InterviewSolution
| 1. |
Solve : Don't Know What to Do Anymore... >:C? |
|
Answer» I have a XP Dell Inspiron 1525 and it has had many viruses in the past. We've gotten it fixed before but now it has another virus and my mom refuses to pay to get it fixed again.
Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. ---------- Go to Start > Run and type Notepad.exe then click OK. Copy and paste the following text within the code box into the new Notepad file. Code: [Select]ECHO OFF sc stop avg8emc sc delete avg8emc sc stop avg8wd sc delete avg8wd exit In Notepad select File and Save as Choose the Save to location to be the Desktop and for the File name: type in fixme.bat making sure that the Save as type field says All files. Next double click fixservice.bat to run it. A black box should open and close after a short time, this is normal. Do not continue until the black box has closed Delete fixservice.bat from the Desktop. ---------- Now go here to download and run the AVG Antivirus Remover utility. http://www.avg.com/us-en/download-tools ---------- Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply. Exit out of MessengerDisable then delete the two files that were put on the desktop. ---------- If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixComboFix 10-03-03.04 - Michelle Dunaway 03/03/2010 22:24:51.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1449 [GMT -5:00] Running from: c:\documents and settings\Michelle Dunaway\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Symantec Endpoint Protection *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Adobe\230046.old c:\program files\Adobe\73090406.old c:\windows\ad2h264dec.dll c:\windows\Downloaded Program Files\f3initialsetup1.0.1.0.inf c:\windows\EventSystem.log c:\windows\system32\ctfmon .exe c:\windows\system32\hkcmd .exe c:\windows\system32\igfxpers .exe c:\windows\system32\igfxtray .exe c:\windows\system32\rundll32 .exe c:\windows\system32\wltray .exe Infected copy of c:\windows\system32\DRIVERS\iaStor.sys was found and DISINFECTED Restored copy from - Kitty ate it :p . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_6TO4 -------\Legacy_SSHNAS ((((((((((((((((((((((((( Files Created from 2010-02-04 to 2010-03-04 ))))))))))))))))))))))))))))))) . 2010-03-02 02:37 . 2010-03-02 02:37 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\Malwarebytes 2010-03-02 02:37 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-02 02:37 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-02 00:26 . 2010-03-02 00:26 -------- d--h--w- c:\windows\system32\GroupPolicy 2010-02-28 20:29 . 2010-02-28 20:29 -------- d-----w- c:\documents and settings\Michelle Dunaway\Local Settings\Application Data\Threat Expert 2010-02-28 20:24 . 2010-03-01 00:28 -------- d-----w- c:\program files\Spyware Doctor 2010-02-28 16:23 . 2010-02-28 16:23 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe 2010-02-28 15:44 . 2008-04-13 19:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys 2010-02-28 15:44 . 2008-04-13 19:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys 2010-02-28 15:44 . 2008-04-13 19:41 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys 2010-02-28 15:44 . 2008-04-13 19:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys 2010-02-28 15:44 . 2008-04-13 19:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys 2010-02-28 15:44 . 2008-04-13 19:40 8192 ----a-w- c:\windows\system32\drivers\changer.sys 2010-02-28 02:36 . 2010-02-28 02:46 2110728 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\Install_Facebook_Plug-In_1.0.3.exe 2010-02-26 06:41 . 2010-02-26 06:41 5582848 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\npfbplugin_1_0_3.dll 2010-02-20 20:52 . 2010-02-20 20:52 -------- d-----w- c:\program files\LyricsSeeker 2010-02-08 00:28 . 2010-02-08 00:28 50354 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\uninstall.exe 2010-02-08 00:28 . 2010-02-28 02:46 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook 2010-02-05 00:44 . 2010-02-05 00:44 -------- d-----w- c:\program files\iPod 2010-02-05 00:44 . 2010-03-03 00:41 -------- d-----w- c:\program files\iTunes 2010-02-05 00:37 . 2010-02-05 00:37 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-04 03:35 . 2009-12-21 20:10 -------- d-----w- c:\program files\Common Files\Akamai 2010-03-04 01:42 . 2009-11-26 18:12 -------- d-----w- c:\program files\QuickTime 2010-03-03 22:18 . 2010-01-28 23:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-03-03 22:05 . 2008-09-19 11:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2010-03-02 03:13 . 2009-11-10 12:00 79488 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-03-02 00:57 . 2009-03-16 22:20 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-02-28 21:01 . 2009-03-16 22:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-02-28 16:29 . 2008-09-20 21:17 -------- d-----w- c:\program files\Safari 2010-02-26 00:04 . 2008-09-28 21:47 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\gtk-2.0 2010-02-24 11:37 . 2007-02-12 19:36 312344 ----a-w- c:\windows\system32\drivers\iaStor.sys 2010-02-24 02:44 . 2008-09-19 11:23 -------- d-----w- c:\program files\Common Files\Adobe 2010-02-05 00:44 . 2008-09-19 21:29 -------- d-----w- c:\program files\Common Files\Apple 2010-02-04 18:08 . 2008-09-19 11:24 -------- d-----w- c:\program files\Google 2010-02-01 22:04 . 