Bobbye
Posts: 16,313 +36
I've been sitting here for an hour trying to make sense out of your logs! There is so much that needs to be removed from the system, rather than try to piece it together, you would do best with a reformay/reinstall.
It's not all malware! You have processes for 3 antivirus programs running: Avast, AVG, Norton Worm Protect. from Norton Security 2005. You also downloaded the setup for Kaspersky AV. It looks like on 10/15 and 10/16, you went around the internet and gathered this and that, maybe in the hope that it would fix things.
Instead, it made the system worse. And on the following dates, you got multiples of the same:
2010-09-09 14:16:31 667136 ----a-w- c:\windows\system32\wininet.dll
2010-09-09 14:16:31 667136 ----a-w- c:\windows\system32\wininet(2)(2).dll
2010-09-09 14:16:31 627712 ----a-w- c:\windows\system32\urlmon(2)(2).dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k(2)(2).sys
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc(2)(2).dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32(2)(2).dll
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4(2)(3).dll
===============================================
I am not sure how you could even run multiple processes of the above! You can remove a few entries in HijackThis, but I think it's a waste of your time:
Please reopen HiackThis to 'do system scan only.' Check each of the following, if present:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} (RtspVaPgCtrl Class) - http://74.73.125.189:8888/RtspVaPgDec.cab
Close all Windows except HijackThis and click on "Fix Checked"
======================================================
Please run this Custom CFScript
Save this as CFScript.txt, in the same location as ComboFix.exe
Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt . Please paste in your next reply.
====================
This may help a little but I don't think it will be any significant improvement.
It's not all malware! You have processes for 3 antivirus programs running: Avast, AVG, Norton Worm Protect. from Norton Security 2005. You also downloaded the setup for Kaspersky AV. It looks like on 10/15 and 10/16, you went around the internet and gathered this and that, maybe in the hope that it would fix things.
Instead, it made the system worse. And on the following dates, you got multiples of the same:
2010-09-09 14:16:31 667136 ----a-w- c:\windows\system32\wininet.dll
2010-09-09 14:16:31 667136 ----a-w- c:\windows\system32\wininet(2)(2).dll
2010-09-09 14:16:31 627712 ----a-w- c:\windows\system32\urlmon(2)(2).dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k(2)(2).sys
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc(2)(2).dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32(2)(2).dll
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4(2)(3).dll
===============================================
I am not sure how you could even run multiple processes of the above! You can remove a few entries in HijackThis, but I think it's a waste of your time:
Please reopen HiackThis to 'do system scan only.' Check each of the following, if present:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} (RtspVaPgCtrl Class) - http://74.73.125.189:8888/RtspVaPgDec.cab
Close all Windows except HijackThis and click on "Fix Checked"
======================================================
Please run this Custom CFScript
[1]. Close any open browsers.
[2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
[3]. Open notepad and copy/paste the text in the code below into it:
Code:
File::
c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys
c:\windows\system32\drivers\klif.sys
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=-
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"=-
DDS::
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
uURLSearchHooks: H - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} - hxxp://74.73.125.189:8888/RtspVaPgDec.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
SecCenter::
{990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
Driver::
SABKUTI
KLIF

Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt . Please paste in your next reply.
====================
This may help a little but I don't think it will be any significant improvement.