Ok, I had a visit from Antivirus Live and luckily I think, or I HOPE, that I caught it before it really wrecked stuff up thanks to Malwarebytes. Well recently (on 1/22 to be exact), I was just surfing the internet and I decided to try to get into Yahoo Messenger Chat and low and behold, nothing would load. So I knew something was up, and I went to start scanning stuff. Well, I'm scanning without updates because BOTH Malwarebytes and SUPERAntiSpyware wouldn't update...AND I thought I'd try updating YIM to it's newest version and as predictable...no dice. Most of my programs that use some form of internet access, iTunes, YIM, MBAM, and SUPERAntiSpyware, and H & R Block, would either not update or do certain things that require. So I know that something's still on my computer and I don't know what, so that's why I need help. I've tried everything I could think of and nothing's working, so please help...
Here's the log that you asked me to provide in that intro to post. Also attached is an MBAM log, a hijackthis log
DS (Ver_09-12-01.01) - NTFSx86
Run by Owner at 16:13:03.04 on Tue 01/26/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.879.205 [GMT -6:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\QuickTime\QTTask.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Freecorder\FLVSrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Documents and Settings\Owner\My Documents\Programs\dds.scr
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3504
uStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3504
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=0sqDzz3f1Ho4EbwgMP-uecoVoU8
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
mSearchAssistant = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3504
uURLSearchHooks: Freecorder Toolbar: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - c:\program files\freecorder\tbFree.dll
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Freecorder Toolbar: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - c:\program files\freecorder\tbFree.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: WebBlock Class: {c6b08e8d-3f9a-4710-9f38-e4bf827c6ac2} - c:\program files\ashkon software\website block\webblock.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\windows\system32\BAE.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Freecorder Toolbar: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - c:\program files\freecorder\tbFree.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [CyberDefender Registry Cleaner] c:\program files\cyberdefender\registry cleaner\CDregclean.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [VirusScan Online] \mcvsshld.exe
mRun: [Freecorder FLV Service] "c:\program files\freecorder\FLVSrvc.exe" /run
mRun: [CyberDefender Registry Cleaner]
dRun: [Power2GoExpress] NA
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\x8z7w5z9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-amo&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\x8z7w5z9.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R1 bckd;bckd;c:\windows\system32\drivers\bckd.sys [2009-12-11 74088]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-11-4 214664]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
R2 bckwfs;Blue Coat K9 Web Protection;c:\program files\blue coat k9 web protection\k9filter.exe [2009-12-11 1078632]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-12-26 93320]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-12-26 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-12-26 144704]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-12-26 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-12-26 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-12-26 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-12-26 40552]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-12-27 34248]
=============== Created Last 30 ================
2010-01-24 05:08:26 0 d-----w- c:\docume~1\owner\applic~1\Trillian
2010-01-24 04:31:04 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-01-24 04:03:59 0 d-----w- c:\windows\pss
2010-01-24 03:56:25 0 d-----w- c:\program files\CCleaner
2010-01-23 02:17:03 0 d-----w- c:\program files\common files\Scanner
2010-01-23 02:17:03 0 d-----w- c:\documents and settings\owner\SmitfraudFix
2010-01-23 02:17:02 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-23 02:16:28 0 d-----w- c:\program files\PDF995
2010-01-23 02:15:08 0 d-----w- c:\program files\common files\DivX Shared
2010-01-22 23:08:49 0 d-----w- c:\program files\Trend Micro
2010-01-22 21:39:05 0 d-----w- c:\program files\CA Yahoo! Anti-Spy
2010-01-22 21:28:59 0 d-----w- c:\program files\SUPERAntiSpyware
2010-01-22 21:28:59 0 d-----w- c:\docume~1\owner\applic~1\SUPERAntiSpyware.com
2010-01-22 20:55:13 0 d-----w- c:\docume~1\owner\applic~1\CyberDefender
2010-01-22 20:55:02 0 d-----w- c:\program files\CyberDefender
2010-01-21 20:19:06 0 d-----w- c:\docume~1\owner\applic~1\TaxCut
2010-01-21 20:14:31 0 d-----w- c:\program files\HRBlock2009
2010-01-21 20:10:21 0 d-----w- c:\docume~1\alluse~1\applic~1\TaxCut
2010-01-18 07:34:17 0 d-----w- c:\program files\Ashkon Software
2010-01-18 07:28:02 0 d-sh--w- c:\documents and settings\owner\PrivacIE
2010-01-18 07:22:14 0 d-sh--w- c:\documents and settings\owner\IETldCache
2010-01-18 07:15:49 0 d-----w- c:\windows\ie8updates
2010-01-18 07:08:01 0 dc-h--w- c:\windows\ie8
2010-01-18 06:40:43 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-01-18 06:40:42 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-01-18 06:40:40 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-01-18 06:40:40 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-01-18 06:40:36 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-01-18 06:40:29 11070464 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-01-18 06:39:57 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-01-18 00:25:02 0 d-----w- c:\program files\Windows Media Connect 2
2010-01-17 22:03:17 0 d-----w- c:\program files\DivX
2010-01-05 19:47:26 45056 ----a-w- c:\windows\system32\WNASPI32.DLL
2010-01-05 19:47:25 16512 ----a-w- c:\windows\system32\drivers\ASPI32.SYS
2010-01-05 19:46:56 0 d-----w- c:\program files\Xilisoft
2010-01-01 07:47:59 0 d-s---w- c:\documents and settings\owner\UserData
2010-01-01 04:54:15 0 d-----w- c:\program files\Blue Coat K9 Web Protection
2009-12-30 17:00:05 0 d-----w- c:\program files\NCH Software
2009-12-30 16:57:26 0 d-----w- c:\program files\NCH Swift Sound
2009-12-30 07:03:08 0 d-----w- c:\docume~1\alluse~1\applic~1\AIM
2009-12-30 07:02:37 0 d-----w- c:\program files\AIM
2009-12-30 07:02:31 0 d-----w- c:\program files\common files\Software Update Utility
2009-12-28 21:29:29 27700 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-28 06:04:33 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-12-28 06:04:32 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-28 03:55:07 2 ----a-w- c:\windows\msoffice.ini
2009-12-28 03:35:16 0 d-----w- c:\program files\Conduit
2009-12-28 03:34:50 0 d-----w- c:\windows\Freecorder
2009-12-28 03:34:50 0 d-----w- c:\program files\Freecorder
==================== Find3M ====================
2010-01-07 22:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-27 04:54:24 8552 ----a-w- c:\windows\system32\drivers\asctrm.sys
2009-12-21 19:14:05 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-11 22:52:52 74088 ----a-w- c:\windows\system32\drivers\bckd.sys
2009-11-14 00:49:00 129784 ------w- c:\windows\system32\pxafs.dll
2009-11-14 00:49:00 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-11-14 00:49:00 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-11-14 00:47:32 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47:28 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47:28 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47:28 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47:28 696320 ----a-w- c:\windows\system32\DivX.dll
============= FINISH: 16:14:03.00 ===============
Attached Files
Edited by JustinLH1125, 26 January 2010 - 07:44 PM.