2010-02-01 22:04 847040 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\axfbootloader.dll 2010-02-01 22:04 . 2010-02-01 22:04 5578752 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\npfbplugin_1_0_1.dll 2010-01-29 01:52 . 2010-01-29 01:52 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\Office Genuine Advantage 2010-01-28 23:07 . 2010-01-28 23:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2010-01-28 23:07 . 2010-01-28 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-01-22 21:01 . 2009-03-16 23:33 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-12 22:57 . 2008-06-20 04:12 162048 ----a-w- c:\windows\system32\drivers\WpsHelper.sys 2010-01-07 00:12 . 2009-12-25 19:29 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT 2010-01-02 20:19 . 2009-12-25 19:27 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT 2009-12-31 16:50 . 2004-08-04 10:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-27 22:39 . 2008-09-20 21:41 86760 ---ha-w- c:\windows\system32\mlfcache.dat 2009-12-25 19:31 . 2009-12-25 19:31 49152 ----a-r- c:\documents and settings\Michelle Dunaway\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe 2009-12-25 19:31 . 2009-12-25 19:31 335872 ----a-r- c:\documents and settings\Michelle Dunaway\Application Data\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe 2009-12-25 19:30 . 2009-12-25 19:30 57344 ----a-r- c:\documents and settings\Michelle Dunaway\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe 2009-12-24 22:35 . 2008-09-19 22:47 189992 ----a-w- c:\documents and settings\Michelle Dunaway\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-12-21 19:14 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll 2009-12-16 18:43 . 2008-09-17 03:42 343040 ----a-w- c:\windows\system32\mspaint.exe 2009-12-14 07:08 . 2004-08-04 10:00 33280 ----a-w- c:\windows\system32\csrsrv.dll 2009-12-08 19:26 . 2005-03-30 01:21 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43 . 2005-03-30 01:01 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-12-04 18:22 . 2004-08-04 10:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2008-09-17 12:41 . 2008-09-17 12:41 76 --sh--r- c:\windows\CT4CET.bin . Code: [Select]<pre> c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe c:\program files\Common Files\Adobe\CS4ServiceManager\cs4servicemanager .exe c:\program files\Common Files\Apple\Mobile Device Support\bin\applesyncnotifier .exe c:\program files\Common Files\Nikon\Monitor\nkmonitor .exe c:\program files\Common Files\Symantec Shared\ccapp .exe c:\program files\iTunes\ituneshelper .exe c:\program files\Java\jre6\bin\jusched .exe c:\program files\Malwarebytes' Anti-Malware\mbam .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\SigmaTel\C-Major Audio\WDM\stsystra .exe </pre> ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeBridge"="" [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-08-14 115560] c:\documents and settings\Michelle Dunaway\Start Menu\Programs\Startup\ Talking Owl Gadget.lnk - c:\program files\Talking Owl Gadget\Talking Owl Gadget.exe [2010-1-2 95232] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Event Reminder.lnk - c:\program files\PrintMaster Silver 17\Remind.exe [2006-2-22 344064] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] ="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] ="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] ="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY] c:\progra~1\AVG\AVG8\avgtray.exe [N/A] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] c:\program files\QuickTime\qttask.exe [N/A] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "enablefirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"= "c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5353:TCP"= 5353:TCP:Adobe CSI CS4 "1033:TCP"= 1033:TCP:Akamai NetSession Interface "5000:UDP"= 5000:UDP:Akamai NetSession Interface R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/4/2004 5:00 AM 14336] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/19/2008 4:30 PM 24652] R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32mpcoinst,serviceStartProc --> RUNDLL32.EXE ykx32mpcoinst,serviceStartProc [?] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/30/2009 8:54 PM 102448] R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [9/17/2008 7:47 AM 105984] S2 gupdate1c9d65c8e7f4cd4;Google Update Service (gupdate1c9d65c8e7f4cd4);c:\program files\Google\Update\GoogleUpdate.exe [5/16/2009 2:28 PM 133104] S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\a5agu.sys [9/16/2008 11:03 PM 347648] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\coh_mon.sys [1/12/2008 5:32 PM 23888] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder 2010-02-18 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2010-03-04 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-19 23:44] 2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-16 19:28] 2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-16 19:28] 2010-03-04 c:\windows\Tasks\OGALogon.job - c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ie8-nickelback.com/start/ uInternet Settings,ProxyOverride = *.local IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxps://lowes.2020.net/Core/Player/2020PlayerAX_Win32.