ShellExec: FRONTPG.EXE: edit=c:\progra~1\micros~3\office\FRONTPG.EXE . =============== Created Last 30 ================ . 2011-07-17 18:57:23 -------- d-----w- c:\users\melly\appdata\roaming\Malwarebytes 2011-07-17 18:57:17 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-07-17 18:57:16 -------- d-----w- c:\programdata\Malwarebytes 2011-07-17 18:57:13 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-07-17 Ask a question and give support. The program is notable for quickly scanning a user's computer to display the most common locations of malware, rather than relying on a database of known spyware. You seem to have CSS turned off. http://optionrefi.com/hijackthis-download/three-month-old-computer-first-hijack-this.php

device: opened successfully user: MBR read successfully . I rebooted again and reran combofix and when it was done the pc seemed happy- able to open the sites we could not in all browsers we tried. C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\rundll32.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Juniper Networks\Common Files\dsNcService.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Combofix log
ComboFix 11-08-27.01 - Melly 08/27/2011 16:11:11.2.2 - x86
Microsoft® check these guys out

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. Just paste your complete logfile into the textbox at the bottom of this page. Retrieved 2010-02-02. HijackPro[edit] During 2002 and 2003, IT entrepreneur Glenn Bluff (owner of Computer Hope UK) made several attempts to buy HijackThis.

The solution is hard to understand and follow. It requires expertise to interpret the results, though - it doesn't tell you which items are bad. C: is FIXED (NTFS) - 327 GiB total, 68.219 GiB free. Hijackthis Bleeping When the scan completes, press List of found threats Push Export of text file and save the file to your desktop using a unique name, such as ESETScan.

Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.Double click on combofix.exe & follow the prompts. HijackThis attempts to create backups of the files and registry entries that it fixes, which can be used to restore the system in the event of a mistake. By clicking on "Follow" below, you are agreeing to the Terms of Use and the Privacy Policy. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 6:54:31 AM, on 3/21/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.17091) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe

Isn't enough the bloody civil war we're going through? How To Use Hijackthis catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-03-27 13:36 Windows 5.1.2600 Service Pack 3 NTFS . HKCU-Run-Aim6 - (no file) HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe HKLM-Run-HotSync - c:\program files\PalmSource\Desktop\HotSync.exe AddRemove-HijackThis - c:\users\Melly\Documents\HijackThis.exe AddRemove-Palm-DB-Tools_is1 - c:\users\Melly\Documents\Palm OS Desktop\pdbtools\unins000.exe . . . ************************************************************************** . Contact Support.

Weird and way above my level of understanding. have a peek at these guys This is normal.Shortly after two logs will appear: DDS.txt Attach.txtA window will open instructing you save & post the logsSave the logs to a convenient place such as your desktopCopy the Hijackthis Log Analyzer Please remove the pirated program. ======================================== Regarding your question about the ecompletion of GMER, this means the end> ---- EOF - GMER 1.0.15 ----. Hijackthis Download Windows 7 awesome work, thanks!

For Eset: Please download OTMovit by Old Timer and save to your desktop. check my blog c:\users\Melly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Melly\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560] . R0 TLRecAgent;TLRecAgent;c:\windows\system32\drivers\TLRecAgent.sys [2009-1-5 37208] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-7-15 441176] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2008-4-7 309848] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-7 19544] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2007-12-11 54104] R2 avast! The solution did not provide detailed procedure. Hijackthis Trend Micro

R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2010-7-1 36432] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2010-7-1 339984] R3 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2010-7-1 51792] R3 TmPfw;Trend Micro Personal Firewall;c:\program files\trend micro\internet security\TmPfw.exe [2010-7-1 497008] R3 TmProxy;Trend Micro Proxy Service;c:\program Disk trace: called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A782735]<< _asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a788990]; MOV EAX, [0x8a788a0c]; PUSH EBX; Uncheck 'Remove found threats' Check 'Scan archives/ Leave remaining settings as is. http://optionrefi.com/hijackthis-download/another-hijack-log.php If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\WINDOWS\system32\svchost.exe

Even for an advanced computer user.

All rights reserved. However, HijackThis does not make value based calls between what is considered good or bad. Using the site is easy and fun. Hijackthis 2016 I hit OK on that screen and a log appeared in Notepad.

Please update Java: Java Updates Note: Uncheck 'Install Yahoo Toolbar' on the download screen before you do the update. 2. D: is FIXED (NTFS) - 9 GiB total, 1.191 GiB free. Please don't fill out this field. http://optionrefi.com/hijackthis-download/help-hijack-log.php Hard-killing it every time it tries to update is not my preference.