
2011-10-31 21:11:00 467592 ----a-w- c:\windows\system32\drivers\n360\0308030.006\cchpx 86.sys
2011-10-31 21:11:00 259632 ----a-w- c:\windows\system32\drivers\n360\0308030.006\BHDrv x86.sys
2011-10-31 21:10:04 -------- d-----w- c:\windows\system32\drivers\n360\0308030.006
.
==================== Find3M ====================
.
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20:51 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-01 00:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 23:48:55 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48:54 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48:54 1469440 ------w- c:\windows\system32\inetcpl.cpl
.
============= FINISH: 10:09:24.73 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 8/21/2007 3:06:33 PM
System Uptime: 11/20/2011 9:46:49 AM (1 hours ago)
.
Motherboard: Hewlett-Packard | | 309B
Processor: AMD Turion(tm) 64 Mobile Technology ML-32 | U23 | 1575/mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 66 GiB total, 42.36 GiB free.
D: is FIXED (FAT32) - 8 GiB total, 0.518 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP129: 9/4/2011 6:22:29 PM - Removed SUPERAntiSpyware Free Edition
RP130: 9/4/2011 7:15:44 PM - Software Distribution Service 3.0
RP131: 9/6/2011 10:11:21 AM - System Checkpoint
RP132: 9/10/2011 7:39:30 AM - Software Distribution Service 3.0
RP133: 9/24/2011 7:42:20 AM - Software Distribution Service 3.0
RP134: 9/25/2011 10:05:43 AM - System Checkpoint
RP135: 10/2/2011 1:29:12 PM - Software Distribution Service 3.0
RP136: 10/13/2011 6:50:46 AM - Software Distribution Service 3.0
RP137: 10/16/2011 4:18:37 PM - Software Distribution Service 3.0
RP138: 10/19/2011 6:27:49 AM - Software Distribution Service 3.0
RP139: 10/29/2011 6:27:01 AM - Software Distribution Service 3.0
RP140: 11/6/2011 7:32:21 PM - Installed Microsoft Office PowerPoint Viewer 2007 (English)
RP141: 11/10/2011 8:50:51 AM - Software Distribution Service 3.0
RP142: 11/11/2011 1:06:38 PM - Software Distribution Service 3.0
RP143: 11/13/2011 9:57:23 AM - Software Distribution Service 3.0
RP144: 11/13/2011 10:43:17 AM - Software Distribution Service 3.0
RP145: 11/19/2011 11:40:22 AM - Installed Epson Event Manager
RP146: 11/19/2011 11:44:18 AM - Installed EpsonNet Print
RP147: 11/19/2011 11:44:53 AM - Installed EpsonNet Setup 3.3
.
==== Installed Programs ======================
.
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 7.0
Adobe Shockwave Player 11.5
Athlon 64 Processor Driver
ATI Control Panel
ATI Display Driver
BadCopy Pro
BufferChm
CCleaner
Conexant AC-Link Audio
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CueTour
Customer Experience Enhancement
Destinations
DeviceManagementQFolder
DVD Decrypter (Remove Only)
DVD Shrink 3.2
EPSON Artisan 720 Series Printer Uninstall
Epson Event Manager
EPSON Scan
EpsonNet Print
EpsonNet Setup 3.3
FullDPAppQFolder
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Help and Support
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Product Detection
HP QuickPlay 2.0
HP Rhapsody
HP Update
HP User Guides--System Recovery
HP User Guides 0026
HP Wireless Assistant 2.00 C1
HpSdpAppCoreApp
InstantShareAlert
InstantShareDevices
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 17
Java(TM) 6 Update 2
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
LightScribe 1.4.56.1
Malwarebytes' Anti-Malware version 1.51.2.1300
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2572067)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2006
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works
Mozilla Firefox 8.0 (x86 en-US)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
muvee autoProducer 4.5
Netscape Browser (remove only)
NetWaiting
Norton Security Suite
Office 2003 Trial Assistant
OptionalContentQFolder
PhotoGallery
Quick Launch Buttons 5.20 F2
RandMap
RealPlayer Basic
REALTEK Gigabit and Fast Ethernet NIC Driver
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Windows (KB2564958)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165-v2)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
SkinsHP1
Soft Data Fax Modem with SmartCP
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
Sonic_PrimoSDK
Spelling Dictionaries For Adobe Reader Package
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
TIPCI
TourSetup
Unload
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows Internet Explorer 8 (KB982664)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2492386)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2607712)
Update for Windows XP (KB2616676-v2)
Update for Windows XP (KB2641690)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player (Remove Only)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
Wireless Home Network Setup
.
==== Event Viewer Messages From Past Week ========
.
11/19/2011 10:24:41 AM, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/19/2011 10:24:34 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
11/14/2011 8:10:15 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd
11/13/2011 946 AM, error: NetBT [4307] - Initialization failed because the transport refused to open initial Addresses.
11/13/2011 10:04:43 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000000D' while processing the file 'BOOT.INI' on the volume 'HarddiskVolume3'. It has stopped monitoring the volume.
.
==== End Of File ===========================
Please, observe following rules:
- Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
- If you're stuck, or you're not sure about certain step, always ask before doing anything else.
- Please refrain from running tools or applying updates other than those I suggest.
- Never run more than one scan at a time.
- Keep updating me regarding your computer behavior, good, or bad.
- The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
- If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
- I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
================================================== ================
Internet explorerer not working right
More details please.
internet exploerer sometimes is not responding and also takes a long time to load
Open IE, go Tools>Internet options>Advanced tab, click on "Reset" button.
Restart IE and let me know how it goes.
it is working good now than you