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {A1662FB6-39BE-41BB-ACDC-0448FB1B5817} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_5/PhotoCenter_ActiveX_Control.cab . - - - - ORPHANS REMOVED - - - - Notify-avgrsstarter - avgrsstx.dll SafeBoot-Symantec Antvirus ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-03 22:36 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1340) c:\windows\System32\BCMLogon.dll - - - - - - - > 'explorer.exe'(3484) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\windows\System32\WLTRYSVC.EXE c:\windows\System32\bcmwltry.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\HPZipm12.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\windows\system32\RUNDLL32.EXE c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe . ************************************************************************** . Completion time: 2010-03-03 22:42:14 - machine was rebooted ComboFix-quarantined-files.txt 2010-03-04 03:42 Pre-Run: 106,908,049,408 bytes free Post-Run: 107,110,699,008 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - 6D9730B51C40200121A613FE4F25A3241. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Driver:: Viewpoint Manager Service Folder:: c:\program files\Viewpoint SecCenter:: {17DDD097-36FF-435F-9E1B-52D74245D6BF} RenV:: c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe c:\program files\Common Files\Adobe\CS4ServiceManager\cs4servicemanager .exe c:\program files\Common Files\Apple\Mobile Device Support\bin\applesyncnotifier .exe c:\program files\Common Files\Nikon\Monitor\nkmonitor .exe c:\program files\Common Files\Symantec Shared\ccapp .exe c:\program files\iTunes\ituneshelper .exe c:\program files\Java\jre6\bin\jusched .exe c:\program files\Malwarebytes' Anti-Malware\mbam .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\QuickTime\qttask .exe c:\program files\SigmaTel\C-Major Audio\WDM\stsystra .exe 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeComboFix 10-03-04.02 - Michelle Dunaway 03/04/2010 17:15:03.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1312 [GMT -5:00] Running from: c:\documents and settings\Michelle Dunaway\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Michelle Dunaway\Desktop\CFScript.txt AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Symantec Endpoint Protection *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Viewpoint c:\program files\Viewpoint\Common\ViewpointService.exe c:\program files\Viewpoint\Common\VistaBoot.sdll c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_0306003B.dll c:\program files\Viewpoint\Viewpoint Media Player\ClassIDs.ini c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr_0306003B.dll c:\program files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini c:\program files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\Cursors.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\MTS3Reader.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\VETScriptInterpreter.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll c:\program files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini c:\program files\Viewpoint\Viewpoint Media Player\HostRegistry.ini c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe c:\program files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt c:\program files\Viewpoint\Viewpoint_log.dmp c:\program files\Viewpoint\Viewpoint_log.txt . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_VIEWPOINT_MANAGER_SERVICE -------\Service_Viewpoint Manager Service ((((((((((((((((((((((((( Files Created from 2010-02-04 to 2010-03-04 ))))))))))))))))))))))))))))))) . 2010-03-02 02:37 . 2010-03-02 02:37 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\Malwarebytes 2010-03-02 02:37 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-02 02:37 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-02 00:26 . 2010-03-02 00:26 -------- d--h--w- c:\windows\system32\GroupPolicy 2010-02-28 20:29 . 2010-02-28 20:29 -------- d-----w- c:\documents and settings\Michelle Dunaway\Local Settings\Application Data\Threat Expert 2010-02-28 20:24 . 2010-03-01 00:28 -------- d-----w- c:\program files\Spyware Doctor 2010-02-28 15:44 . 2008-04-13 19:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys 2010-02-28 15:44 . 2008-04-13 19:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys 2010-02-28 15:44 . 2008-04-13 19:41 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys 2010-02-28 15:44 . 2008-04-13 19:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys 2010-02-28 15:44 . 2008-04-13 19:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys 2010-02-28 15:44 . 2008-04-13 19:40 8192 ----a-w- c:\windows\system32\drivers\changer.sys 2010-02-20 20:52 . 2010-02-20 20:52 -------- d-----w- c:\program files\LyricsSeeker 2010-02-08 00:28 . 2010-02-28 02:46 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook 2010-02-05 00:44 . 2010-02-05 00:44 -------- d-----w- c:\program files\iPod 2010-02-05 00:44 . 2010-03-04 22:15 -------- d-----w- c:\program files\iTunes . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-04 22:21 . 2009-12-21 20:10 -------- d-----w- c:\program files\Common Files\Akamai 2010-03-04 22:15 . 2009-11-26 18:12 -------- d-----w- c:\program files\QuickTime 2010-03-04 22:15 . 2010-01-28 23:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-03-03 22:05 . 2008-09-19 11:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2010-03-02 03:13 . 2009-11-10 12:00 79488 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-03-02 00:57 . 2009-03-16 22:20 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-02-28 21:01 . 2009-03-16 22:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-02-28 16:29 . 2008-09-20 21:17 -------- d-----w- c:\program files\Safari 2010-02-28 16:23 . 2010-02-28 16:23 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe 2010-02-28 02:46 . 2010-02-28 02:36 2110728 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\Install_Facebook_Plug-In_1.0.3.exe 2010-02-26 06:41 . 2010-02-26 06:41 5582848 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\npfbplugin_1_0_3.dll 2010-02-26 00:04 . 2008-09-28 21:47 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\gtk-2.0 2010-02-24 11:37 . 2007-02-12 19:36 312344 ----a-w- c:\windows\system32\drivers\iaStor.sys 2010-02-24 02:44 . 2008-09-19 11:23 -------- d-----w- c:\program files\Common Files\Adobe 2010-02-08 00:28 . 2010-02-08 00:28 50354 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\uninstall.exe 2010-02-05 00:44 . 2008-09-19 21:29 -------- d-----w- c:\program files\Common Files\Apple 2010-02-05 00:37 . 2010-02-05 00:37 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe 2010-02-04 18:08 . 2008-09-19 11:24 -------- d-----w- c:\program files\Google 2010-02-01 22:04 . 2010-02-01 22:04 847040 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\axfbootloader.dll 2010-02-01 22:04 . 2010-02-01 22:04 5578752 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\npfbplugin_1_0_1.dll 2010-01-29 01:52 . 2010-01-29 01:52 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\Office Genuine Advantage 2010-01-28 23:07 . 2010-01-28 23:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2010-01-28 23:07 . 2010-01-28 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-01-22 21:01 . 2009-03-16 23:33 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-12 22:57 . 2008-06-20 04:12 162048 ----a-w- c:\windows\system32\drivers\WpsHelper.sys 2010-01-07 00:12 . 2009-12-25 19:29 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT 2010-01-02 20:19 . 2009-12-25 19:27 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT 2009-12-31 16:50 . 2004-08-04 10:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-27 22:39 . 2008-09-20 21:41 86760 ---ha-w- c:\windows\system32\mlfcache.dat 2009-12-25 19:31 . 2009-12-25 19:31 49152 ----a-r- c:\documents and settings\Michelle Dunaway\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe 2009-12-25 19:31 . 2009-12-25 19:31 335872 ----a-r- c:\documents and settings\Michelle Dunaway\Application Data\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe 2009-12-25 19:30 . 2009-12-25 19:30 57344 ----a-r- c:\documents and settings\Michelle Dunaway\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe 2009-12-24 22:35 . 2008-09-19 22:47 189992 ----a-w- c:\documents and settings\Michelle Dunaway\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-12-21 19:14 . 2006-03-04 03:33 916480 ------w- c:\windows\system32\wininet.dll 2009-12-16 18:43 . 2008-09-17 03:42 343040 ----a-w- c:\windows\system32\mspaint.exe 2009-12-14 07:08 . 2004-08-04 10:00 33280 ----a-w- c:\windows\system32\csrsrv.dll 2009-12-08 19:26 . 2005-03-30 01:21 2145280 ------w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43 . 2005-03-30 01:01 2023936 ------w- c:\windows\system32\ntkrnlpa.exe 2008-09-17 12:41 . 2008-09-17 12:41 76 --sh--r- c:\windows\CT4CET.bin . Code: [Select]<pre> c:\program files\Common Files\Symantec Shared\ccapp .exe </pre> ((((((((((((((((((((((((((((( [email protected]_03.36.28 ))))))))))))))))))))))))))))))))))))))))) . + 2010-03-04 22:21 . 2010-03-04 22:21 16384 c:\windows\Temp\Perflib_Perfdata_334.dat + 2010-03-04 22:21 . 2010-03-04 22:21 16384 c:\windows\Temp\Perflib_Perfdata_330.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeBridge"="" [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-08-14 115560] c:\documents and settings\Michelle Dunaway\Start Menu\Programs\Startup\ Talking Owl Gadget.lnk - c:\program files\Talking Owl Gadget\Talking Owl Gadget.exe [2010-1-2 95232] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Event Reminder.lnk - c:\program files\PrintMaster Silver 17\Remind.exe [2006-2-22 344064] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] ="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] ="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] ="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY] c:\progra~1\AVG\AVG8\avgtray.exe [N/A] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2010-02-28 18:10 55808 ----a-w- c:\program files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "enablefirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"= "c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5353:TCP"= 5353:TCP:Adobe CSI CS4 "1033:TCP"= 1033:TCP:Akamai NetSession Interface "5000:UDP"= 5000:UDP:Akamai NetSession Interface R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/4/2004 5:00 AM 14336] R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32mpcoinst,serviceStartProc --> RUNDLL32.EXE ykx32mpcoinst,serviceStartProc [?] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/30/2009 8:54 PM 102448] R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [9/17/2008 7:47 AM 105984] S2 gupdate1c9d65c8e7f4cd4;Google Update Service (gupdate1c9d65c8e7f4cd4);c:\program files\Google\Update\GoogleUpdate.exe [5/16/2009 2:28 PM 133104] S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\a5agu.sys [9/16/2008 11:03 PM 347648] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\coh_mon.sys [1/12/2008 5:32 PM 23888] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder 2010-02-18 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2010-03-04 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-19 23:44] 2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-16 19:28] 2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-16 19:28] 2010-03-04 c:\windows\Tasks\OGALogon.job - c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ie8-nickelback.com/start/ uInternet Settings,ProxyOverride = *.local IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxps://lowes.2020.net/Core/Player/2020PlayerAX_Win32.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {A1662FB6-39BE-41BB-ACDC-0448FB1B5817} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_5/PhotoCenter_ActiveX_Control.cab . - - - - ORPHANS REMOVED - - - - AddRemove-ViewpointMediaPlayer - c:\program files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-04 17:21 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1344) c:\windows\System32\BCMLogon.dll - - - - - - - > 'explorer.exe'(3604) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\windows\System32\WLTRYSVC.EXE c:\windows\System32\bcmwltry.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\HPZipm12.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\windows\system32\RUNDLL32.EXE c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe . ************************************************************************** . Completion time: 2010-03-04 17:27:50 - machine was rebooted ComboFix-quarantined-files.txt 2010-03-04 22:27 ComboFix2.txt 2010-03-04 03:42 Pre-Run: 107,085,824,000 bytes free Post-Run: 107,058,651,136 bytes free - - End Of File - - 8428627679F475ACDC94A9D0B0C5C8E3 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Folder:: c:\Program Files\AVG RenV:: c:\program files\Common Files\Symantec Shared\ccapp .exe Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeBridge"=- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeComboFix 10-03-04.02 - Michelle Dunaway 03/04/2010 19:46:59.3.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1373 [GMT -5:00] Running from: c:\documents and settings\Michelle Dunaway\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Michelle Dunaway\Desktop\CFScript.txt AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Symantec Endpoint Protection *enabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\AVG c:\program files\AVG\AVG8\avg.snu c:\program files\AVG\AVG8\avgatend.stp c:\program files\AVG\AVG8\avgatupd.stp c:\program files\AVG\AVG8\avgchk.exe c:\program files\AVG\AVG8\avgchk.exe0 c:\program files\AVG\AVG8\avginet.dll c:\program files\AVG\AVG8\avgiproxy.exe c:\program files\AVG\AVG8\avgmwdef_us.mht c:\program files\AVG\AVG8\avgrsx.exe c:\program files\AVG\AVG8\avgupd.dll c:\program files\AVG\AVG8\avgupd.exe c:\program files\AVG\AVG8\cf.dat c:\program files\AVG\AVG8\commonpriv.log c:\program files\AVG\AVG8\commonpriv.log.lock c:\program files\AVG\AVG8\dbghelp.dll c:\program files\AVG\AVG8\fixfp.exe c:\program files\AVG\AVG8\Icons\background_middle_gray.gif c:\program files\AVG\AVG8\Icons\background_middle_green.gif c:\program files\AVG\AVG8\Icons\background_middle_orange.gif c:\program files\AVG\AVG8\Icons\background_middle_red.gif c:\program files\AVG\AVG8\Icons\background_middle_yellow.gif c:\program files\AVG\AVG8\Icons\background_top_gray.gif c:\program files\AVG\AVG8\Icons\background_top_green.gif c:\program files\AVG\AVG8\Icons\background_top_orange.gif c:\program files\AVG\AVG8\Icons\background_top_red.gif c:\program files\AVG\AVG8\Icons\background_top_yellow.gif c:\program files\AVG\AVG8\Icons\block-doc.gif c:\program files\AVG\AVG8\Icons\blocked.gif c:\program files\AVG\AVG8\Icons\border_bottom_gray.gif c:\program files\AVG\AVG8\Icons\border_bottom_green.gif c:\program files\AVG\AVG8\Icons\border_bottom_orange.gif c:\program files\AVG\AVG8\Icons\border_bottom_red.gif c:\program files\AVG\AVG8\Icons\border_bottom_yellow.gif c:\program files\AVG\AVG8\Icons\border_top_gray.gif c:\program files\AVG\AVG8\Icons\border_top_green.gif c:\program files\AVG\AVG8\Icons\border_top_orange.gif c:\program files\AVG\AVG8\Icons\border_top_red.gif c:\program files\AVG\AVG8\Icons\border_top_yellow.gif c:\program files\AVG\AVG8\Icons\box_bottom_red.gif c:\program files\AVG\AVG8\Icons\box_top_red.gif c:\program files\AVG\AVG8\Icons\caution.gif c:\program files\AVG\AVG8\Icons\click_here_gray.gif c:\program files\AVG\AVG8\Icons\click_here_green.gif c:\program files\AVG\AVG8\Icons\click_here_orange.gif c:\program files\AVG\AVG8\Icons\click_here_red.gif c:\program files\AVG\AVG8\Icons\click_here_yellow.gif c:\program files\AVG\AVG8\Icons\clock.gif c:\program files\AVG\AVG8\Icons\close.gif c:\program files\AVG\AVG8\Icons\icons_blocked.gif c:\program files\AVG\AVG8\Icons\icons_caution.gif c:\program files\AVG\AVG8\Icons\icons_close.gif c:\program files\AVG\AVG8\Icons\icons_safe.gif c:\program files\AVG\AVG8\Icons\icons_unknown.gif c:\program files\AVG\AVG8\Icons\icons_warning.gif c:\program files\AVG\AVG8\Icons\LS_Logo_Results.gif c:\program files\AVG\AVG8\Icons\safe.gif c:\program files\AVG\AVG8\Icons\unknown.gif c:\program files\AVG\AVG8\Icons\warning.gif c:\program files\AVG\AVG8\license_us.txt c:\program files\AVG\AVG8\Notification\cmp2008_App_Free_8_fr.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Free_8_it.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Free_8_nl.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Free_8_pt.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Free_8_sp.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Free_8_us.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Paid_8_fr.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Paid_8_it.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Paid_8_nl.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Paid_8_pt.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Paid_8_sp.html c:\program files\AVG\AVG8\Notification\cmp2008_App_Paid_8_us.html c:\program files\AVG\AVG8\Notification\icon_bulb.gif c:\program files\AVG\AVG8\Notification\logo_avg8.gif c:\program files\AVG\AVG8\Notification\style.css c:\program files\AVG\AVG8\ph.dat c:\program files\AVG\AVG8\sb.dat c:\program files\AVG\AVG8\sb.dat.xcd c:\program files\AVG\AVG8\sb2.dat c:\program files\AVG\AVG8\sc.dat c:\program files\AVG\AVG8\sc.dat.xcd c:\program files\AVG\AVG8\updatecomps.cfg . ((((((((((((((((((((((((( Files Created from 2010-02-05 to 2010-03-05 ))))))))))))))))))))))))))))))) . 2010-03-02 02:37 . 2010-03-02 02:37 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\Malwarebytes 2010-03-02 02:37 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-02 02:37 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-02 00:26 . 2010-03-02 00:26 -------- d--h--w- c:\windows\system32\GroupPolicy 2010-02-28 20:29 . 2010-02-28 20:29 -------- d-----w- c:\documents and settings\Michelle Dunaway\Local Settings\Application Data\Threat Expert 2010-02-28 20:24 . 2010-03-01 00:28 -------- d-----w- c:\program files\Spyware Doctor 2010-02-28 16:23 . 2010-02-28 16:23 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe 2010-02-28 15:44 . 2008-04-13 19:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys 2010-02-28 15:44 . 2008-04-13 19:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys 2010-02-28 15:44 . 2008-04-13 19:41 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys 2010-02-28 15:44 . 2008-04-13 19:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys 2010-02-28 15:44 . 2008-04-13 19:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys 2010-02-28 15:44 . 2008-04-13 19:40 8192 ----a-w- c:\windows\system32\drivers\changer.sys 2010-02-28 02:36 . 2010-02-28 02:46 2110728 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\Install_Facebook_Plug-In_1.0.3.exe 2010-02-26 06:41 . 2010-02-26 06:41 5582848 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\npfbplugin_1_0_3.dll 2010-02-20 20:52 . 2010-02-20 20:52 -------- d-----w- c:\program files\LyricsSeeker 2010-02-08 00:28 . 2010-02-08 00:28 50354 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\uninstall.exe 2010-02-08 00:28 . 2010-02-28 02:46 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook 2010-02-05 00:44 . 2010-02-05 00:44 -------- d-----w- c:\program files\iPod 2010-02-05 00:44 . 2010-03-04 22:15 -------- d-----w- c:\program files\iTunes 2010-02-05 00:37 . 2010-02-05 00:37 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-05 00:53 . 2009-12-21 20:10 -------- d-----w- c:\program files\Common Files\Akamai 2010-03-04 23:06 . 2008-09-19 11:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2010-03-04 22:15 . 2009-11-26 18:12 -------- d-----w- c:\program files\QuickTime 2010-03-04 22:15 . 2010-01-28 23:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-03-02 03:13 . 2009-11-10 12:00 79488 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-03-02 00:57 . 2009-03-16 22:20 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-02-28 21:01 . 2009-03-16 22:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-02-28 16:29 . 2008-09-20 21:17 -------- d-----w- c:\program files\Safari 2010-02-26 00:04 . 2008-09-28 21:47 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\gtk-2.0 2010-02-24 11:37 . 2007-02-12 19:36 312344 ----a-w- c:\windows\system32\drivers\iaStor.sys 2010-02-24 02:44 . 2008-09-19 11:23 -------- d-----w- c:\program files\Common Files\Adobe 2010-02-05 00:44 . 2008-09-19 21:29 -------- d-----w- c:\program files\Common Files\Apple 2010-02-04 18:08 . 2008-09-19 11:24 -------- d-----w- c:\program files\Google 2010-02-01 22:04 . 2010-02-01 22:04 847040 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\axfbootloader.dll 2010-02-01 22:04 . 2010-02-01 22:04 5578752 ----a-w- c:\documents and settings\Michelle Dunaway\Application Data\Facebook\npfbplugin_1_0_1.dll 2010-01-29 01:52 . 2010-01-29 01:52 -------- d-----w- c:\documents and settings\Michelle Dunaway\Application Data\Office Genuine Advantage 2010-01-28 23:07 . 2010-01-28 23:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2010-01-28 23:07 . 2010-01-28 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-01-22 21:01 . 2009-03-16 23:33 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-12 22:57 . 2008-06-20 04:12 162048 ----a-w- c:\windows\system32\drivers\WpsHelper.sys 2010-01-07 00:12 . 2009-12-25 19:29 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT 2010-01-02 20:19 . 2009-12-25 19:27 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT 2009-12-31 16:50 . 2004-08-04 10:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-27 22:39 . 2008-09-20 21:41 86760 ---ha-w- c:\windows\system32\mlfcache.dat 2009-12-25 19:31 . 2009-12-25 19:31 49152 ----a-r- c:\documents and settings\Michelle Dunaway\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe 2009-12-25 19:31 . 2009-12-25 19:31 335872 ----a-r- c:\documents and settings\Michelle Dunaway\Application Data\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe 2009-12-25 19:30 . 2009-12-25 19:30 57344 ----a-r- c:\documents and settings\Michelle Dunaway\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe 2009-12-24 22:35 . 2008-09-19 22:47 189992 ----a-w- c:\documents and settings\Michelle Dunaway\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-12-21 19:14 . 2006-03-04 03:33 916480 ------w- c:\windows\system32\wininet.dll 2009-12-16 18:43 . 2008-09-17 03:42 343040 ----a-w- c:\windows\system32\mspaint.exe 2009-12-14 07:08 . 2004-08-04 10:00 33280 ----a-w- c:\windows\system32\csrsrv.dll 2009-12-08 19:26 . 2005-03-30 01:21 2145280 ------w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43 . 2005-03-30 01:01 2023936 ------w- c:\windows\system32\ntkrnlpa.exe 2008-09-17 12:41 . 2008-09-17 12:41 76 --sh--r- c:\windows\CT4CET.bin . Code: [Select]<pre> c:\program files\Common Files\Symantec Shared\ccapp .exe </pre> ((((((((((((((((((((((((((((( [email protected]_03.36.28 ))))))))))))))))))))))))))))))))))))))))) . + 2010-03-05 00:53 . 2010-03-05 00:53 16384 c:\windows\Temp\Perflib_Perfdata_3e4.dat + 2010-03-05 00:53 . 2010-03-05 00:53 16384 c:\windows\Temp\Perflib_Perfdata_36c.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-08-14 115560] c:\documents and settings\Michelle Dunaway\Start Menu\Programs\Startup\ Talking Owl Gadget.lnk - c:\program files\Talking Owl Gadget\Talking Owl Gadget.exe [2010-1-2 95232] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Event Reminder.lnk - c:\program files\PrintMaster Silver 17\Remind.exe [2006-2-22 344064] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] ="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] ="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] ="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY] c:\progra~1\AVG\AVG8\avgtray.exe [N/A] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2010-02-28 18:10 55808 ----a-w- c:\program files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "enablefirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"= "c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5353:TCP"= 5353:TCP:Adobe CSI CS4 "1033:TCP"= 1033:TCP:Akamai NetSession Interface "5000:UDP"= 5000:UDP:Akamai NetSession Interface R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/4/2004 5:00 AM 14336] R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32mpcoinst,serviceStartProc --> RUNDLL32.EXE ykx32mpcoinst,serviceStartProc [?] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/30/2009 8:54 PM 102448] R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [9/17/2008 7:47 AM 105984] S2 gupdate1c9d65c8e7f4cd4;Google Update Service (gupdate1c9d65c8e7f4cd4);c:\program files\Google\Update\GoogleUpdate.exe [5/16/2009 2:28 PM 133104] S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\a5agu.sys [9/16/2008 11:03 PM 347648] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\coh_mon.sys [1/12/2008 5:32 PM 23888] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder 2010-02-18 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2010-03-05 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-19 23:44] 2010-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-16 19:28] 2010-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-16 19:28] 2010-03-05 c:\windows\Tasks\OGALogon.job - c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ie8-nickelback.com/start/ uInternet Settings,ProxyOverride = *.local IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxps://lowes.2020.net/Core/Player/2020PlayerAX_Win32.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {A1662FB6-39BE-41BB-ACDC-0448FB1B5817} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_5/PhotoCenter_ActiveX_Control.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-04 19:59 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1344) c:\windows\System32\BCMLogon.dll - - - - - - - > 'explorer.exe'(3360) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\windows\System32\WLTRYSVC.EXE c:\windows\System32\bcmwltry.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\HPZipm12.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\windows\system32\RUNDLL32.EXE c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe . ************************************************************************** . Completion time: 2010-03-04 19:59:58 - machine was rebooted ComboFix-quarantined-files.txt 2010-03-05 00:59 ComboFix2.txt 2010-03-04 22:27 ComboFix3.txt 2010-03-04 03:42 Pre-Run: 106,909,802,496 bytes free Post-Run: 107,017,216,000 bytes free - - End Of File - - 5DBAAE0650E9E1A509CB87FB2904ED78That file isn't wanting to be removed. Download OTM by OldTimer to your desktop. Note: If you are using Vista or Windows 7, right-click on OTM.exe and choose Run As Administrator. * Save it to your Desktop. * Double-click OTM.exe to run it. * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy) Code: [Select]:Processes explorer.exe :services :reg :files c:\program files\Common Files\Symantec Shared\ccapp .exe :Commands [purity] [emptytemp] [start explorer] * Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste. * Click the red Moveit! button. * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply. * Close OTM Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. How is the computer running now? All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== c:\program files\Common Files\Symantec Shared\ccapp .exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: Michelle Dunaway ->Temp folder emptied: 234539 bytes ->Temporary Internet Files folder emptied: 21530592 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Apple Safari cache emptied: 1267570 bytes ->Flash cache emptied: 2865 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 1717 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 32768 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 22.00 mb OTM by OldTimer - Version 3.1.10.0 log created on 03042010_202933 Files moved on Reboot... File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFBFC9.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFBFD6.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC063.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC070.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC151.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC15E.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC198.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC1A5.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC1DF.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC1EC.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC226.tmp not found! File C:\Documents and Settings\Michelle Dunaway\Local Settings\Temp\~DFC233.tmp not found! C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\YSYX4AVO\connect[1].htm moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\YSYX4AVO\iframe3[1].htm moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\YSYX4AVO\st[1] moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\K6UENPQ2\10[2].htm moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\K6UENPQ2\468x60x728x90b[1].html moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\K6UENPQ2\Chapter_21_Northern_Eurasia_1_0[1].htm moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\K6UENPQ2\home[1].htm moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\K6UENPQ2\signin[1].htm moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\HV3LFTZ7\adservercontinuation[1].htm moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\HV3LFTZ7\redirectiframe[1].html moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\HV3LFTZ7\topicseen[1].html moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\HKDJ2IXM\06615[1].htm moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\Content.IE5\HKDJ2IXM\history_manager[1].htm moved successfully. C:\Documents and Settings\Michelle Dunaway\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. File C:\WINDOWS\temp\Perflib_Perfdata_36c.dat not found! File C:\WINDOWS\temp\Perflib_Perfdata_43c.dat not found! Registry entries deleted on Reboot... Its been running great! It's actually better than before because I used to have to right click and press start or go into Program Files and find the .exe to make anything run, and that was because Malwarebytes did something last time I had the fake Internet Security. Thank you so much! If there are no more malware issues we can finish up now. * Click START then RUN * Now type Combofix /Uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter. The above procedure will: * Delete: ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- 1. Double click OTM to launch it. Vista and Windows 7 users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTM will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. When finished exit out of OTM. ---------- Use the Secunia Software Inspector to check for out of date software. * Click Start Scanner * Check the box next to Enable thorough system inspection. * Click Start * Allow the scan to finish and scroll down to see if any updates are needed. * Update anything listed. ---------- Go to Microsoft Windows Update and get all critical updates. ---------- If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page. ---------- I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize FEATURE in Spybot - Search & Destroy. * Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you very very much! uh oh... i just got "ActiveMovie Window: aim6.exe -Unable To Locate Component This application has failed to start because ad2h264dec.dll was not found. Re-installing the application may fix this problem." Does this mean that re-installing it would really fix it or is that a sign of another problem? That's an Adobe file. Not sure if it's audio or video related though. Probably a codec. See if you have the Adobe Premiere Elements folder on your computer. C:\ProgramFiles\Adobe\Adobe Premiere Elements 4.0 |
|